Offensive awareness / Defensive readiness

Understand What You Are Defending Against.

Common attack patterns and emerging AI risks, translated into ministry scenarios and concrete defensive practices. Use this guide to start a leadership discussion—and an assessment to understand your actual exposure.

A defense that keeps learning

A Familiar Message
Can Carry an Unfamiliar Risk.

AI can help criminals produce persuasive messages and imitate voices. Other attacks exploit account settings, software weaknesses, or ordinary process gaps. The right response combines secure configuration with staff who know how to verify, report, and escalate.

These are illustrative church scenarios, not a ranking of incident frequency or claims about attacks against a particular congregation. Controls must be configured for your actual systems; no single setting prevents every technique.

Social engineering

AI-Assisted Phishing & Pastor Impersonation

Offensive approach

A polished message imitates a pastor, colleague, or trusted vendor and creates urgency around a payment, document, or account request.

Defensive position

Verify unusual requests through a known independent channel. Use a clear reporting process, safer email settings, and phishing-resistant sign-in methods where supported.

What is at stake: Misuse of staff trust, stolen sign-ins, or diverted church funds.

AI impersonation

Voice Cloning & Deepfake Requests

Offensive approach

A convincing voice or video appears to come from someone in authority and asks staff to bypass a normal process.

Defensive position

Treat a familiar voice as insufficient verification. Call back using an established number and require an independent approver for sensitive changes.

What is at stake: Fraudulent transfers or disclosure of confidential information.

Cloud identity

Account, Session & App-Consent Theft

Offensive approach

A deceptive sign-in, unexpected approval prompt, or malicious connected app can grant access to email and shared information. Device-code lures and other techniques can target authentication tokens rather than passwords.

Defensive position

Prefer phishing-resistant MFA; limit app consent and administrative privileges; review sign-in evidence; and prepare procedures to revoke access and investigate suspicious sessions.

What is at stake: A real church account becomes a platform for further fraud.

Operational disruption

Ransomware & Data Extortion

Offensive approach

An intruder disrupts access to files or systems and may threaten to expose stolen information to pressure the church.

Defensive position

Maintain supported systems and endpoint protection, restrict privileges, separate critical networks, protect backups, and test recovery with an approved sample.

What is at stake: Interrupted ministry, recovery costs, and exposure of sensitive records.

Financial fraud

Invoice, Payroll & Giving Diversion

Offensive approach

A false bank-change request, compromised mailbox, or substituted giving link redirects money while appearing routine.

Defensive position

Use dual approval, independent callbacks, verified giving destinations, and review of administrator changes. Require the same controls even for senior leaders.

What is at stake: Loss of donations, payroll, or vendor payments.

Public trust

Website & Social Account Takeover

Offensive approach

Weak administrator access or neglected software gives an attacker control of ministry pages, messages, or donation destinations.

Defensive position

Secure and inventory administrators; keep software supported; document domain and account recovery; and restrict vendor access to what the work requires.

What is at stake: Fraudulent content, damaged credibility, and interrupted communications.

Third-party access

Vendor & Connected-Device Exposure

Offensive approach

Excessive vendor access or an exposed connected system becomes an entry point into systems it should not be able to reach.

Defensive position

Inventory third parties and devices, separate guest and operational networks, use time-bounded access, and name owners for updates and recovery.

What is at stake: One weak connection creates a wider ministry problem.

Emerging AI risk

Unsafe AI Tools & Connected Agents

Offensive approach

Sensitive information can leave approved systems through a prompt or connected app. Untrusted content may also try to influence an AI assistant’s actions.

Defensive position

Approve tools and data use, minimize connector permissions, keep confidential records out of unapproved services, and require human approval for sensitive actions.

What is at stake: Unintended disclosure or unauthorized changes made through automation.

A shared staff response

Pause. Verify. Report.

Pause the request.

Do not let urgency override the normal approval or sign-in process.

Verify independently.

Use a known number or established channel, and involve the required approver.

Report promptly.

Contact your designated church or IT lead. If you already clicked or approved something, report that too.

Build a Defense Worthy of Your Mission.

Start with a clear view of your risks, a practical plan, and the right preparation for your people.

Start a Conversation