Church Wire Fraud and Business Email Compromise

The most expensive church fraud today rarely involves a stolen offering. It involves an email. A bookkeeper receives what looks like a routine message from the pastor, a contractor, or a familiar vendor, asking to update payment details or approve a transfer. The money leaves by wire or ACH, and by the time anyone notices, it is gone.

What business email compromise is

Business email compromise is a fraud in which an attacker impersonates a trusted person by email, or takes over a real mailbox, and persuades someone at the organization to send money or change payment instructions. It relies on deception rather than hacking, which is why most standard coverage does not respond.

This matters because church finance often runs on trust and a small number of people. A single bookkeeper with payment authority and an email request that looks legitimate is the entire attack surface.

The three versions churches actually see

SchemeHow it arrivesTypical loss
Vendor payment redirectA contractor or supplier emails new banking details mid projectThe largest losses, often a full construction or roofing draw
Pastor or executive impersonationAn urgent request from leadership to wire funds or buy gift cards, usually while they are travelingSmaller but frequent, and often repeated before it is caught
Payroll diversionA staff member appears to request a change to direct depositOne or two pay cycles before it surfaces

Why the standard policy usually does not pay

Churches assume crime coverage or employee dishonesty handles this. Usually it does not. Employee dishonesty covers theft by your own people. Computer fraud coverage often requires an actual unauthorized system intrusion. Business email compromise involves an authorized employee voluntarily sending money after being deceived, which many forms treat as a separate peril called funds transfer fraud, social engineering fraud, or deception fraud.

That coverage frequently must be added by endorsement, and when it is included it often carries a low sublimit, commonly in the range of ten thousand to one hundred thousand dollars, well below what a redirected construction payment can cost. Check the declarations page for a named social engineering or funds transfer sublimit. If you do not see one, assume you do not have it.

The controls that actually stop it

Insurers increasingly require these, and they work regardless of coverage.

Verify every banking change by phone, using a number you already have on file, never a number in the email. Require dual authorization for any transfer above a set threshold. Treat urgency as a warning sign rather than a reason to hurry, since manufactured time pressure is the core of the technique. Enable multifactor authentication on every church email account. And confirm any request that arrives while leadership is traveling, which is precisely when attackers strike.

Imagine a church midway through a roof project that receives updated wire instructions from what appears to be the contractor's office manager. One phone call to the number on the signed contract ends the entire attempt.

Common questions

Does church insurance cover wire fraud?
Often not by default. Losses from deception usually require a social engineering or funds transfer fraud endorsement, which is separate from employee dishonesty and computer fraud coverage.

What is the difference between employee dishonesty and social engineering coverage?
Employee dishonesty covers theft committed by your own staff or volunteers. Social engineering coverage responds when an authorized person is tricked into sending money to an outsider.

How much social engineering coverage should a church carry?
Enough to cover your largest routine payment, which for most churches means the biggest contractor draw or payroll run rather than a small default sublimit.

What is the single best control against church wire fraud?
Verify every change to banking details by calling a phone number you already had on file, never one supplied in the email requesting the change.

If you would like a second opinion on whether your church carries social engineering or funds transfer coverage, contact us for a free church risk assessment.

Contact Hale Street Insurance at 978.712.0111 or [email protected] for a free church insurance review. You can also visit our church insurance page or request a quote to get started.


Jake Lubinski is the founder of Hale Street Insurance and a licensed insurance broker with years of church board and stewardship experience. Based in Boxford, MA he works with churches throughout Massachusetts and the US to build insurance and risk programs designed around how ministry actually operates. Reach Jake at [email protected] or 978.712.0111.


Related reading: Church Embezzlement Prevention | Church Cyber Liability Insurance | Church Insurance Sublimits | Church Benevolence Fund Governance

Previous
Previous

Winter Prep for New England Church Buildings: Ice Dams, Frozen Pipes, and Snow Load

Next
Next

Insurance for Religious Organizations Beyond Churches