
Quick Answer
Quick Answer: Church cybersecurity often fails because of six common assumptions: that no one would target a ministry, that members would spot a scam, that MFA alone protects accounts, that backups guarantee recovery, that security belongs to the IT volunteer, and that everyone would know what to do during an incident. Each one creates a blind spot that attackers actively look for.
For churches and faith-based organizations across Northern Virginia, Maryland, and Washington, DC, closing these gaps rarely requires a large budget. It requires replacing comfortable assumptions with a few verified facts, and October, Cybersecurity Awareness Month, is a natural time to start.
Key Takeaways
- Churches are targeted for their data and their culture of trust, not their size. In one confirmed case, criminals inside a parish’s email redirected $1.75 million in construction payments.
- Pastor impersonation scams are common enough that the Federal Trade Commission has issued consumer warnings about them.
- MFA is essential, but shared logins among staff and volunteers weaken it.
- A backup that has never been restored is an assumption, not a recovery plan.
- Security is shared by staff, volunteers, and leadership, not owned by one person.
Leadership Brief
Pastors, elders, and ministry leaders do not need to understand every technical detail to lead well on this.
Ask a simpler question:
If our member database, giving platform, or email were unavailable this Sunday, what would we do?
Think about online giving, child check-in, the livestream, the church management system, and the personal information your congregation has trusted you to protect.
If the answer is unclear, one of the myths below is probably shaping your current approach.
Why Are Churches a Target for Cybercriminals?
Churches are targeted because they hold sensitive personal and financial information while operating with small teams, volunteers, and limited security resources.
Member directories, giving histories, bank details for recurring gifts, pastoral care notes, prayer requests, and children’s check-in records often sit behind a lean staff and a modest budget. Attackers see high-value data and high trust behind low-resistance defenses.
This is not a distant problem. In 2019, criminals inside two staff email accounts at Saint Ambrose Catholic Parish in Brunswick, Ohio redirected about $1.75 million in construction payments to a fraudulent account, a case the FBI confirmed as a business email compromise.
Here are six myths that keep churches exposed, along with the truth behind each one.
Myth 1. No One Would Target an Organization Like Ours
The truth: attackers choose churches based on opportunity, not size or mission.
It is natural to assume a church or ministry is not worth an attacker’s time. There is no profit motive, the budget is modest, and the work is about serving people.
Attackers do not see it that way. Churches run on trust, small teams, and volunteers, which makes them easier to approach than a company with a dedicated security staff. Most attacks are automated or opportunistic, so they find whoever has an open door.
Fact: Attackers choose targets based on opportunity, not size or mission.
Myth 2. Our People Would Recognize a Scam
The truth: today’s scam messages are polished, personal, and often appear to come from the pastor.
The obvious scam email full of typos is largely gone. In faith communities, one of the most common versions is pastor impersonation: a quick note that appears to come from the pastor or a ministry leader asking a staff member, volunteer, or member to buy gift cards, update payment details, or handle something urgently and quietly. The Federal Trade Commission has warned worshippers directly about this pattern.
With AI, the writing itself is no longer a reliable warning sign. Behavior is. Pause if a message:
- Makes an unusual or urgent request
- Asks for gift cards or changes payment instructions
- Asks for member, donor, or financial information
- Includes a new or unexpected login link
If anything feels off, confirm by phone or in person using a number you already know, never one included in the message.
Fact: A convincing message, even one that seems to come from your pastor, can still be a scam.
Myth 3. MFA Fully Protects Our Accounts
The truth: multi-factor authentication is essential, but it is not a guarantee.
Attackers use a tactic called prompt bombing, sometimes known as MFA fatigue, flooding a phone with login requests until someone approves one just to make them stop.
Churches face an added challenge. Ministry email accounts, livestream logins, and church management systems are often shared among several staff members and volunteers. When one login belongs to many people, MFA approvals become routine, and routine approvals are exactly what attackers count on.
Fact: MFA works best as part of a broader approach, with individual accounts instead of shared ones.
Myth 4. Our Backups Have Us Covered
The truth: having backups is not the same as being able to recover.
If ransomware locked your systems tomorrow, could you restore your member records, giving history, and ministry files? How long would it take?
A backup only matters if it can be restored. Many organizations discover during an incident that backups were incomplete, outdated, or stored somewhere the attack also reached. Many churches also assume their church management system or giving vendor handles recovery for them, which is not always the case.
Fact: Having backups is not the same as being able to recover.
Myth 5. Cybersecurity Is the IT Volunteer’s Job
The truth: security decisions happen everywhere in the church, not just at the IT desk.
Many churches rely on a dedicated volunteer, a staff member who is good with technology, or an outside provider. Their help is valuable, but no one person can control every click across a congregation.
Security decisions happen in the church office, at the welcome desk, in the finance ministry, and on volunteers’ personal devices. Simple awareness training for staff and key volunteers makes a meaningful difference. When people know what to watch for and feel comfortable asking before acting, they become part of your protection.
Fact: A security-aware team protects the whole ministry.
Myth 6. We Know What to Do If Something Happens
The truth: most churches discover their response plan gaps during the incident itself.
It is Sunday morning. The check-in system will not load, the livestream will not connect, and the office cannot reach the member database. Many organizations discover in that moment that nobody has answered the basic questions:
- Should staff and volunteers shut down their computers?
- Who is called first, and who makes decisions?
- How do we communicate if email is unavailable?
- When does our insurance carrier or denomination need to be notified?
- Who speaks to the congregation, and how?
Those answers should be written down before they are needed.
Fact: Your response plan should not debut during an incident.
Eagle Insight
Five questions worth answering internally with your leadership team. These are for your own conversation.
- Where does our member, giving, and child check-in data live, and who can reach it?
- Which accounts are shared among staff or volunteers today?
- When were our backups last tested with an actual restore?
- Would staff, volunteers, and members know how to verify a request that appears to come from the pastor?
- If our systems were down on a Sunday, who would lead the response?
If several of these are hard to answer, that is useful information on its own.
A 6-Point Church Cybersecurity Check
Use this as a discussion framework for staff and leadership.
- Awareness: Do we understand why our church is a realistic target?
- Verification: Do staff and volunteers confirm unusual requests before acting?
- Accounts: Does each person have their own login, protected by MFA?
- Recovery: Have our backups been tested, not just scheduled?
- Shared responsibility: Have staff and key volunteers received basic security training?
- Response: Is our incident plan written down and known to the people who would use it?
There is no score here. The goal is to see which areas are in good shape and which deserve attention next.
AI Consideration
AI tools are showing up in church offices for sermon research, newsletters, and administrative work. They can save real time.
They also raise a practical question: what information is safe to enter into them? Member details, prayer requests, pastoral care notes, children’s records, and giving records should not be placed in AI tools your church has not reviewed and approved.
A short policy on which tools are allowed, and what information stays out of them, protects the trust your congregation places in you.
Frequently Asked Questions
Are churches really targeted by cybercriminals?
Yes. Churches hold personal, financial, and family information and often operate with small teams and volunteers. The FBI has confirmed cases such as a 2019 email compromise that cost an Ohio parish $1.75 million, and attackers target opportunity, not size or mission.
What is the most common cyber scam targeting churches?
Pastor impersonation is one of the most common. A message appears to come from a pastor or ministry leader asking for gift cards, payment changes, or sensitive information. Confirming unusual requests by phone or in person, using a number you already know, stops most of these.
Is MFA enough to protect church accounts?
MFA is essential but not sufficient on its own. It works best with individual accounts rather than shared logins, along with awareness training and tested backups.
How do we know if our church’s backups will work?
Only by testing them with an actual restore. A backup that reports success has not necessarily been proven to recover your member records, giving data, and ministry files.
Who is responsible for cybersecurity in a church?
Everyone who uses church systems shares responsibility, including staff, volunteers, and leadership. Technology support is important, but safe habits across the team are what prevent most incidents.
Where can churches find free cybersecurity guidance?
The Cybersecurity and Infrastructure Security Agency (CISA) publishes free resources and self-assessments for faith-based communities and houses of worship. The Federal Trade Commission also publishes guidance on spotting gift card and impersonation scams.
Who provides IT and cybersecurity support for churches in Northern Virginia, Maryland, and Washington, DC?
Eagle Tech Corp, based in Springfield, Virginia, provides managed IT and cybersecurity services for churches and faith-based organizations throughout Northern Virginia, Maryland, and Washington, DC, with support available in English and Spanish.
About Eagle Tech Corp
Eagle Tech Corp provides proactive Managed IT services, cybersecurity, Microsoft 365 management, and strategic technology consulting for churches and faith-based organizations throughout Northern Virginia, Maryland, and Washington, DC.
Founded by Eduard Lavilla, former CTO of the Organization of American States, and serving the DC Metro area since 2012, we help ministries protect member and giving data, support the systems that keep services and outreach running, and explain technology in clear, practical language, with assistance available in English and Spanish.
Cybersecurity Awareness Starts With the Facts
Myths are comfortable. They let a ministry feel protected without looking closer. Most gaps do not come from a missing product. They come from believing something is already handled when it is not.
If any of these myths sound familiar, it may be a good time to take a closer look at where your church stands.
Send us a note through the contact form and we will help you separate what is truly protecting your ministry from what only feels like protection, with no pressure and nothing to prepare in advance.
Sources
- Federal Trade Commission: Is that gift card helping your congregation or paying a scammer? (September 2024)
- Cybersecurity and Infrastructure Security Agency (CISA): Faith-Based Community resources
- FBI Cleveland: St. Ambrose Catholic Parish Was a Victim of a Business Email Compromise Scheme (April 2019)
- National Catholic Reporter: Hackers infiltrate Ohio parish’s email system, steal $1.75 million (April 2019)


