How Business Email Compromise Scams Are Draining Church Bank Accounts (and How to Stop Them)

A finance volunteer gets an email that looks like it's from the senior pastor: "I'm in a meeting, can't talk, but I need you to wire $8,400 to a contractor today — it's time-sensitive." The tone matches. The signature matches. Even the reply-to address looks almost right. Twenty minutes later, the money is gone, sent to an account in another state, and there was never a contractor. This is business email compromise (BEC), and churches are some of the easiest targets in the country. Small finance teams, high trust between staff and leadership, public staff directories, and a culture of quick action on urgent requests make congregations a favorite target for organized scam operations. The FBI's IC3 has named BEC the costliest form of cybercrime for years running, and faith-based organizations report losses ranging from a few thousand dollars to well over six figures in a single incident. The good news: BEC scams follow predictable patterns, and a handful of concrete controls — most of them free — stop nearly all of them.

What business email compromise actually looks like at a church

BEC isn't a virus or a hacked website — it's a con built entirely out of trust and urgency, usually with no malware involved at all. The scammer either spoofs a leader's email address (making outgoing mail appear to come from pastor@yourchurch.org when it didn't) or, in a smaller number of cases, has actually broken into that person's real inbox and is emailing from it directly.

At churches, the pattern almost always follows one of three scripts. The "pastor needs a favor" script asks a bookkeeper or admin to buy gift cards, wire money to a vendor, or change a payroll direct-deposit account, framed as urgent and confidential. The "vendor invoice" script impersonates a contractor, a ChMS/software vendor, or a utility company and asks that an upcoming payment be redirected to "updated" bank details. The "building fund" or "missions trip" script targets a specific known transaction — a construction payment, a mission trip deposit — because the scammer has learned the real project exists, often from a church newsletter, bulletin, or public Facebook post.

What makes these convincing is specificity. Scammers research staff directories on the church website, read bulletins and social media for real project names and dollar amounts, and study writing style from publicly available sermons or newsletters. The email itself often uses a lookalike domain (yourchurch-org.com instead of yourchurch.org) or a free Gmail/Outlook address with the pastor's real name as the display name — most email apps show the display name prominently and bury the actual address.

Why churches are targeted more than most small businesses

Churches combine several traits that scammers actively look for. Staff directories, board member names, and pastor bios are usually public by design — the church wants to be findable. Financial approval is often concentrated in one or two people (a part-time bookkeeper, a volunteer treasurer) rather than spread across a finance department with built-in checks. And the culture of ministry runs on trust and responsiveness: saying "let me verify that first" to an apparent request from the senior pastor feels, to a lot of staff, like second-guessing spiritual authority.

Scammers also know that many churches still use free or low-tier email hosting without the authentication records (SPF, DKIM, DMARC) that make spoofing harder, and that financial oversight — a second signature on large transfers, a callback policy — is often informal or undocumented rather than a written, enforced procedure. None of this is a judgment on how churches are run; it's simply the profile a fraud operation screens for before choosing a target.

The single highest-leverage fix: lock down your domain's email authentication

Most BEC attacks depend on spoofing — sending an email that claims to be from your domain without actually having access to it. Three DNS records make that dramatically harder, and Google Workspace supports all three natively: SPF (Sender Policy Framework) lists which mail servers are allowed to send as your domain; DKIM (DomainKeys Identified Mail) cryptographically signs your outgoing mail so receivers can verify it wasn't altered; and DMARC (Domain-based Message Authentication, Reporting and Conformance) tells receiving mail servers what to do with messages that fail SPF or DKIM checks — and can instruct them to reject spoofed mail outright before it ever reaches an inbox.

A church running on Google Workspace can set up SPF and DKIM in about 15 minutes through the Admin Console (Apps → Google Workspace → Gmail → Authenticate email), then add a DMARC record starting in monitor mode (p=none) to see what's actually happening, and move to p=quarantine or p=reject once legitimate mail is confirmed to be passing. This single change stops the most common version of BEC — a scammer sending mail that appears to come directly from your domain — cold. It's also worth checking whether your current provider makes this easy: if you're on a legacy or consumer-grade email plan, migrating to Google Workspace is often the fastest way to get modern authentication, admin-level phishing controls, and 2-Step Verification in one move.

Build a wire-transfer policy that a spoofed email can't defeat

Technology stops spoofed domains, but it can't stop a scammer who compromises a real inbox or uses a convincing lookalike address a filter didn't catch. That's why the second layer has to be a process, not a tool: no money moves, and no bank or vendor payment detail changes, based on an email request alone — ever, regardless of how urgent it sounds or who it appears to come from.

The standard that stops nearly all of these scams is dual control plus out-of-band verification. Any wire transfer, ACH payment, or change to vendor banking details above a set threshold (many churches use $500-$1,000) requires a second person's sign-off, and that second person verifies the request by calling a phone number they already have on file — never a number provided in the email itself — before releasing funds. If the pastor "emails" asking for an urgent wire, the correct response is a phone call to the pastor's known cell number, not a reply to the email. This single habit, practiced consistently, defeats the vast majority of BEC attempts because the scammer can fake an email far more easily than they can answer a phone call as the person they're impersonating.

Write this down as a one-page policy, get board or elder approval, and walk new finance volunteers through it during onboarding. A verbal policy that "everyone knows" tends to break down exactly when someone new is filling in during a busy week — which is often when scammers strike.

Train staff and volunteers to spot the tells

Most BEC emails share detectable warning signs once someone knows to look: urgency paired with secrecy ("don't mention this to anyone else yet"), a request to change communication channels ("my usual email is down, respond here" or "text me instead"), pressure to bypass normal approval steps, and a sender address that's close but not exact — a hyphen, an extra letter, or a different top-level domain (.org vs .com) from the real one.

Run a short training at least twice a year with every staff member and finance volunteer who touches money or has email access, including part-time and seasonal help. It doesn't need to be elaborate: walk through 2-3 real, anonymized examples of BEC emails (the FBI's IC3 site and the Better Business Bureau publish real case writeups), and rehearse the exact verification step from your wire-transfer policy so it's muscle memory, not a rule people vaguely remember. Encourage a "see something, forward it" culture — staff should feel comfortable flagging a weird email to IT or leadership without worrying it makes them look paranoid or slow.

Turn on the free technical controls Google Workspace already includes

Beyond domain authentication, Google Workspace includes several protections that are off or set loosely by default in many small organizations and are worth confirming are active. Enable 2-Step Verification for every staff account, especially anyone with financial or admin access — this alone stops most account-takeover attempts even if a password is phished. Turn on Gmail's enhanced phishing and spoofing protection in the Admin Console (Apps → Gmail → Safety), which flags messages that impersonate your own domain or employees. Enable "identify unusual emails as potential phishing" and automatic mail warnings for messages from unauthenticated senders, so staff see a visible in-Gmail warning banner instead of relying on their own judgment. And review Admin Console alerts periodically — Google will flag suspicious login attempts and mass forwarding rules, which is exactly what an attacker sets up after successfully phishing a password so they can silently monitor an inbox for the right moment to strike.

What to do in the first hour if you suspect a fraudulent transfer

Speed matters more than almost anything else once money has moved. Call your bank's fraud department immediately and request a wire recall or ACH reversal — banks can sometimes claw back funds within the first 24-72 hours, but the odds drop fast after that window closes. Report the incident to the FBI's Internet Crime Complaint Center at ic3.gov the same day; IC3 has a Recovery Asset Team that works directly with banks on time-sensitive cases and has recovered funds for organizations that reported quickly.

Separately, secure the compromised or spoofed account: force a password reset, revoke active sessions and any mail-forwarding or delegate rules an attacker may have added, and enable 2-Step Verification if it wasn't already on. Preserve the original email with full headers rather than forwarding it (forwarding strips the routing information investigators need). Finally, notify your board or elder team and, depending on your state and the amount involved, consider whether your insurance carrier's cyber liability coverage applies — a growing number of church insurance policies now include a rider for exactly this kind of loss.

Get a free church email deliverability audit →

Frequently asked questions

Can a scammer really send email that looks like it's from our church's own domain?

Yes, if your domain doesn't have SPF, DKIM, and DMARC records configured correctly. Without them, nothing stops another mail server from claiming to send as pastor@yourchurch.org. Setting up all three in Google Workspace closes this gap and is free.

Our church is small and doesn't move much money. Are we really a target?

Small organizations are actually preferred targets, not overlooked ones. Scammers run these attacks at scale against thousands of small nonprofits and churches at once, betting on informal financial controls rather than large individual payouts. A single successful $3,000-$8,000 transfer is a common and profitable outcome for them.

What's the single most effective thing we can do this week?

Write and adopt a one-page policy requiring phone verification, using a number already on file, before any wire transfer or bank-detail change tied to an email request. This process step stops most BEC attempts even when the technical filters miss something.

If we move to Google Workspace, does that alone stop these scams?

It removes a major attack path by making it far harder for scammers to spoof your domain and by adding admin-level phishing detection and 2-Step Verification, but it isn't a complete solution on its own. Pairing it with a written verification policy and periodic staff training covers the gap that technology can't close by itself.

How quickly can we recover money after a fraudulent wire transfer?

The first 24-72 hours are critical. Call your bank's fraud line immediately to request a recall and file a report at ic3.gov the same day — IC3's Recovery Asset Team works directly with financial institutions and has successfully frozen or returned funds in cases reported within that early window.