Home Communications Directories, scammers, and gift cards, oh my!

Directories, scammers, and gift cards, oh my!

0
10

Many of us can recall a time when we received a message that felt a little off. An email from “the pastor” or “the bishop” asking for a favor, a text about a gift card, a request that seemed urgent but didn’t quite sound like the person it claimed to be. Online fraud is a real and growing concern, and the church is not exempt from it.

Churches and other nonprofits are common targets. We are open, welcoming, and generous by nature, and we tend to assume the best of people. Those are good things, yet they are exactly the qualities fraudsters hope to exploit. Many of the most common schemes rely on relationships. A message that appears to come from a trusted pastor, a fellow member, or a conference staff person is meant to make us drop our guard. When we feel we know the sender, we stop asking questions.

Church directories and email lists are especially attractive. Even a simple list of names, addresses, and email accounts can give a bad actor what they need to make a fraudulent request sound convincing. Some churches in the conference have recently reported that people who appear to be fraudsters are contacting church offices to request a directory. The requests often sound polite and ordinary — “I visited last Sunday” —which is part of why they work.

If you host your directory online somewhere, consider whether it is sufficiently protected.

  • Does it have some level of protection? Is it sufficient?
  • Am I confident that everyone with access is trusted?
  • When was the password last updated?

Printed directories are less likely to be exploited, but care is warranted there as well.

The proliferation of fraud doesn’t call for fear or suspicion of one another. It does call for a little wisdom. Here are three practices that can help your congregation build resilience.

Help your people know how you communicate. Tell members plainly how the church and its leaders reach out: which email addresses are used, what the newsletter looks like, and which channels leaders will and will not use. Repeat it regularly, in the bulletin, in announcements, and on your website if you have one. A member who knows that “our pastor will never text asking for gift cards” is far harder to fool.

Decide how leaders will ask for benevolence, then stick to it. Fraudsters often pose as a church leader in need of urgent financial help, or as someone asking a leader to send money quickly. Settle on a clear practice for how requests for benevolence are made and approved, and tell your congregation what it is. Then follow it every time, even when the request feels pressing, and the person seems familiar. A consistent process protects your leaders as much as your members.

Train those who handle member information. Anyone on your staff or volunteer team who answers phones, responds to email, or has access to directories and contact lists should know how to protect that information. The Pacific Northwest Conference is formalizing a policy for its own staff, and its basic ideas could work just as well in a local church:

  • When in doubt, don’t share. No one will be faulted for saying, “I’m not able to share that directly, but I’d be glad to pass your message along.”
  • Ask who and why. Find out who the person is trying to reach and why, and take down their name and contact information.
  • Offer to relay the message. Pass it along to the person they are seeking using the contact information you already have, and let that person decide whether to respond.
  • Don’t confirm or deny. Avoid saying whether someone is a member or part of the church beyond what is already public.
  • Treat urgency as a warning sign. Pressure to act “right now” is a reason for more care, not less.
  • Trust your instincts and tell someone. If a request feels wrong, decline it, let your pastor or lead staff member know, and keep any related emails or notes.

Staff and volunteers should also know they are supported. No one should feel they’ll be in trouble for being careful, even if the request turns out to be legitimate.

No organization is immune to the bad actions of others, and the conference is no exception. We are working to improve our own practices and limit access to sensitive information. We offer these suggestions in the same spirit as fellow stewards of the trust that people place in us.

May we be, as Jesus said, “wise as serpents and innocent as doves” (Matthew 10:16), generous in our welcome and careful with what has been entrusted to us.

For additional advice on the topic, I’d recommend this recent, excellent post from the New York Annual Conference. It comes with a solid list of resources from the church and beyond to make our congregations safer in digital spaces.

Previous articleMicrosoft Publisher is set to retire. What now?
Patrick Scriven
Patrick Scriven is a husband who married well, a father of three amazing girls, and a seminary-educated layperson working professionally in The United Methodist Church. Scriven serves the Pacific Northwest Conference as Director of Communications.

Leave a Reply