{"id":205,"date":"2026-08-03T13:00:00","date_gmt":"2026-08-03T13:00:00","guid":{"rendered":"https:\/\/missiondefend.com\/blog\/?p=205"},"modified":"2026-07-31T19:55:33","modified_gmt":"2026-07-31T19:55:33","slug":"vishing-phone-scams-churches","status":"publish","type":"post","link":"https:\/\/missiondefend.com\/blog\/vishing-phone-scams-churches\/","title":{"rendered":"Vishing: When the Scam Comes by Phone"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The phone in the church office rings at 2:40 on a Wednesday. The screen says <strong>FIRST NATIONAL BANK<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The caller is calm and slightly bored, the way people sound when they do this all day. There&#8217;s been unusual activity on the church&#8217;s account &mdash; two attempted transfers this morning, both declined. He needs to confirm he&#8217;s speaking with an authorized signer before he can discuss details, and then he&#8217;ll need to verify a code that&#8217;s about to be texted to the number on file, so the fraud hold can be lifted.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Everything about that call is false, including the name on the screen.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Email scams get most of the attention, and reasonably so. But phone-based attacks have a particular power that email doesn&#8217;t: a live human being, responding in real time, adapting to whatever you say. There&#8217;s no time to reread. There&#8217;s no forwarding it to a colleague. Social pressure operates the way it does in any conversation &mdash; hanging up on someone feels rude in a way that deleting an email never does.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What vishing means<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Vishing<\/strong> is short for <em>voice phishing<\/em> &mdash; the same persuasion attack you&#8217;ve read about in this series, delivered by phone call instead of email.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The goal is one of three things: get you to reveal a credential (a password, or more often a one-time code), get you to move money, or get you to install something on a computer.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The name is jargon, but there&#8217;s nothing exotic underneath. Someone calls with an invented reason to be calling, and asks you to do something.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Your caller ID is not evidence<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This is the single most important technical fact in this post, and most people have never been told it plainly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The number and name shown on your phone are supplied by the caller. They are not verified by anyone.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When a call is placed, the caller&#8217;s system includes the number it wants displayed. Historically, the phone network passed that along without checking it. That&#8217;s how legitimate systems work too &mdash; it&#8217;s why a call from a hospital&#8217;s back office can display the hospital&#8217;s main switchboard number, and why your church&#8217;s outgoing calls can all show the office line rather than whichever extension dialled.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That same flexibility is what lets an attacker display your bank&#8217;s actual customer service number, or your denomination&#8217;s regional office, or &mdash; and this happens &mdash; your own church&#8217;s number, calling a member of your congregation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The FCC describes caller ID spoofing as scammers falsifying the number that appears on your display in order to &#8220;trick Americans into answering their phones when they shouldn&#8217;t.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There is a countermeasure, and it&#8217;s worth understanding both what it does and what it doesn&#8217;t.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>STIR\/SHAKEN<\/strong> is a caller ID authentication framework that US carriers are required to implement. In plain terms: the phone company that originates a call digitally &#8220;signs&#8221; it, and the companies that carry it onward can verify that signature. It&#8217;s the reason your phone sometimes displays &#8220;Caller Verified&#8221; or a similar label.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What it does <em>not<\/em> do is guarantee that an unlabelled call is fake, or that a verified call is trustworthy. Verification confirms the call really came from the number shown &mdash; not that the person on the line is honest. Plenty of legitimate calls arrive unsigned, particularly from smaller carriers and internet-based phone systems. Treat it as weak supporting evidence, not proof.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The practical takeaway for your staff: <strong>the name on the screen tells you nothing about who is actually calling.<\/strong><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The versions aimed at ministries<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The bank fraud department.<\/strong> As above. The prize is usually a one-time code &mdash; the six digits your bank texts you. The caller creates a reason you&#8217;d expect to receive one, then asks you to read it out. That code is the second factor protecting your account; handing it over hands over the account.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The IT helpdesk.<\/strong> &#8220;I&#8217;m calling from the company that supports your Microsoft 365 &mdash; we&#8217;re seeing sync errors on your mailbox.&#8221; The ask is either your password or permission to install a remote access tool so they can &#8220;take a look.&#8221; This one succeeds in small offices because the staff genuinely don&#8217;t know exactly who supports their systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The utility shutoff.<\/strong> Aggressive, deadline-driven, aimed at the office administrator: the church&#8217;s power will be cut this afternoon unless an overdue balance is paid immediately, usually by prepaid card or transfer. Real utilities don&#8217;t operate this way.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The denominational or grant office.<\/strong> More targeted. Someone who knows your affiliation calls about a compliance filing, an insurance audit, or a grant disbursement, and needs bank details or staff information to proceed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The follow-up call after an email.<\/strong> Increasingly common, and effective. An email arrives requesting a payment change; then a call arrives &#8220;confirming&#8221; it. Two channels agreeing feels like verification. It isn&#8217;t &mdash; the attacker controls both.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The call to your congregation.<\/strong> Your church&#8217;s number is displayed, and an elderly member is told there&#8217;s a problem with their giving record, or that the church is collecting for an emergency. This one damages trust you spent decades building.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Why it works on good people<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Live conversation removes the two things that protect you in email: time, and the ability to reread.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A skilled caller uses <strong>authority<\/strong> (a title, an institution), <strong>urgency<\/strong> (a hold that expires, a shutoff today), and <strong>plausibility<\/strong> (they already know your pastor&#8217;s name, your bank, your address &mdash; all public). They may also use <strong>reciprocity<\/strong>, doing you a small favour first: <em>&#8220;I&#8217;ve placed a temporary hold on the account for you, that&#8217;ll protect you while we sort this out.&#8221;<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And they exploit ordinary manners. Ending a call abruptly on a polite, professional-sounding person feels aggressive. Most people would rather stay on the line and be uncomfortable.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That instinct is the thing to override, and the way to override it is not to make your staff ruder. It&#8217;s to give them a script that isn&#8217;t rude at all.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The habit that defeats all of it<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">One rule. It handles every variant above without anyone having to judge whether a particular call sounds legitimate:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Hang up and call back on a number you already had.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Not the number the caller gives you. Not the number that appeared on your screen &mdash; that&#8217;s the one that can be faked. The number on the back of your bank card, on a previous statement, in your contacts, on the signed contract, on the utility&#8217;s official website.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The polite version, which anyone can say without confrontation:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p class=\"wp-block-paragraph\"><em>&#8220;I&#8217;m not able to discuss account details on an inbound call. Let me call you back on the number we have on file.&#8221;<\/em><\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">A legitimate caller from any real institution will not object to that. Fraud departments in particular expect it &mdash; it&#8217;s exactly what they train their own customers to do. A caller who pushes back, who explains why calling back won&#8217;t work, who says the case number will expire, has just identified themselves.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Two absolute rules to teach alongside it, with no exceptions:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Never read a one-time code to anyone on the phone.<\/strong> No bank, no vendor, no IT provider, no denominational office will ever ask you to. The entire purpose of that code is to prove <em>you<\/em> are present. Reading it aloud defeats it completely. Most banks now print this warning in the text message itself.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Never install software or grant remote access because of an incoming call.<\/strong> If someone needs to see your screen, that arrangement is made through a relationship you initiated.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Prepare before it happens<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Write down who actually supports you.<\/strong> A single sheet: your bank&#8217;s real fraud number, your IT support&#8217;s real number, your payroll provider, your insurer, your denominational contact. Print it. Put it where the phone is. Most vishing succeeds because the person answering genuinely doesn&#8217;t know who legitimately calls them, and searching for a number under pressure is when people click the wrong result.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Extend the money rule to phone calls.<\/strong> The verification rule from earlier in this series &mdash; no payment change without a callback &mdash; applies identically to requests that arrive by voice. Write it that way so nobody wonders whether the phone is different.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Give people permission to hang up.<\/strong> Say it out loud in a staff meeting: <em>&#8220;If a call feels off, end it. You will never be in trouble for hanging up on someone, even if it turns out to be legitimate. We&#8217;ll sort it out.&#8221;<\/em> Without that explicit permission, junior staff and volunteers will stay on the line out of politeness.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Warn your congregation.<\/strong> Include a line in the newsletter: <em>the church will never call you asking for payment, gift cards, or account details.<\/em> Older members are being targeted heavily &mdash; the FBI logged 201,266 complaints from victims aged 60 and over in 2025, totalling $7.748 billion, up 59% in a single year.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Run one practice call.<\/strong> Ask a board member to call the office pretending to be the bank. Ninety seconds, at a staff meeting. People remember doing it in a way they do not remember being told about it.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">If someone already gave something up<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>If a one-time code was shared:<\/strong> change that account&#8217;s password immediately from a different device, sign out all active sessions, and call the institution&#8217;s real fraud line. Assume the account was accessed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>If remote access was granted:<\/strong> disconnect that computer from the network &mdash; unplug the cable, turn off Wi-Fi &mdash; but don&#8217;t wipe it. Get someone technical to look at it before it goes back into use.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>If money moved:<\/strong> call your bank&#8217;s fraud line before doing anything else, then report to the FBI at <strong>ic3.gov<\/strong>. The Bureau&#8217;s Recovery Asset Team froze $507,042,623 across 3,574 domestic cases in 2025, and that process depends almost entirely on speed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>In every case, tell someone immediately.<\/strong> The pattern that turns a contained mistake into a serious loss is a person who is embarrassed and waits.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What to do this week<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Make the one-page contact sheet &mdash; bank fraud line, IT support, payroll, insurer &mdash; and tape it up next to the office phone. Then, at your next staff meeting, say the sentence out loud: <em>nobody will ever be in trouble for hanging up and calling back.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That&#8217;s fifteen minutes, and it closes the whole category.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">MissionDefend&#8217;s free assessment asks plain-English questions about how your organization handles email, donations, member data, and accounts, then gives you a baseline score and a ranked list of what to fix first.<\/p>\n\n\n\n<div class=\"wp-block-buttons is-content-justification-center is-layout-flex wp-container-core-buttons-is-layout-35f06ea7 wp-block-buttons-is-layout-flex\">\n\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/missiondefend.com\/#notify\" style=\"border-radius:999px\">Join the launch list &rarr;<\/a><\/div>\n\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">No spam and no sales calls &mdash; just one email when it&#8217;s live.<\/p>\n\n\n\n<h2 class=\"wp-block-heading md-related\">Related reading<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li><a href=\"https:\/\/missiondefend.com\/blog\/callback-phishing-fake-renewal\/\">the email written to make you dial the number<\/a><\/li>\n\n\n<li><a href=\"https:\/\/missiondefend.com\/blog\/deepfake-video-call-board\/\">what happens when the voice on the line is cloned<\/a><\/li>\n\n\n<li><a href=\"https:\/\/missiondefend.com\/blog\/social-engineering-churches-nonprofits\/\">the six levers every one of these attacks pulls<\/a><\/li>\n\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p class=\"has-small-font-size wp-block-paragraph\"><em>MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Sources:<\/strong> Federal Communications Commission, <a href=\"https:\/\/www.fcc.gov\/call-authentication\" target=\"_blank\" rel=\"noopener\">Combating Spoofed Robocalls with Caller ID Authentication<\/a>; FBI Internet Crime Complaint Center, <a href=\"https:\/\/www.ic3.gov\/AnnualReport\/Reports\/2025_IC3Report.pdf\" target=\"_blank\" rel=\"noopener\">2025 Internet Crime Report<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Your caller ID can say anything the caller wants. Here&#8217;s how phone-based scams work against churches and nonprofits, and the one habit that defeats all of them.<\/p>\n","protected":false},"author":1,"featured_media":111,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[26,25,10,24],"class_list":["post-205","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-threats-scams","tag-caller-id-spoofing","tag-phone-scams","tag-social-engineering","tag-vishing"],"_links":{"self":[{"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/posts\/205","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/comments?post=205"}],"version-history":[{"count":1,"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/posts\/205\/revisions"}],"predecessor-version":[{"id":342,"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/posts\/205\/revisions\/342"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/media\/111"}],"wp:attachment":[{"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/media?parent=205"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/categories?post=205"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/tags?post=205"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}