Home Articles Get your free assessmentComing soon

Tag: wire fraud

  • The Board Member on the Call Wasn’t Real

    The Board Member on the Call Wasn’t Real

    The finance committee meets at seven on Thursday, on video, the way it has since 2020. Four squares on the screen. The treasurer joins eight minutes late, apologises, says the audio on his end is bad, and keeps his camera on anyway.

    He’s brief. The contractor for the roof project needs the deposit moved tonight to hold the crew for next month — the account details came through this afternoon and he’s forwarded them to the administrator. He asks whether anyone objects. Nobody does. His camera freezes twice while he’s talking, which is completely normal on a church Wi-Fi connection, and which is also the reason nobody looks too closely.

    The treasurer was at his daughter’s recital that evening and did not attend the meeting.

    What a deepfake actually is

    Deepfake is a plain word wearing a technical costume. It means a fake image, video, or audio recording generated by software that has studied real recordings of a person until it can produce new ones — a video of someone saying something they never said, or a voice speaking words the person never spoke.

    There’s no mystery in it and nothing exotic. The software needs examples of the person, and it produces convincing new material from them. The more examples it has, the better the result.

    The two forms that matter to a church are different in maturity, and it’s worth being precise about which is which, because the difference determines how you should think about the risk.

    Where the technology actually is

    Synthetic voice is here, it is cheap, and it is fast. This is the mature threat. Software that clones a voice from a short sample is widely available and requires no skill to operate. The FBI’s public warning on generative AI fraud describes criminals using AI-generated audio to impersonate people — a relative in a crisis asking for immediate financial help, or an account holder calling their own bank — in order to extract funds or gain access to accounts. If a caller’s voice sounds exactly like your finance chair, that no longer tells you anything.

    We’ll cover voice cloning on its own in a later post, because it deserves the room.

    Live synthetic video on a call is real but harder. This is where it’s easy to overstate, so here are the actual facts of the best-documented case.

    In January 2024, an employee at Arup — a London-headquartered engineering and design firm — joined a video conference at the company’s Hong Kong office with people who appeared to be the chief financial officer and other colleagues. They were digital recreations. Over the following week the employee made fifteen transfers totalling HK$200 million, roughly US$25 million. Hong Kong police disclosed the case in February 2024, and Arup confirmed in May 2024 that it had been the victim, with a spokesperson saying the firm notified police in January.

    That is one very large fraud against a global firm with thousands of employees, and it should be read as a demonstration rather than as a description of what happens on a typical Tuesday. The everyday version of this attack is still a plain email or a phone call. But the Arup case establishes something that is no longer arguable: a video call is not proof of who you are talking to.

    The FBI’s guidance reflects the same conclusion, noting that criminals generate AI video to depict executives and authority figures in real-time chats or to lend credibility in private communication.

    Why a church is unusually exposed

    Voice cloning needs reference material. Consider what your organization publishes, on purpose, every single week.

    Sermons. Livestreamed services, archived and public. Podcast episodes. Announcement videos. Staff introduction clips on the website. A capital campaign video with the board chair speaking directly to camera for three minutes.

    Most small businesses have almost nothing like this. A church typically has hours of clean, well-recorded audio of its most authoritative voices, freely downloadable, indexed and organized by name.

    None of that is a reason to stop. The livestream is ministry, and taking it down to prevent a hypothetical fraud would be trading something real for something speculative. The right response is not to publish less. It is to stop treating a familiar voice as identification — because for your organization specifically, a familiar voice is public information.

    The rest of the reference material is public too. Your board members are listed on your website or in your 990 filing. Your bank is on your checks. Your building project is in the newsletter. A fraudster does not need to research you; they need to read you.

    The rule that works no matter how good the fake is

    Everything above is about how convincing the impersonation can be. The control below doesn’t care.

    A decision to move money is never made on a call. It is confirmed on a channel the requester did not choose.

    Sit with that second sentence, because it’s the load-bearing part. If the request came in on a video call, confirmation happens by phone. If it came by phone, confirmation happens by a text to the number in your records, or in person, or on a second call you place. The attacker controls the channel they contacted you through — that’s the one thing you can be certain of. So verification has to happen somewhere else.

    This is the same money rule that runs through everything else on this blog: any change to payment details is verified by voice, on a number you already had, before the payment goes out. The deepfake era changes exactly one thing about it. Voice alone is no longer sufficient confirmation. The channel is doing the verifying now, not the sound of the person.

    Three specific mechanisms make that rule practical.

    A shared verbal passphrase for leadership. Agree on a word or short phrase, in person, among the small group of people who can authorize payments — pastor, treasurer, board chair, administrator. It is never written in email, never stored in a shared drive, never said on a video call. When a request to move money arrives from a person rather than a process, the recipient asks for it. The FBI recommends exactly this technique for families targeted by AI voice fraud: “Create a secret word or phrase with your family to verify their identity.” A leadership team is the same idea with a different roster.

    Pick something unguessable and unGoogleable. Not the church’s founding year, not the pastor’s dog. A random pair of words is ideal, and you should agree in advance that anyone may ask for it without it being awkward, including from the senior person in the room.

    A callback rule. No payment instruction is executed on the strength of the call it arrived on. The administrator hangs up, dials the number already in the personnel file or the vendor contract, and confirms. It adds ten minutes and defeats the entire category.

    Dual approval above a threshold. Pick a dollar figure appropriate to your budget and require two named people to approve anything above it — with the second approval given through a channel other than the one the request came in on. This is the control that survives even when the first person is completely fooled, and it’s why it belongs in your written policy rather than in someone’s habits.

    Write all three down. A control that lives only in the treasurer’s head disappears the moment the treasurer is on vacation, which is the week the request will arrive.

    Tells on a live call, and why they expire

    If you find yourself on a call and something is off, there are things worth trying.

    Ask the person to turn their head fully to one side, or to stand up and step back from the camera. Current systems handle a straight-on face far better than a sharp profile or an unusual angle, and artifacts often appear at the edges — around the ears, the jawline, the hairline, or where hair meets background.

    Ask them to hold a hand up beside their face. Hands are still difficult.

    Better than either: ask something only the real person would know, and make it specific and recent. Not “what’s our budget” — anything published is available. Ask what they ordered at lunch on Tuesday, or what the sanctuary thermostat has been doing, or the name of the person who fixed the parking lot lights. A synthetic impersonation is usually driven by someone reading from research, and research does not include last Tuesday’s lunch.

    Now the honest caveat, which matters more than the tips: these tells are expiring. Every one of them exists because the technology has a current limitation, and current limitations do not stay current. Head turns will get better. Hands will get better. The list above may be substantially useless in two years, and there is no version of it that stays reliable.

    That’s not a reason to skip them. It’s the reason the procedure matters more than the perception. A passphrase and a callback rule work identically whether the fake is crude or flawless, because they never ask anyone to judge how real something looks. They’re the only part of this article with a shelf life.

    If it already happened

    Move fast; recovery is a race measured in hours.

    Call your bank’s fraud line first, before anything else, and ask them to attempt a recall. Wire transfers are hardest to reverse and ACH transfers sometimes possible — either way, the first hour matters more than everything you do afterward.

    Report to the FBI at ic3.gov, and say business email compromise even if the request arrived by video, because that’s the category the Bureau’s recovery process runs on. The FBI’s Recovery Asset Team ran 3,574 domestic cases in 2025 and froze $507,042,623, and that process works dramatically better inside the first 24 to 72 hours.

    Tell your board and your insurer the same day. Many policies have prompt-notice requirements, and a delay can affect coverage.

    Then look at the mailbox. These attacks are frequently preceded by someone reading email inside your organization for weeks. Change passwords from a different device, sign out all sessions, enable multi-factor authentication if it isn’t on, and check every mailbox for forwarding rules nobody remembers creating.

    For scale: the FBI logged 24,768 business email compromise complaints in 2025, with losses of $3,046,598,558 — an average of about $123,005 per report. This is where the money in fraud actually goes, and a synthetic voice or face is simply a new way to open the same door.

    What to do this week

    Choose a passphrase with your leadership team — pastor, treasurer, board chair, administrator — in person or on a call where you can see each other, and agree it is never written down or emailed. Then send one message to whoever executes payments, in your own words: no payment or change of payment details goes out on the strength of a call, however convincing. Hang up, call the number we already have, confirm.

    That’s twenty minutes, and unlike every visual tell in this article, it doesn’t stop working next year.

    Procedures are what hold up when the technology stops helping you tell real from fake. MissionDefend’s free assessment asks plain-English questions about how your organization approves payments, handles email, and manages accounts, then returns a baseline score and a ranked list of what to fix first — including whether your money controls depend on someone recognizing a voice.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: FBI Internet Crime Complaint Center, Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud; South China Morning Post, UK multinational Arup confirmed as victim of HK$200 million deepfake scam; CNN, Arup revealed as victim of $25 million deepfake scam involving Hong Kong employee; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.

  • Business Email Compromise: How One Fake Invoice Drains an Account

    Business Email Compromise: How One Fake Invoice Drains an Account

    Your church is six months into a roof replacement. The contractor has invoiced twice already, both paid without incident. On a Thursday morning, the third invoice arrives from the same email address you’ve been corresponding with all spring.

    The invoice looks right. Same logo, same layout, same project reference, correct amount. There’s one difference, and it’s mentioned in a single line of the email body:

    Please note we’ve changed banks — updated remittance details are on the invoice. Sorry for the inconvenience.

    Your bookkeeper updates the payee, sends $47,000, and files the confirmation.

    Eleven days later the contractor calls to ask when they’re getting paid.

    This is business email compromise. It is the most expensive attack aimed at organizations your size, and it almost never looks like an attack while it’s happening.

    What BEC actually means

    Business email compromise — you’ll see it shortened to BEC everywhere — is the category of fraud where someone uses email to impersonate a person you trust in order to redirect a payment.

    The name is slightly misleading, and the confusion matters, because the two versions call for different responses.

    Version one: nothing was compromised. The attacker registered a domain that looks like your contractor’s and sent mail from it. Your vendor is `midlandroofing.com`; the attacker owns `midiandroofing.com` — an l swapped for an i, invisible in most fonts at normal size. Or `midland-roofing.com` with a hyphen. Or `midlandroofing.co` dropping the m. Everything else in the email is copied from real correspondence. Nobody’s account was ever accessed.

    Version two: an account really was taken over. The attacker got into a mailbox — usually through a phished password — and is sending from the genuine address. This version is far more dangerous, because there is nothing to spot in the sender line. It’s genuinely the right address. Worse, the attacker can read the entire history first: they know your project, your invoice format, your payment cycle, who approves what, and how your bookkeeper writes. They often set up a quiet mail rule that moves the real vendor’s messages into an unread folder, so the two of you stop seeing each other’s emails while the attacker relays between you.

    The second version is why “just look at the sender address” is necessary advice but not sufficient advice.

    The scale of it

    The FBI’s Internet Crime Complaint Center recorded 24,768 BEC complaints in 2025, totalling $3,046,598,558 in losses. That works out to an average reported loss of about $123,005 per complaint.

    Sit with that figure against a church budget. For most congregations, one successful BEC is larger than a quarter of total giving. For a small nonprofit, it can be existential.

    And BEC is a rounding error away from being invisible. There’s no ransom note, no locked screen, no alarm. The first sign is almost always a vendor politely asking about an overdue payment.

    The five shapes it takes in a ministry

    The vendor bank change. The scenario above. Most common and most costly, and it spikes during building projects, capital campaigns, and any period when large payments to unfamiliar contractors are normal.

    The leadership wire request. An email that appears to come from your pastor or executive director, asking the bookkeeper to send a payment urgently, usually with a reason it can’t be discussed by phone.

    The payroll redirect. A staff member appears to email HR asking to update their direct deposit details. We’re covering this one in full tomorrow, because it works differently enough to deserve its own post.

    The invoice that was never real. A plausible bill for something a church actually buys — copier maintenance, website hosting, denominational dues, a directory listing — from a company you can’t quite remember but probably use. Small enough to approve without scrutiny. Often repeated monthly until someone notices.

    The data request. No money at all. Someone asks for the staff list, W-2 information, or the donor database. That data becomes the ammunition for the next attack, aimed at a different organization.

    Why churches are good targets for this specifically

    Three things, none of them a failing.

    Approval is informal. In a five-person office, the person who receives the invoice is often the person who pays it. There’s no purchasing department, and adding one would be absurd. But it means a single deceived person completes the whole transaction.

    Large, irregular payments are normal. A church might make three $40,000 payments a year and hundreds of $200 payments. The big ones don’t recur often enough for anyone to develop an instinct about them, and they cluster in exactly the periods — building projects, campaigns — when everyone is busy and moving fast.

    Your relationships are public. Your bulletin thanks the contractor. Your newsletter names the architect. Your board minutes list the vendors. An attacker doesn’t have to guess who you’re paying.

    The one control that stops it

    There is a single procedure that defeats every version of this attack, and it costs nothing:

    Any change to payment details is verified by voice, using a phone number you already had, before the payment goes out.

    Every word in that sentence is load-bearing.

    Any change — not just large ones. The threshold approach fails, because attackers learn thresholds.

    By voice — not by email. If the attacker controls the email thread, every confirmation you receive is written by them. This is the part people get wrong most often: replying to the message and getting a reassuring answer feels like verification, and it is the opposite of verification.

    A number you already had — from a signed contract, a previous invoice, or your own contacts. Never the number in the email or on the new invoice. Attackers put their own number on the document precisely so you’ll “verify.”

    Before the payment goes out — because after is a recovery problem, not a prevention one.

    Two additions make it stronger. Require two people for any payment over a threshold your board sets — one to initiate, a different one to release. And read the bank details aloud during the verification call, digit by digit, rather than asking “did you change banks?” A yes-or-no question invites a yes.

    Write the rule down. Give it to everyone who touches a payment. And state plainly that no one will ever be criticized for making the call, including when the request appears to come from the senior pastor. In a small church, the person most likely to be defrauded is the one who feels least entitled to question leadership.

    Hardening the email side

    The procedure is the main defense. Three technical measures reduce how often you’re tested.

    Multi-factor authentication on every mailbox. This is the extra step after your password — a code from an app, or a tap on your phone. It’s what prevents version two of this attack, where an account is genuinely taken over. Microsoft’s research finds MFA blocks more than 99.2% of account compromise attacks. It’s free on Microsoft 365 and Google Workspace.

    External sender warnings. Ask whoever manages your email to enable the banner reading “This message came from outside your organization.” When a message claiming to be from your executive director carries that banner, the contradiction is visible immediately.

    Check for mail rules you didn’t create. After any suspected compromise — and once a quarter regardless — look in each mailbox’s settings for forwarding rules and filters. Attackers routinely add a rule that forwards everything to an outside address, or that files messages containing “invoice” or “payment” into an obscure folder. It’s the most common thing left behind, and it’s the thing people forget to check after changing a password.

    If it already happened

    Speed is nearly everything. The recall window on a fraudulent transfer is measured in hours.

    Call your bank’s fraud line first. Before you investigate, before you email anyone, before you’re certain. Ask them to attempt a recall. If you have the number ready in advance rather than searching for it, that alone can be the difference.

    Report to the FBI at ic3.gov immediately, and say the words business email compromise and fraudulent wire transfer. This is not a formality. The FBI’s Recovery Asset Team can initiate what’s called the Financial Fraud Kill Chain — a process to freeze funds before they’re moved onward. In 2025 it ran 3,574 domestic cases and froze $507,042,623. It works far better within the first 24–72 hours.

    Don’t reply to the fraudulent thread, and don’t delete anything. The mailbox is evidence.

    Change passwords from a different device and revoke active sessions — in Microsoft 365 and Google Workspace there’s a “sign out everywhere” option. Changing a password alone doesn’t kick out someone who’s already signed in.

    Then check the mail rules, as above.

    And tell your insurer. Many cyber liability policies cover funds transfer fraud, and most impose short notification deadlines.

    What to do this week

    Write down the verification rule and circulate it to everyone who can initiate or approve a payment. One paragraph. Then find your bank’s fraud number and put it somewhere that doesn’t require logging into a computer — taped inside a cabinet door is fine.

    That’s an afternoon’s work against the single most expensive attack aimed at organizations your size.

    When you’re ready to see where else you stand, MissionDefend’s free assessment asks plain-English questions about how your organization handles email, donations, member data, and accounts, then gives you a baseline score and a ranked list of priorities.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: FBI Internet Crime Complaint Center, 2025 Internet Crime Report; Microsoft, mandatory multifactor authentication guidance.