{"id":404,"date":"2026-08-13T13:00:00","date_gmt":"2026-08-13T13:00:00","guid":{"rendered":"https:\/\/missiondefend.com\/blog\/?p=403"},"modified":"2026-08-13T13:00:00","modified_gmt":"2026-08-13T13:00:00","slug":"pretexting-fake-it-support-vendor","status":"publish","type":"post","link":"https:\/\/missiondefend.com\/blog\/pretexting-fake-it-support-vendor\/","title":{"rendered":"Pretexting: The Fake IT Guy and the Vendor Who Isn&#8217;t"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The call comes in on a Wednesday around 10 a.m., which is not an accident &mdash; late enough that the office is busy, early enough that nobody&#8217;s left for lunch.<\/p>\n\n\n\n<p class=\"has-small-font-size wp-block-paragraph\"><em>&#8220;Hi, this is Marcus from TechServe &mdash; we handle the copier contract? We&#8217;re pushing a security update to all our units this week and I need someone to read me the numbers off the admin sticker on the back. Should take two minutes. Sorry for the hassle &mdash; half the churches in the county are on my list today.&#8221;<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There is no Marcus. There is no update. But notice everything that call already got right: a plausible company, a plausible task, an apology, a time limit, and a detail &mdash; <em>half the churches in the county<\/em> &mdash; that makes the whole thing feel routine. By the time an ask arrives, it doesn&#8217;t feel like a request from a stranger. It feels like step three of a process that started before you picked up.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That manufactured backstory has a name: <strong>pretexting<\/strong>. The <em>pretext<\/em> is the invented situation &mdash; the role, the reason, the paperwork &mdash; that makes the eventual request seem normal. If phishing is a fake message, pretexting is a fake <em>context<\/em>. It&#8217;s the con artist&#8217;s stage set, and it&#8217;s the engine inside most of the attacks this series has covered: the <a href=\"https:\/\/missiondefend.com\/blog\/business-email-compromise-nonprofits\/\">fake invoice<\/a> works because &#8220;vendor billing you&#8221; is a pretext, and the <a href=\"https:\/\/missiondefend.com\/blog\/vishing-phone-scams-churches\/\">phone scam<\/a> works because &#8220;your bank&#8217;s fraud department&#8221; is one.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The costumes that get worn at churches<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Attackers pick pretexts the target already expects to encounter. For a church or small nonprofit, four costumes come up over and over.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The IT technician.<\/strong> &#8220;We&#8217;re doing maintenance on your email this afternoon &mdash; I&#8217;ll need someone to confirm the login so accounts don&#8217;t lock out.&#8221; Small congregations rarely have in-house IT, so <em>someone external who handles computer things<\/em> is entirely believable &mdash; most churches genuinely do have a guy. The test is simple: real technicians you actually pay never need your password. Anyone who asks for one is not your technician, whatever the caller ID says.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The vendor with an account problem.<\/strong> The copier company, the payroll processor, the giving platform, the alarm monitoring service. The caller knows which one you use &mdash; often because it&#8217;s visible on your website, in a bulletin PDF, or on a sticker by the door &mdash; and the &#8220;problem&#8221; needs an account number, a card update, or remote access to fix.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The authority up the chain.<\/strong> The diocese, the district office, the denomination&#8217;s insurance program, an &#8220;auditor&#8221; doing an annual review. Hierarchical organizations are trained to respond to the level above them, and attackers borrow that reflex. A folder of official-looking paperwork, a confident tone, and a Friday-afternoon deadline can move remarkable amounts of information.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The government caller.<\/strong> The IRS about your exempt status, a &#8220;grant administrator&#8221; about funds you&#8217;re eligible for, a court officer about a missed jury summons for your pastor. Impersonating agencies and businesses is now squarely illegal under a rule the Federal Trade Commission put into force on <strong>April 1, 2024<\/strong> &mdash; a rule created precisely because the FTC logged <strong>over $1.1 billion in reported impersonation-scam losses in 2023, more than triple the 2020 figure<\/strong>. A rule after the fact, of course, only helps you if you didn&#8217;t comply during the call.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Why good people hold the door open<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Pretexting exploits the two instincts churches deliberately cultivate: helpfulness and trust. The volunteer at the desk wants to be useful to the nice technician. The bookkeeper doesn&#8217;t want to make the diocese wait. Nobody wants to be the suspicious one &mdash; it feels rude, and ministry culture prizes warmth.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So the fix cannot be &#8220;make everyone suspicious.&#8221; It won&#8217;t take, and it would cost you something real. The fix is to make verification <em>feel like procedure instead of accusation<\/em> &mdash; the same shift that makes a bank teller checking ID feel professional rather than hostile.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What to do this week<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Give the front desk a script that isn&#8217;t rude.<\/strong> One laminated card: <em>&#8220;Happy to help with that &mdash; our process is to call you back through the main number we have on file for your company. What&#8217;s your name and extension?&#8221;<\/em> A real vendor hears bookkeeping hygiene. A pretexter hears the con failing. The power of the callback is that it routes around everything the attacker controls &mdash; their number, their story, their urgency &mdash; to a channel you already trusted before the call existed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Keep a one-page vendor sheet.<\/strong> Every company that can plausibly call you &mdash; copier, payroll, giving platform, insurance, IT, alarm &mdash; with the phone number <em>from your contract or a bill you&#8217;ve paid<\/em>, not from the internet. Verification only works if the real number takes ten seconds to find. Update it when contracts change, and note who your actual account rep is.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Decide what the &#8220;sticker information&#8221; is worth.<\/strong> Serial numbers, account numbers, staff direct lines, which software you use &mdash; none of it is secret, exactly, but each piece makes the next pretext more convincing. The attacker who knows your copier model and your administrator&#8217;s first name sounds like Marcus. Trim what&#8217;s published where you can, and treat unsolicited requests for those details as the reconnaissance they are.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Rehearse the two-question test.<\/strong> Before acting on any unsolicited contact, staff ask: <em>Did I have a way to expect this?<\/em> and <em>Am I being given a reason not to verify?<\/em> A real vendor&#8217;s real update survives a callback tomorrow. Only the fake one needs it done on this call, today, before lunch.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Pretexting is patient, polite, and completely dependent on one thing: the target acting inside the story the attacker built. A callback steps outside the story. Nothing inside it survives that.<\/p>\n\n\n\n<p class=\"has-small-font-size wp-block-paragraph\"><em>MissionDefend&#8217;s free assessment includes the unglamorous controls that stop pretexting &mdash; callback rules, vendor verification, front-desk procedure &mdash; and shows you which ones your organization is missing. <a href=\"https:\/\/missiondefend.com\/#notify\">Get on the launch list<\/a>.<\/em><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Sources:<\/strong> Federal Trade Commission, <a href=\"https:\/\/www.ftc.gov\/news-events\/news\/press-releases\/2024\/04\/ftc-announces-impersonation-rule-goes-effect-today\" target=\"_blank\" rel=\"noopener\">FTC Announces Impersonation Rule Goes into Effect Today<\/a> (April 1, 2024); Cybersecurity and Infrastructure Security Agency, <a href=\"https:\/\/www.cisa.gov\/secure-our-world\/recognize-and-report-phishing\" target=\"_blank\" rel=\"noopener\">Recognize and Report Phishing<\/a>; FBI Internet Crime Complaint Center, <a href=\"https:\/\/www.ic3.gov\/AnnualReport\/Reports\" target=\"_blank\" rel=\"noopener\">2025 Internet Crime Report<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Pretexting is the story a scammer builds before the ask \u2014 the fake IT tech, the copier company, the diocese office. How to spot a manufactured reason to comply.<\/p>\n","protected":false},"author":1,"featured_media":397,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[14,147,12,72],"class_list":["post-404","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-threats-scams","tag-impersonation","tag-pretexting","tag-staff-training","tag-vendor-fraud"],"_links":{"self":[{"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/posts\/404","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/comments?post=404"}],"version-history":[{"count":1,"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/posts\/404\/revisions"}],"predecessor-version":[{"id":415,"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/posts\/404\/revisions\/415"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/media\/397"}],"wp:attachment":[{"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/media?parent=404"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/categories?post=404"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/missiondefend.com\/blog\/wp-json\/wp\/v2\/tags?post=404"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}