What a gift-card impersonation attempt inside a Bible Study Fellowship email chain teaches the rest of us about trust, exposure, and the personal connection that stops fraud.
Last week, my Bible Study Fellowship email chain filled up with requests for Amazon gift cards. It was a targeted impersonation attempt — someone borrowing the names and relationships inside our group to pry money out of a community built on generosity.
It didn’t work.
Discernment, not a dashboard
A whip-smart woman in her 70s spotted the request almost immediately. The tone was off. The behavior didn’t match the person supposedly sending it. She raised the alarm before anyone lost a dime.
No product caught this. No expensive security stack flagged it. It was stopped by people who know each other well enough to notice when something feels wrong — and who were willing to say so out loud.
So please don’t file this under “older women nearly scammed.” That is not what happened. A group of older women detected an adversary operating inside a trusted channel, challenged the abnormal behavior, and escalated fast enough to kill the attack before it matured into a loss. The criminals bet that generosity would move faster than judgment. They bet wrong.
Incident Analysis
I’ve spent more than two decades in adversary-informed military and cybersecurity operations. I also happen to prefer the company of older, wiser women — and I had their experience to draw on here. So here’s the honest assessment, the same one I shared with my whip-smart Bible study group.
Someone had enough relational information about our group to impersonate members convincingly. That is a fact. There are at least three ways an attacker ends up with what this one had, and only one of them is a corporate breach:
- A single compromised mailbox. If one member’s email account is taken over — through a reused password, a convincing phishing page, or an old credential exposed in someone else’s breach — the attacker inherits that person’s entire address book and message history. One inbox can expose an entire group.
- Publicly available information. Names, leaders, meeting locations, and group affiliations often sit in plain view on websites, bulletins, and social media. Reporting on these exact scams repeatedly shows criminals building convincing impersonations straight from public directories — no breach required.
- A breach of the organization holding the data. Possible. But possible is not confirmed, and there is no public disclosure or reporting of a breach at Bible Study Fellowship.
Why faith communities keep getting hit
The Federal Trade Commission has warned for years about scammers posing as pastors, rabbis, priests, imams, and bishops, asking worshippers to buy gift cards for a “worthy cause,” then demanding the number and PIN off the back. The FTC’s own guidance notes that these criminals use real leaders’ names — and sometimes your real name — to earn trust, and lean on urgency and secrecy (“a surprise staff-appreciation gift, so don’t tell anyone”) to rush you.
They work because faith communities run on exactly the things attackers exploit: volunteerism, hospitality, generosity, and trust between people who feel a moral responsibility toward one another. A member who believes a friend needs help moves faster than a member reading a cold invoice from a stranger. The attacker doesn’t need theology. They need a few minutes of borrowed trust.
Gift cards are the payment rail of choice because they’re fast, familiar, and nearly impossible to claw back once the codes are shared. At that point the card is just cash — with better laundering instructions. And no legitimate ministry, church, or nonprofit will ever need the back of a gift card transmitted like launch codes. That single detail is enough to end the conversation.
The pattern, so you can name it out loud
These campaigns are predictable once you’ve seen a few:
- The soft open — “Are you available?” or “I need a quick favor.” It tests whether you’ll engage.
- The constraint — “I’m in a meeting,” “I can’t talk right now,” “please keep this between us.” This isn’t small talk; it’s the control mechanism. It exists to stop you from calling the real person or looping in the group — the five-minute pause where most scams collapse.
- The ask — gift cards, a wire, a payment app, crypto. Always irreversible. With gift cards, always “scratch it off, photograph the code, send it over.”
Unexpected secrecy is a red flag. Urgency is a red flag. Any push to move off normal channels is a red flag. A demand for gift-card numbers, PINs, wires, or crypto is a red flag with a siren on top.
If you were exposed, here’s what to do
For members:
- Pause, call, confirm. If a request seems to come from a member or leader, verify it using a phone number you already trust — never the contact details inside the suspicious message. Even a real account that’s been compromised can send fraudulent mail, so always verify through a separate, known-good channel.
- Rotate your email password — and change it anywhere you reused it. Reused passwords are how one compromise quietly becomes ten.
- Turn on multi-factor authentication (MFA) everywhere it’s offered, starting with your email. It’s the highest-value fifteen minutes you’ll spend all year.
- Check for hidden mailbox rules. This is the step almost everyone misses: an attacker who gets into an inbox often sets up forwarding or filter rules so they keep reading your mail after you change the password. Open your email settings and delete any forwarding, auto-delete, or filter rules you didn’t create yourself.
- Watch for follow-on attempts. Being targeted once usually means you’ll be targeted again, sometimes from a new angle. Tell the group so everyone is watching together.
If money has already moved:
- Contact the gift-card issuer immediately and report the card as used in a scam. Speed is everything — sometimes funds can still be frozen.
- Report to the FTC at ReportFraud.ftc.gov.
- File with the FBI’s Internet Crime Complaint Center at IC3.gov.
- Warn your group and your organization so the next person is protected before they’re hit.
For organizations holding member data:
Directories, rosters, class assignments, and leader lists are sensitive information, because attackers treat them that way. Limit who can access and export them, require MFA for anyone with administrative access, and — if exposure is even suspected — send a short, plain-language warning fast. A three-sentence heads-up today beats a lawyered paragraph next week, after the list has already been tested.
The lesson
The most effective control in this story wasn’t technical. It was a group of people who knew each other well enough to notice when something was wrong — inside a culture where saying “this feels off” was welcomed instead of brushed aside. Discernment is part of your security model. Build it, name it, and reward it.
Countervail helps organizations, teams, and communities understand their cyber footprint, see how attackers exploit digitally collected information to create trust and prey on predictable human behavior, and train individuals to disrupt the scheme. If your church, business, or group wants to turn this kind of awareness into a repeatable defense, that’s exactly the conversation I want to have.
Joanna Wiggum is the founder and agency principal of Countervail, a veteran-owned, Washington State–licensed private investigation and adversary-informed cybersecurity agency, and President of Operation Child Shield. Enterprise-grade cybersecurity, made personal.
