Skip to main content
Products Back
Solutions Back
Resources Back
Success Services Back
For Partners Back
Security Awareness

For Churches: Safeguard Your Congregation Phishing Simulator

Read 3 phishing emails targeting church staff and learn how to identify the red flags before they cost your organization.

How This Works

Below are three realistic phishing emails modeled after attacks that target churches. Read through each email and click on the numbered indicators to explore each red flag. Every indicator reveals an explanation of what makes that element suspicious and how to recognize it in your own inbox.
Email 1 of 3
Urgent — W-2 Files Needed Before EOD
P
Pastor David Mitchell <pastor.david.mitchell@gmail.com>
Spoofed sender
The sender address is a personal Gmail — not the church domain

Your pastor's real emails come from @gracecommunity.org.
This message comes from a free Gmail account that just uses the pastor's name. Always verify the actual email address, not just the display name.

to karen.thompson@gracecommunity.org · Mon, Jan 13, 2025 at 8:02 AM

Hi Karen,

I hope you’re doing well. I’m in a meeting with our insurance advisor right now and he’s asking for the W-2 forms for all staff members from last year. Could you send those over as a PDF to this email as soon as possible? He needs them before end of day.


Manufactured urgency

"As soon as possible" + "before end of day" creates artificial pressure

Phishing emails almost always create time pressure to prevent you from thinking critically or verifying the request. Legitimate requests for sensitive documents rarely demand same-day turnaround with no prior discussion.


Sensitive data request

W-2 forms contain Social Security numbers, salary data, and home addresses

W-2 forms are among the most valuable documents for identity theft. They contain everything a criminal needs: full legal names, SSNs, home addresses, and income data. No legitimate request would ask for these to be emailed as an unencrypted PDF.

Please don’t mention this to anyone else on staff yet — we’re working through some sensitive benefits changes and I’ll announce everything at the next team meeting.


Secrecy request

Don't mention this to anyone

This is the most dangerous element. By asking you not to tell anyone, the attacker eliminates the one thing that would expose the scam: you walking down the hall and asking Pastor David in person. Legitimate leadership never asks staff to secretly send tax documents.

Thanks so much for handling this quickly.

Blessings,

Pastor David

Sent from my iPhone
Email 2 of 3
HCM Provider — Payroll Processing Alert
Action Required: Verify Direct Deposit Information — Processing Suspended
H
HCM Workforce Notification <noreply@hcm-workforce-notify.com>
Fake domain
"hcm-workforce-notify.com" is not your payroll provider's real domain

Legitimate payroll providers send emails from their actual corporate domain. This uses a lookalike domain with extra words that sounds official but is entirely attacker-controlled. Always check: does the domain after the @ match your provider's actual website?

to karen.thompson@gracecommunity.org · Fri, Jan 10, 2025 at 6:47 AM
Strategic timing
Sent at 6:47 AM on a Friday — designed to catch you before you're fully alert

W-2 forms are among the most valuable documents for identity theft. They contain everything a criminal needs: full legal names, SSNs, home adPhishing emails are often timed for early mornings, Fridays, or just before holidays — moments when you're rushing, distracted, or worried about leaving something unresolved over a weekend. This is deliberate.

Dear Grace Community Church Payroll Administrator,

We’ve detected an anomaly in your organization’s direct deposit configuration. To prevent disruption to your next payroll cycle (scheduled 01/15/2025), you must verify your banking information within 24 hours.


Threat + deadline

"Within 24 hours" + payroll disruption threat exploits your sense of responsibility

Church administrators feel personally responsible for their colleagues’ pay. This email weaponizes that care — making you feel that your coworkers won’t get paid if you don’t act immediately. Real payroll providers don’t threaten service suspension via a single email with a 24-hour window.

Verify Direct Deposit Now →


Malicious link

This button leads to a credential-harvesting page, not your payroll provider

The link goes to hcm-workforce-notify.com — the fake domain. It will show a convincing replica of your provider’s login page and capture your username and password. Never click links in unexpected emails. Instead, open a new browser tab and go directly to your provider’s website.

https://hcm-workforce-notify.com/verify/gc-church

If this issue is not resolved within 24 hours, direct deposit processing will be suspended and all payments will revert to paper checks, which may delay employee compensation by 5–7 business days.

Reference: CASE-2025-GCC-44891

This is an automated message from HCM Workforce. Do not reply to this email. © 2025 HCM Provider, LLC.
Email 3 of 3
Internal Revenue Service — Tax Exempt & Government Entities Division
Notice: Annual Tax-Exempt Status Review — Response Required
I
IRS Tax Exempt Division <te-review@irs-taxexempt-review.gov.com>
Deceptive domain
"irs-taxexempt-review.gov.com" is not a .gov address

This is the most sophisticated trick in this email. The domain ends in .gov.com — which looks like a government address at a glance but is actually a regular commercial domain. Real IRS emails come from @irs.gov (a true .gov domain). The extra .com at the end means anyone could have registered it.

to karen.thompson@gracecommunity.org · Wed, Jan 8, 2025 at 2:15 PM

RE: Grace Community Church — EIN 84-2991037

Dear Responsible Party,

As part of our annual compliance review for 501(c)(3) organizations, we require verification of your organization’s financial records for the fiscal year ending December 31, 2024. Failure to respond within 14 business days may result in a formal examination of your tax-exempt status.


Existential threat

Losing 501(c)(3) status would be catastrophic for a church — donors lose their tax deductions, the organization owes back taxes, and operations may become unsustainable. The attacker knows this is the single most terrifying threat for a church administrator, and uses it to override your judgment.

Please upload the following documents to our secure review portal:

• Form 990 or 990-EZ (most recent filing)
• Bank statements (January–December 2024)
• Donor records exceeding $5,000
• Board of Directors meeting minutes


Massive data harvest

Bank statements, donor records, and board minutes — far beyond any real IRS request

The IRS already has your Form 990 (you filed it). They would never ask for bank statements, donor records, and board minutes via email. This request is designed to harvest your church’s complete financial profile — donor identities, account numbers, and internal governance documents.

Access Secure Upload Portal →

https://irs-taxexempt-review.gov.com/upload/gc-church

This review is conducted under IRC Section 7611. Non-compliance may result in revocation of tax-exempt status under IRC Section 501(c)(3).


Fake legal citations

Real IRC section numbers used to create false authority

IRC Section 7611 and Section 501(c)(3) are real parts of the tax code. Including them makes the email feel legally authoritative. But quoting real law doesn’t make the email real — it just means the attacker did their homework. The IRS initiates examinations by certified mail, never by email with a link.

IRS Tax Exempt & Government Entities Division | 1111 Constitution Ave NW, Washington, DC 20224
Icons32x32 (2) data risk icon (3)

Keep Your Team Safe

Download a one-page reference checklist your staff can use to identify phishing emails — designed for church and nonprofit organizations.
Phishing Email Red Flag Checklist · PDF · Free

Protect Your Organization

If you'd like to learn how APS supports workforce security for churches and faith-based organizations, schedule a demo with our team.

Schedule a Demo

No commitment required