Church Cyber Liability and the Gift Card Scam Every Ministry Sees
Ministry Insured Team · 7/14/2026

Almost every congregation we work with has received the email: a message that looks like it came from the pastor, asking a bookkeeper or member to buy gift cards quietly, or a vendor requesting that this month's payment go to a new account number. These are not sophisticated attacks. They are cheap, high-volume social engineering — and churches are targeted precisely because they are trusting and often thinly staffed.
The three losses that actually happen
Funds transfer fraud. Someone at the church is deceived into sending money to a criminal's account. Recovery after 24 hours is rare.
Data breach. Donor records, member directories, background check files, payroll data and preschool rosters all sit in church systems. A breach triggers notification obligations, credit monitoring costs and, in some states, regulatory exposure.
Ransomware. Membership, giving and A/V systems locked until payment, with the real cost usually in downtime and restoration rather than the ransom itself.
Controls that stop most of it
Require dual authorization for any payment over a set threshold, and verify every change of bank details by phone at a number you already have on file — never a number in the email. Turn on multi-factor authentication for email, banking, giving platforms and the church management system. Train staff and volunteers to look at the actual sending address, not the display name. Keep offline backups and test a restore at least once a year. Limit who can access donor and background check data.
What insurance covers
Cyber liability typically responds to breach response and notification, forensics, credit monitoring, ransomware and business interruption, and liability to affected individuals. Crime or employee dishonesty coverage responds to theft by an insider and, when the endorsement is present, to social engineering and funds transfer fraud. That last point matters: many church programs carry crime coverage that expressly excludes voluntary transfers induced by deception unless a social engineering endorsement is added. Check the sublimit — it is often far lower than the policy limit.
Also review your financial controls
Two signatures on checks. Counting teams of at least two unrelated people. Monthly bank reconciliation performed by someone who does not write checks. Annual review of the books by an outside party. Carriers look favorably on these, and they prevent far more loss than any policy pays.
Ask us for a cyber review
Call the Ministry Insured program team at 800-318-6717 and we will show you exactly what your current policy would and would not pay after a fraudulent transfer.