Being Wise: Protect YouRself from Phishing and Impersonation Scams

Chantilly Bible Church — Member Awareness Guide

 
 

Context

Almost every week one or more people in our church receive an email appearing to come from a staff member or other church leader asking for money or information in some form.  Typical example: an e-mail from Pastor Mike asking for someone to purchase gift cards for some good cause and send them to him.  While there are sometimes signs that would indicate these are deceptive emails, the quality of the nefarious communications are getting better and better.

This isn't unique to CBC. Cybersecurity researchers estimate that roughly 4 in 10 North American cyberattacks now target ministries and nonprofits — and church cyber-incident reports have climbed sharply over the past two years. Churches are attractive targets for a few specific reasons:

•      Trust culture. Churches are built on trust and a willingness to help — exactly what scammers exploit when they pose as a pastor or elder in urgent need.

•      Wide, semi-public contact networks. Church directories, bulletins, and staff lists make it easy for a criminal to learn names, roles, and relationships.

•      Frequent, legitimate money requests. Churches regularly ask members for donations, mission trip support, and benevolence gifts — which gives cover to a fraudulent version of the same request.

Key Points

  • The CBC staff and church leadership will NEVER e-mail or text and ask you to purchase gift cards or transfer money to themselves directly.

  • ALWAYS verify these types of financial or information requests that you receive by e-mail from CBC leadership BEFORE you take action. You can do this by using some other means - texting or calling the person who appears to make the request.

How it works

Criminals get access to contact information (email, phone number) in some way. This can be through a compromised contact list in someone’s email or other app, an email sent to many people (directly not via bcc), or even a printed directory.

Once they have names and contact details, here's typically what happens next:

1.    Research. The scammer looks up staff and leadership names on the church website, Facebook page, or other publication — enough to know who "Pastor Mike" is and that he'd plausibly email the congregation.

2.    Spoofing or lookalike setup. They either fake the "From" name on an email (the display name says "Pastor Mike" but the actual address is unrelated), or they register a lookalike domain/address that's one letter off from the real one.

3.    The ask. The message creates urgency and asks for something quiet and fast to convert — gift cards are especially common because they're untraceable and instant once the codes are shared.

4.    Escalation if you reply. If you respond, the scammer often continues the conversation personally, adding pressure ("I'm in a meeting, please hurry," "don't mention this to the office yet") to keep you from verifying independently.

5.    Reuse. The same contact list is often reused for weeks or sold to other criminals, which is why the same scam pattern tends to resurface repeatedly in a church.

Red Flags

•      Urgency or secrecy — "I need this right now," "please don't tell anyone yet," "I'm in a meeting and can't talk."

•      A request to switch channels — a text out of nowhere, or a reply-to address that doesn't match the sender's normal email.

•      Requests for gift cards, wire transfers, cryptocurrency, or payment apps to a personal account.

•      Mismatched or slightly altered email addresses — an extra letter, a different domain (e.g., "@chantillybiblechurch.org" vs the correct "@chantillybible.org"), or a display name that doesn't match the actual address.

•      Generic or slightly "off" tone — wording, greeting, or phrasing that doesn't sound like how that person normally writes.

•      Pressure to act before you can verify, especially outside normal business hours.

•      Unexpected attachments or links, especially ones asking you to "log in" or "verify your account."

•      A request that's unusual for that person's role — e.g., a pastor personally handling a financial transaction that would normally go through the church office.

Advice and Tips

•      Pause before acting. Legitimate requests can wait a few minutes for you to verify them. Scammers rely on you not taking that time.

•      Verify independently, every time. Call or text the person using a number you already have — from your phone's contacts, the church directory, or the church website — never a number provided in the suspicious message itself.

•      Don't click links or open attachments in unexpected messages, even if they appear to come from someone you know.

•      Check the actual sender address, not just the display name, before trusting any request.

•      Never buy gift cards, wire money, or share banking/login information based solely on an email or text request.

•      Report suspicious messages to the church office at info@chantillybible.org so we can be aware of new phishing activities, respond appropriately, and communicate helpful information to others.

•      Tell the person you're helping. If a request seems even slightly unusual, mentioning it to a spouse, friend, or the office often surfaces doubts you hadn't quite named yet.

•      If you already responded or paid: Contact your bank or gift card issuer immediately, keep records of the messages, and let the church office know — there's no shame in reporting it, and doing so protects others.

•      Consider turning on two-factor authentication on your email account. A compromised email account is one of the most common ways these scams start in the first place.

Look carefully then how you walk, not as unwise but as wise,

making the best use of the time, because the days are evil.

Ephesians 5:15–16