Home / News / Email scams target congregations

Email scams target congregations

Cyber criminals are increasingly targeting churches, congregations, treasurers, ministers, office bearers and volunteers through convincing emails designed to steal money, passwords or sensitive information.

Common scams affecting congregations include:

 Fake invoice and payment requests

  • Emails appear to come from church leaders, ministers or suppliers.
  • Request urgent payment of an invoice or changes to bank account details.
  • Often create a sense of urgency to pressure recipients into acting quickly.

 Impersonation of Uniting Church leaders

  • Attackers pretend to be ministers, church council members or Synod staff.
  • May request gift cards, donations, bank transfers or confidential information.
  • Often ask recipients not to discuss the request with others.

Microsoft 365 and email account scams

  • Fake emails claim your mailbox is full, your password is expiring or your account will be suspended.
  • Designed to trick users into entering their username and password on a fraudulent website.

Donation and charity fraud

  • Scammers request donations for fictitious causes or emergency appeals.
  • Emails can be designed to imitate legitimate church ministries or charitable organisations.

Malicious attachments

  • Unexpected attachments claiming to be invoices, remittance advice, statements or forms.
  • Opening these attachments may install malware or ransomware.

Warning signs to look out for

  • Unexpected requests for money, gift cards or financial assistance.
  • Requests to change supplier or creditor bank account details.
  • Urgent language designed to pressure immediate action.
  • Email addresses that look similar to, but are not exactly the same as, legitimate addresses.
  • Links that direct you to unfamiliar websites.
  • Unexpected attachments or documents.
  • Spelling mistakes, unusual formatting or language that does not match the sender’s normal style.
  • Requests for passwords, multi-factor authentication (MFA) codes, banking details or other sensitive information.

 How to stay safe

  • Verify payment requests by ringing the person or organisation using a known phone number (take care if Googling the telephone number).
  • Independently confirm any changes to bank account details before processing payments.
  • Never provide passwords or MFA codes via email.
  • Hover over links before clicking to check where they lead.
  • If you are unsure whether an email is genuine, stop and verify before taking action.

If an email involves money, banking details, passwords or urgency, pause and verify through another communication channel before acting. A few minutes of checking can protect your congregation and prevent significant financial losses.

Posted in

Related news

Sorry, we couldn't find any posts. Please try a different search.

Leave a Comment