The first flag is human · Churches & faith-based nonprofits

Trust is the whole point. It’s also the opening.

A text that looks like it's from the pastor, asking for gift cards "for a member in need." An email that looks like the treasurer's, requesting a wire transfer. These scams work precisely because a congregation is built on trust and quick responses to need — and most churches have no one whose job is to slow that down.

What’s actually happening

High-trust, low-tech — exactly what these scams are built for.

Pastor-impersonation scams, where a text or email pretending to be clergy asks a member or staffer to quietly buy gift cards or wire funds, have become common enough that denominational offices now publish standing guidance on them. The pattern works because it mimics exactly how a real pastoral request would arrive — urgent, personal, and awkward to question.

Suspected vs. confirmed account compromises, 2024

Community IT Innovators, 2025 Nonprofit Report

Among the nonprofit organizations it supports, Community IT Innovators flagged nearly 500 suspected account compromises in 2024 — while confirmed, successful compromises fell 27% year over year, alongside a 20% increase in security-awareness training adoption. Training is measurably working where it’s in place.

193,407

phishing and spoofing complaints reported to the FBI in 2024 — the single most common category of cyber crime complaint nationally, with reported losses reaching $70 million.

FBI, Internet Crime Report 2024
−27%

drop in confirmed nonprofit account compromises in 2024, as security-awareness training adoption grew 20% — a direct, measured link between training and fewer successful attacks.

Community IT Innovators, 2025 Nonprofit Cybersecurity Incident Report
Documented pattern

A text or email impersonating clergy, asking a member to quietly buy gift cards for someone “in need,” is common enough that denominational risk offices now publish standing guidance on it.

General Council on Finance and Administration (UMC); Christianity Today, Jan 2025
What actually goes wrong

It’s rarely a hacked server. It’s a trusted name.

Almost none of these incidents involve breaking into church systems. Nearly all of them involve someone impersonating a trusted name — a pastor, a treasurer, a denominational office — and asking a real person to act quickly.

The anatomy of a pastor-impersonation scam

Pattern documented by GCFA and multiple denominational risk offices
Impersonates a trusted name (pastor, staff, treasurer)step 1
Creates urgency around a member “in need”step 2
Requests gift cards or a wire — hard to reversestep 3
Asks the recipient to keep it quiet, for nowstep 4
Source: General Council on Finance and Administration (GCFA) and Christianity Today reporting on pastor-impersonation scams, 2025. Bar widths illustrate the scam’s escalating structure, not a statistical breakdown.

Urgency is the mechanism, not a side effect

Every version of this scam is built to make pausing to verify feel like the wrong response. That’s the tell — and it’s trainable to recognize.

One trained volunteer changes the outcome

The 27% drop in confirmed compromises was tracked alongside a 20% rise in training adoption — one of the more directly measurable returns in cybersecurity.

Financial and member data both need a policy

Giving records, member contact info, and counseling notes all carry real sensitivity — and most congregations have never written down who can access them.

Who this is for

Deep trust, wide financial access, and no security staff.

Churches & faith-based nonprofits

Congregations, ministries, and faith-based nonprofits

Churches, ministries, and faith-based nonprofits run largely on volunteers and a small staff, with financial access, giving records, and member data spread across whoever needs it in the moment. You carry real fiduciary and privacy responsibility to your congregation — without a security budget or a dedicated IT role.

Services

Three ways to work together.

Same arc every time: find the gaps, train the eyes, build the program that holds.

Start here 01 · Workshop

Before the Breach

Train the eyes

A half-day session for pastoral staff, treasurers, and key volunteers — how these impersonation and phishing scams actually work, plus a one-page verification step before any urgent financial request goes through.

From $7,000Founding rate $5,000 for the first cohorts
02 · Assessment

Program Readiness & Gap Assessment

Find the gaps

2–3 weeks: review of financial approval processes, giving-platform and member-data access, and volunteer account hygiene, with a prioritized, budget-realistic roadmap.

From $11,000Fixed fee · scope set before we start
03 · Retainer

Program Advisory

Build it for real

A monthly advisor for church leadership — policy updates, new-volunteer training refreshers, and a second opinion before adopting new giving or communication tools.

From $6,000/mo6-month minimum
Let's talk

Would your staff recognize the request before they acted on it?

A 20-minute call, no pitch. Tell us where you're exposed and what your insurance policy requires — we'll tell you honestly where we'd start.

Book a 20-minute call