Trust is the whole point. It’s also the opening.
A text that looks like it's from the pastor, asking for gift cards "for a member in need." An email that looks like the treasurer's, requesting a wire transfer. These scams work precisely because a congregation is built on trust and quick responses to need — and most churches have no one whose job is to slow that down.
High-trust, low-tech — exactly what these scams are built for.
Pastor-impersonation scams, where a text or email pretending to be clergy asks a member or staffer to quietly buy gift cards or wire funds, have become common enough that denominational offices now publish standing guidance on them. The pattern works because it mimics exactly how a real pastoral request would arrive — urgent, personal, and awkward to question.
Suspected vs. confirmed account compromises, 2024
Community IT Innovators, 2025 Nonprofit ReportAmong the nonprofit organizations it supports, Community IT Innovators flagged nearly 500 suspected account compromises in 2024 — while confirmed, successful compromises fell 27% year over year, alongside a 20% increase in security-awareness training adoption. Training is measurably working where it’s in place.
phishing and spoofing complaints reported to the FBI in 2024 — the single most common category of cyber crime complaint nationally, with reported losses reaching $70 million.
drop in confirmed nonprofit account compromises in 2024, as security-awareness training adoption grew 20% — a direct, measured link between training and fewer successful attacks.
A text or email impersonating clergy, asking a member to quietly buy gift cards for someone “in need,” is common enough that denominational risk offices now publish standing guidance on it.
It’s rarely a hacked server. It’s a trusted name.
Almost none of these incidents involve breaking into church systems. Nearly all of them involve someone impersonating a trusted name — a pastor, a treasurer, a denominational office — and asking a real person to act quickly.
The anatomy of a pastor-impersonation scam
Urgency is the mechanism, not a side effect
Every version of this scam is built to make pausing to verify feel like the wrong response. That’s the tell — and it’s trainable to recognize.
One trained volunteer changes the outcome
The 27% drop in confirmed compromises was tracked alongside a 20% rise in training adoption — one of the more directly measurable returns in cybersecurity.
Financial and member data both need a policy
Giving records, member contact info, and counseling notes all carry real sensitivity — and most congregations have never written down who can access them.
Deep trust, wide financial access, and no security staff.
Congregations, ministries, and faith-based nonprofits
Churches, ministries, and faith-based nonprofits run largely on volunteers and a small staff, with financial access, giving records, and member data spread across whoever needs it in the moment. You carry real fiduciary and privacy responsibility to your congregation — without a security budget or a dedicated IT role.
Three ways to work together.
Same arc every time: find the gaps, train the eyes, build the program that holds.
Before the Breach
A half-day session for pastoral staff, treasurers, and key volunteers — how these impersonation and phishing scams actually work, plus a one-page verification step before any urgent financial request goes through.
Program Readiness & Gap Assessment
2–3 weeks: review of financial approval processes, giving-platform and member-data access, and volunteer account hygiene, with a prioritized, budget-realistic roadmap.
Program Advisory
A monthly advisor for church leadership — policy updates, new-volunteer training refreshers, and a second opinion before adopting new giving or communication tools.
Would your staff recognize the request before they acted on it?
A 20-minute call, no pitch. Tell us where you're exposed and what your insurance policy requires — we'll tell you honestly where we'd start.
Book a 20-minute call