For Churches: Safeguard Your Congregation Phishing Simulator
Read 3 phishing emails targeting church staff and learn how to identify the red flags before they cost your organization.
Hi Karen,
I hope you’re doing well. I’m in a meeting with our insurance advisor right now and he’s asking for the W-2 forms for all staff members from last year. Could you send those over as a PDF to this email as soon as possible? He needs them before end of day.
Manufactured urgency
Phishing emails almost always create time pressure to prevent you from thinking critically or verifying the request. Legitimate requests for sensitive documents rarely demand same-day turnaround with no prior discussion.
Sensitive data request
W-2 forms are among the most valuable documents for identity theft. They contain everything a criminal needs: full legal names, SSNs, home addresses, and income data. No legitimate request would ask for these to be emailed as an unencrypted PDF.
Please don’t mention this to anyone else on staff yet — we’re working through some sensitive benefits changes and I’ll announce everything at the next team meeting.
Secrecy request
This is the most dangerous element. By asking you not to tell anyone, the attacker eliminates the one thing that would expose the scam: you walking down the hall and asking Pastor David in person. Legitimate leadership never asks staff to secretly send tax documents.
Thanks so much for handling this quickly.
Blessings,
Pastor David
Dear Grace Community Church Payroll Administrator,
We’ve detected an anomaly in your organization’s direct deposit configuration. To prevent disruption to your next payroll cycle (scheduled 01/15/2025), you must verify your banking information within 24 hours.
Threat + deadline
Church administrators feel personally responsible for their colleagues’ pay. This email weaponizes that care — making you feel that your coworkers won’t get paid if you don’t act immediately. Real payroll providers don’t threaten service suspension via a single email with a 24-hour window.
Verify Direct Deposit Now →
Malicious link
The link goes to hcm-workforce-notify.com — the fake domain. It will show a convincing replica of your provider’s login page and capture your username and password. Never click links in unexpected emails. Instead, open a new browser tab and go directly to your provider’s website.
https://hcm-workforce-notify.com/verify/gc-church
If this issue is not resolved within 24 hours, direct deposit processing will be suspended and all payments will revert to paper checks, which may delay employee compensation by 5–7 business days.
Reference: CASE-2025-GCC-44891
RE: Grace Community Church — EIN 84-2991037
Dear Responsible Party,
As part of our annual compliance review for 501(c)(3) organizations, we require verification of your organization’s financial records for the fiscal year ending December 31, 2024. Failure to respond within 14 business days may result in a formal examination of your tax-exempt status.
Existential threat
Losing 501(c)(3) status would be catastrophic for a church — donors lose their tax deductions, the organization owes back taxes, and operations may become unsustainable. The attacker knows this is the single most terrifying threat for a church administrator, and uses it to override your judgment.
Please upload the following documents to our secure review portal:
• Form 990 or 990-EZ (most recent filing)
• Bank statements (January–December 2024)
• Donor records exceeding $5,000
• Board of Directors meeting minutes
Massive data harvest
The IRS already has your Form 990 (you filed it). They would never ask for bank statements, donor records, and board minutes via email. This request is designed to harvest your church’s complete financial profile — donor identities, account numbers, and internal governance documents.
Access Secure Upload Portal →
https://irs-taxexempt-review.gov.com/upload/gc-church
This review is conducted under IRC Section 7611. Non-compliance may result in revocation of tax-exempt status under IRC Section 501(c)(3).
Fake legal citations
IRC Section 7611 and Section 501(c)(3) are real parts of the tax code. Including them makes the email feel legally authoritative. But quoting real law doesn’t make the email real — it just means the attacker did their homework. The IRS initiates examinations by certified mail, never by email with a link.
Keep Your Team Safe
Protect Your Organization
If you'd like to learn how APS supports workforce security for churches and faith-based organizations, schedule a demo with our team.
Schedule a DemoNo commitment required