Imagine leaving your church's front doors wide open, the offering unlocked, and a list of congregants' home addresses pinned to the bulletin board on a night when thieves are working the neighborhood. That's not hypothetical. For many churches, it's the current state of digital security.
Cybercriminals target churches because they're trusted institutions with public contact info, regular financial transactions, and rich personal data, but usually no dedicated IT security staff. Nearly 43% of cyberattacks in North America now target ministries and nonprofits, and phishing alone cost victims $70 million in 2024, up from $18.7 million the year before.
This article is for communicators, administrators, pastors, and volunteers managing your church's digital presence, often without formal tech training. You don't need a cybersecurity degree to reduce risk dramatically. You need practical knowledge, good habits, and a few inexpensive tools.
Why Churches Are Targets
Churches operate in what researchers call "high-trust, low-tech environments." Congregations trust leadership completely, and attackers exploit that trust.
By the numbers: 43% of North American cyberattacks target nonprofits/ministries; 193K+ phishing complaints hit the FBI in 2024; phishing losses nearly quadrupled year-over-year; 34% of church staff fail phishing simulations (among the highest of any sector); it takes an average of 241 days to identify a breach; and 70% of nonprofits have no formal cybersecurity policy even though 60% report an attack in the past two years.
Structural weaknesses compound the risk: staff emails are publicly listed, volunteers with little security training manage critical systems and rotate frequently, and church management software holds a goldmine of names, addresses, and giving records - the same sensitive data that banks hold - often without equivalent protection.
Five Attacks Hitting Churches Now
1. Staff Business Email Compromise - An attacker tricks a staff member out of their password and MFA code, then quietly emails vendors and congregants from the hijacked account.
2. Vendor Email Compromise - A vendor's email is hijacked, and the attacker requests a payment redirect to "new banking information."
3. Pastor/Executive Impersonation - A text or email appears to come from the senior pastor, urgently requesting gift cards. Authority plus urgency overrides critical thinking.
4. Church Management System (ChMS) Compromise - Stolen login credentials expose your entire congregant directory for targeted follow-on attacks.
5. Ransomware - Attackers encrypt your data and threaten to leak congregant information if you refuse to pay.
In one 2025 case, a North Carolina pastor had to warn his congregation after a near-identical spoofed email began soliciting gift-card donations. The same scam hit multiple Georgia churches simultaneously. This is common, not rare.
Phishing: The Everyday Threat
Phishing succeeds not through technical sophistication but through psychological manipulation that exploits fear, greed, and empathy. Church-targeted phishing is personal and plausible: "quick favor" emails from the pastor, urgent vendor wire-redirect requests, fake donation pages, and texts asking you to "handle something discreetly."
Red flags: slightly misspelled sender addresses, unusual urgency or secrecy, any request involving gift cards or wire transfers, unexpected links/attachments, and messages that just feel "off."
The one rule that stops most attacks: if an email requests money, credentials, or urgent action, call the sender using a number you already know, never one from the email.
Passwords and MFA
Weak or reused passwords are the most common entry point for attackers. Strong passwords are 16 or more characters, mix character types, and are unique per account. Password managers such as 1Password and Bitwarden, many of which offer nonprofit pricing, generate and store these automatically, and instantly revoke access when someone leaves.
Multi-factor authentication (MFA) is your single best free defense - it blocks over 99.9% of account compromise attempts. Even a stolen password is useless without the second factor. Authenticator apps are the sweet spot for most churches; hardware security keys are the gold standard for high-value accounts like email. Enable MFA first on email, then social media, ChMS, giving platforms, and cloud storage.
Social Media and Email Habits
Protect social accounts by auditing admin access regularly, using a generic church email as the top-level admin, enabling MFA for every team member, and requiring a signed social media use agreement. Revoke outdated third-party app permissions and monitor for unusual login activity. For email: never click links in unsolicited messages, forward suspicious emails to a tech lead, use web filtering, and always verify unusual requests by phone.
Data Minimization
The simplest defense is not having data to lose. As Candid's Joshua Peskay puts it, "Your liability for protecting data never decreases even as its value does." In other words, you can't suffer a breach of data you don't have. Create a data retention policy, delete outdated sensitive spreadsheets, and limit ChMS access to those who genuinely need it.
Network Basics
Keep guest Wi-Fi separate from the network running your ChMS and giving platform. Enable automatic software updates, avoid public Wi-Fi for sensitive tasks, and run endpoint protection on all church devices.
Building a Culture of Security
Every source agrees: training is the single best investment a church can make. Use real church scenarios, run periodic simulated phishing tests, repeat training regularly, and build a "pause and verify" culture. Require signed use agreements at onboarding and establish a no-blame reporting process so staff report mistakes instead of hiding them.
Free Resources
- CISA - Faith-Based Community resources: cisa.gov/audiences/faith-based-community
- GuideStone - free white paper on protecting churches from cyberattacks: guidestone.org
- Sightline Security - nonprofit-focused cybersecurity guidance
Five Things to Do
- Turn on MFA for church email and social media.
- Audit who has access to social accounts and your ChMS; remove anyone who no longer needs it.
- Choose a password manager and start phasing out reused passwords.
- Brief staff on the "quick favor" gift card scam and the vendor wire-redirect scam.
- Confirm guest Wi-Fi is separated from your staff and ministry network.
None of this requires technical expertise or a big budget, just the decision to act. The church has always been built on trust. Cybersecurity is how you protect that trust in a digital world.
References and sources:
1. Email Phishing Scams Increasingly Target Churches (August 20, 2025) https://ministrywatch.com/email-phishing-scams-increasingly-target-churches/
2. Top 5 Cyber Threats Churches Face in 2025 (September 22, 2025) https://enableministry.com/resources/top-5-cyber-threats-churches-face-in-2025/
3. Cybersecurity and Social Media: How to Protect Your Church's Data - and Your Own by Sharon McDowell (July 27, 2023) https://www.mmbb.org/resources/church-executive-articles/2023/july/cybersecurity-and-social-media-how-to-protect-your-church-s-data-and-your-own-13
4. 10 Essential Steps to Secure Your Church's Social Media Accounts by Jeremy Katherman (August 9, 2023) https://missionalmarketing.com/10-essential-steps-to-secure-your-churchs-social-media-accounts/
5. Cyber Threats Facing Churches Today and How to Defend Against Them by Kelsey Gonzalez (December 17, 2025) https://get.steeplemate.com/2025/12/17/cyber-threats-facing-churches-today-and-how-to-defend-against-them/
6. Cybersecurity, Why Churches Are So Vulnerable (March 4, 2024; updated November 2025) https://www.acstechnologies.com/church-growth/cybersecurity-why-churches-are-so-vulnerable/
7. Practical Cybersecurity Tips for Nonprofits by Joshua Peskay (January 6, 2026) https://candid.org/blogs/useful-cybersecturity-practices-for-nonprofits-prevent-data-breach/
8. The 5 Best Password Managers for Nonprofits (2026 Review) by Timothy Ware (June 1, 2026) https://teampassword.com/blog/best-password-manager-for-nonprofits
9. CISA Faith-Based Community Resources https://www.cisa.gov/audiences/faith-based-community
10. How to Protect Your Church or Ministry Against Cyberattacks (White Paper) https://www.guidestone.org/-/media/Landing-Pages/Property-and-Casualty/Cybersecurity-White-Paper.pdf
11. 2024 Internet Crime Report by FBI Internet Crime Complaint Center (2024) https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf
12. 2025 Cost of Data Breach Report by IBM Security (2025) https://www.ibm.com/reports/data-breach
13. Email Phishing Scams Increasingly Target Churches (August 2025) https://religionunplugged.com/news/2025/8/21/email-phishing-scams-increasingly-target-churches
14. Staying Safe on Social Networking Sites by CISA https://www.cisa.gov/news-events/news/staying-safe-social-networking-sites
15. Rising Tides: Kelley Misata on Bringing Cybersecurity to Nonprofits (May 2025) https://www.securityweek.com/rising-tides-kelley-misata-on-bringing-cybersecurity-to-nonprofits/