Cybersecurity basics for church communicators: Protecting your accounts in a high-trust, high-risk world

Photo: FlyD for Unsplash
Photo: FlyD for Unsplash

Imagine leaving your church's front doors wide open, the offering unlocked, and a list of congregants' home addresses pinned to the bulletin board on a night when thieves are working the neighborhood. That's not hypothetical. For many churches, it's the current state of digital security.

Cybercriminals target churches because they're trusted institutions with public contact info, regular financial transactions, and rich personal data, but usually no dedicated IT security staff. Nearly 43% of cyberattacks in North America now target ministries and nonprofits, and phishing alone cost victims $70 million in 2024, up from $18.7 million the year before.

This article is for communicators, administrators, pastors, and volunteers managing your church's digital presence, often without formal tech training. You don't need a cybersecurity degree to reduce risk dramatically. You need practical knowledge, good habits, and a few inexpensive tools.


Why Churches Are Targets

Churches operate in what researchers call "high-trust, low-tech environments." Congregations trust leadership completely, and attackers exploit that trust.

By the numbers: 43% of North American cyberattacks target nonprofits/ministries; 193K+ phishing complaints hit the FBI in 2024; phishing losses nearly quadrupled year-over-year; 34% of church staff fail phishing simulations (among the highest of any sector); it takes an average of 241 days to identify a breach; and 70% of nonprofits have no formal cybersecurity policy even though 60% report an attack in the past two years.

Structural weaknesses compound the risk: staff emails are publicly listed, volunteers with little security training manage critical systems and rotate frequently, and church management software holds a goldmine of names, addresses, and giving records - the same sensitive data that banks hold - often without equivalent protection.

 

Five Attacks Hitting Churches Now

1.    Staff Business Email Compromise - An attacker tricks a staff member out of their password and MFA code, then quietly emails vendors and congregants from the hijacked account.

2.    Vendor Email Compromise - A vendor's email is hijacked, and the attacker requests a payment redirect to "new banking information."

3.    Pastor/Executive Impersonation - A text or email appears to come from the senior pastor, urgently requesting gift cards. Authority plus urgency overrides critical thinking.

4.    Church Management System (ChMS) Compromise - Stolen login credentials expose your entire congregant directory for targeted follow-on attacks.

5.    Ransomware - Attackers encrypt your data and threaten to leak congregant information if you refuse to pay.

In one 2025 case, a North Carolina pastor had to warn his congregation after a near-identical spoofed email began soliciting gift-card donations. The same scam hit multiple Georgia churches simultaneously. This is common, not rare.

Phishing: The Everyday Threat

Phishing succeeds not through technical sophistication but through psychological manipulation that exploits fear, greed, and empathy. Church-targeted phishing is personal and plausible: "quick favor" emails from the pastor, urgent vendor wire-redirect requests, fake donation pages, and texts asking you to "handle something discreetly."

Red flags: slightly misspelled sender addresses, unusual urgency or secrecy, any request involving gift cards or wire transfers, unexpected links/attachments, and messages that just feel "off."

The one rule that stops most attacks: if an email requests money, credentials, or urgent action, call the sender using a number you already know, never one from the email.

Are you ready to upgrade your ministry communications?

SUBSCRIBE NOW TO MyCom ►

Passwords and MFA

Weak or reused passwords are the most common entry point for attackers. Strong passwords are 16 or more characters, mix character types, and are unique per account. Password managers such as 1Password and Bitwarden, many of which offer nonprofit pricing, generate and store these automatically, and instantly revoke access when someone leaves.

Multi-factor authentication (MFA) is your single best free defense - it blocks over 99.9% of account compromise attempts. Even a stolen password is useless without the second factor. Authenticator apps are the sweet spot for most churches; hardware security keys are the gold standard for high-value accounts like email. Enable MFA first on email, then social media, ChMS, giving platforms, and cloud storage.

Social Media and Email Habits

Protect social accounts by auditing admin access regularly, using a generic church email as the top-level admin, enabling MFA for every team member, and requiring a signed social media use agreement. Revoke outdated third-party app permissions and monitor for unusual login activity. For email: never click links in unsolicited messages, forward suspicious emails to a tech lead, use web filtering, and always verify unusual requests by phone.

Data Minimization

The simplest defense is not having data to lose. As Candid's Joshua Peskay puts it, "Your liability for protecting data never decreases even as its value does." In other words, you can't suffer a breach of data you don't have. Create a data retention policy, delete outdated sensitive spreadsheets, and limit ChMS access to those who genuinely need it.

Network Basics

Keep guest Wi-Fi separate from the network running your ChMS and giving platform. Enable automatic software updates, avoid public Wi-Fi for sensitive tasks, and run endpoint protection on all church devices.

Building a Culture of Security

Every source agrees: training is the single best investment a church can make. Use real church scenarios, run periodic simulated phishing tests, repeat training regularly, and build a "pause and verify" culture. Require signed use agreements at onboarding and establish a no-blame reporting process so staff report mistakes instead of hiding them.
Free Resources

  • CISA - Faith-Based Community resources: cisa.gov/audiences/faith-based-community
  • GuideStone - free white paper on protecting churches from cyberattacks: guidestone.org
  • Sightline Security - nonprofit-focused cybersecurity guidance

Five Things to Do

  1. Turn on MFA for church email and social media.
  2. Audit who has access to social accounts and your ChMS; remove anyone who no longer needs it.
  3. Choose a password manager and start phasing out reused passwords.
  4. Brief staff on the "quick favor" gift card scam and the vendor wire-redirect scam.
  5. Confirm guest Wi-Fi is separated from your staff and ministry network.

None of this requires technical expertise or a big budget, just the decision to act. The church has always been built on trust. Cybersecurity is how you protect that trust in a digital world.

References and sources:

1.    Email Phishing Scams Increasingly Target Churches (August 20, 2025) https://ministrywatch.com/email-phishing-scams-increasingly-target-churches/

2.    Top 5 Cyber Threats Churches Face in 2025 (September 22, 2025) https://enableministry.com/resources/top-5-cyber-threats-churches-face-in-2025/

3.    Cybersecurity and Social Media: How to Protect Your Church's Data - and Your Own by Sharon McDowell (July 27, 2023) https://www.mmbb.org/resources/church-executive-articles/2023/july/cybersecurity-and-social-media-how-to-protect-your-church-s-data-and-your-own-13

4.    10 Essential Steps to Secure Your Church's Social Media Accounts by Jeremy Katherman (August 9, 2023) https://missionalmarketing.com/10-essential-steps-to-secure-your-churchs-social-media-accounts/

5.    Cyber Threats Facing Churches Today and How to Defend Against Them by Kelsey Gonzalez (December 17, 2025) https://get.steeplemate.com/2025/12/17/cyber-threats-facing-churches-today-and-how-to-defend-against-them/

6.    Cybersecurity, Why Churches Are So Vulnerable (March 4, 2024; updated November 2025) https://www.acstechnologies.com/church-growth/cybersecurity-why-churches-are-so-vulnerable/

7.    Practical Cybersecurity Tips for Nonprofits by Joshua Peskay (January 6, 2026) https://candid.org/blogs/useful-cybersecturity-practices-for-nonprofits-prevent-data-breach/

8.    The 5 Best Password Managers for Nonprofits (2026 Review) by Timothy Ware (June 1, 2026) https://teampassword.com/blog/best-password-manager-for-nonprofits

9.    CISA Faith-Based Community Resources https://www.cisa.gov/audiences/faith-based-community

10. How to Protect Your Church or Ministry Against Cyberattacks (White Paper) https://www.guidestone.org/-/media/Landing-Pages/Property-and-Casualty/Cybersecurity-White-Paper.pdf

11. 2024 Internet Crime Report by FBI Internet Crime Complaint Center (2024) https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf

12. 2025 Cost of Data Breach Report by IBM Security (2025) https://www.ibm.com/reports/data-breach

13. Email Phishing Scams Increasingly Target Churches (August 2025) https://religionunplugged.com/news/2025/8/21/email-phishing-scams-increasingly-target-churches

14. Staying Safe on Social Networking Sites by CISA https://www.cisa.gov/news-events/news/staying-safe-social-networking-sites

15. Rising Tides: Kelley Misata on Bringing Cybersecurity to Nonprofits (May 2025) https://www.securityweek.com/rising-tides-kelley-misata-on-bringing-cybersecurity-to-nonprofits/


 

 


United Methodist Communications is an agency of The United Methodist Church

©2026 United Methodist Communications. All Rights Reserved