What Your Church Needs to Know About Email Spoofing

*Warning: Please exercise heightened caution when responding to requests for member directories, particularly those received via email. Spoofers may send a general inquiry to an office administrator while impersonating a member. If the directory is provided in response, they can gain access to the organization’s full email distribution list. Similar incidents have occurred within partner organizations and highlight the importance of verifying such requests before sharing directory information.

 

Recently, some of our clients received a threatening email that appeared to come from a legitimate source, warning that their website would be taken down unless they complied with certain demands. We want to be direct with you: this was a scam. Your site was not in danger. But the experience is a good reminder that these kinds of attacks are becoming more common, more sophisticated, and more targeted, and your ministry deserves to understand why.

Here’s what happened, how these attacks work, and what you can do to protect yourself and your congregation.

What Is Email Spoofing?

Email spoofing is when someone sends an email that appears to come from a trusted source (a vendor, a colleague, or even your own organization) but is actually from a bad actor. The “From” name and address can be forged to look convincing, even if the message originates from a completely different server.

In the case of what our clients experienced, the scammers likely:

  1. Scraped publicly available websites to build a list of ministry and church organizations
  2. Collected email addresses listed on those sites (contact forms, staff pages, footer info)
  3. Sent mass threatening emails designed to create panic and prompt a quick reaction: clicking a link, paying a fee, or handing over credentials

This is sometimes called a phishing attack when it’s fishing for information or access, or a scareware campaign when the goal is fear-based compliance. Either way, the goal is the same: get you to act before you think.

How AI Makes These Attacks Easier and More Convincing

A few years ago, a scam email was easy to spot: awkward phrasing, obvious spelling errors, vague threats. That’s no longer reliable as a filter.

Today, AI tools allow bad actors to:

  • Scrape and organize large amounts of data quickly. AI-powered bots can visit thousands of websites in minutes, harvesting email addresses, staff names, phone numbers, and organizational details. What once took significant manual effort now takes moments.
  • Craft personalized, professional-sounding messages. Using AI writing tools, scammers can generate emails that sound authoritative, urgent, and even familiar, addressing your organization by name, referencing your website, or mimicking the tone of a legal notice.
  • Scale attacks cheaply. Sending threatening emails to thousands of organizations simultaneously costs almost nothing. Your ministry doesn’t have to be individually targeted; you may simply be one of thousands caught in the same sweep.
  • Bypass spam filters. AI-generated text often avoids the obvious trigger words that spam filters look for, making these messages more likely to land in your inbox.

This is why the bar for “this looks legitimate” has changed. A well-written email is no longer enough proof that it’s real.

Why What You Put on Your Website Matters

Your website is a gift to your congregation and community, and it should be. But it also functions as a public-facing data source, and the information you include can be harvested and used in ways you didn’t intend.

Here are some things worth being thoughtful about:

  • Email addresses displayed in plain text are the easiest for bots to scrape. A contact page with pastor@yourchurch.org displayed openly is a direct invitation to any bot crawling the web. Consider using a contact form instead of a bare email address, or use a simple obfuscation method like pastor [at] yourchurch [dot] org.
  • Staff names and roles can be used to make phishing emails feel personal. A scammer who knows your pastor’s name, your worship director’s role, and your church’s location can craft a message that feels uncomfortably specific.
  • Phone numbers and physical addresses are generally fine to list (and necessary for community trust), but be aware they can appear in data compilations and be used to add legitimacy to a scam.
  • Generic “Contact Us” forms with spam protection (like a CAPTCHA) are a much safer way to receive inquiries while keeping your direct contact information off the open web.

None of this means you should strip your site of all personal information; that would undermine the very warmth and accessibility that draws people to your ministry. It means being intentional about what’s visible and why.

How to Detect a Fraudulent Email

When an email arrives that feels threatening, urgent, or “off,” here’s a framework to help you evaluate it:

  • Pause before you act. Scammers rely on urgency. Any email demanding immediate action, especially involving payment, credentials, or account access, should be slowed down, not sped up.
  • Check the actual sender address. The display name might say “Worship Times Support” or “Google Security Team,” but the real email address (usually visible by hovering over or clicking the sender name) will often reveal something quite different, like service@randomdomain.xyz.
  • Look for pressure tactics. Legitimate companies do not threaten to delete your website within 24 hours unless you pay. Legitimate vendors don’t ask for gift cards or wire transfers. If it reads like a threat designed to make you panic, treat it as a red flag.
  • Search for the message content online. Copy a distinctive phrase from the suspicious email and search it in quotes on Google. Scam campaigns send the same message to thousands of people, and often others have already reported it.
  • Contact the supposed sender through a known, trusted channel. If an email claims to be from your hosting company or a vendor, don’t reply to that email. Go directly to the company’s official website and contact them through their published support channels.
  • Trust your instincts. If something feels wrong, it probably is. This is especially true of emails that seem to “know” details about your organization; that specificity is often designed to disarm your skepticism.

What You Should Do If You Receive a Threatening Email

  • Do not click any links or attachments in the suspicious email.
  • Do not reply, even to “unsubscribe” or demand to be removed. Replies confirm your address is active.
  • Forward it to us if it references your Worship Times website. We can help verify its legitimacy.
  • Report it to the FTC at reportfraud.ftc.gov or forward phishing emails to reportphishing@apwg.org.
  • Alert your team. If you received it, others in your organization may have too.

A Word of Encouragement

We know how unsettling it is to receive a message threatening something you’ve worked hard to build. Your website is an extension of your ministry, and the thought of it being used against you is deeply frustrating.

Here’s the truth: these attacks are largely indiscriminate. You were not singled out because of anything you did wrong. You were caught in a wide net cast by someone looking for easy targets. The best response is not fear; it’s information.

We’re committed to helping you steward your online presence wisely, and we’re always here when something doesn’t feel right.

Have questions about your website’s security or want a review of what contact information you’re displaying publicly? Reach out to the Worship Times team; we’re glad to help.

Leave a Reply

    Stay in the Loop
    You will receive occasional emails such as:
    New Features | Announcements | Special Offers | Exciting Projects

    Related Posts

    What Church Communicator’s Google the Most

    What Church Communicator’s Google the Most

    Churches most often google questions about their communications relating to defining their strategy, engaging their community, and using digital channels effectively. Many questions reflect a need for clear, consistent messaging…
    Read more
    What should church communicators be asking AI?

    What should church communicators be asking AI?

    We asked AI, “what are the three most common and frequent requests from church communicators?”: Social media captions Email rewriting Sermon series descriptions What should church communicators be asking ChatGPT…
    Read more

    Copyright © 2008 - 2026. Worship Times. All rights reserved.