These updates are shared to help raise the situational awareness of Faith-Based organizations to best defend against and mitigate the impacts from all-hazards threats including physical security, cybersecurity, and natural disasters.
A data-security incident at CAF Bank, a UK bank serving more than 14,000 charities, has raised concerns about how a cyber incident affecting a third-party technology provider can quickly become an operational problem for churches and other nonprofit organizations. CAF Bank detected suspicious activity involving a small number of accounts and subsequently identified what it described as a previously unknown vulnerability in third-party software used to connect to its online banking service. Although the bank said its core banking systems and customer funds remained secure, it suspended online banking while investigating and addressing the vulnerability. The disruption meant charities and churches had to rely on telephone banking for payments and other financial activity, creating significant delays and operational difficulties.
The incident is particularly notable because the impact extended beyond the suspected cyber activity itself. A parish priest described the resulting disruption as having a “ripple effect,” highlighting how the loss of access to normal banking services can affect routine charitable and church operations. CAF Bank reportedly increased staffing for telephone support, but customers still experienced difficulties accessing services. The situation demonstrates how an organization can maintain the security of funds while still experiencing substantial consequences from the availability and resilience of a critical service.
Analyst Comments: For faith-based organizations, the incident highlights how a disruption at a trusted third-party provider can quickly become an operational issue, even when the organization’s own systems and funds remain secure. Churches may depend on outside providers for banking, payroll, accounting, giving, and other essential services, creating dependencies that can be easy to overlook.
The situation also illustrates the importance of operational resilience alongside cybersecurity. Losing access to online banking can affect payroll, bills, vendors, and ministry activities even without a direct compromise of the church. The incident provides a useful example of how a third-party cyber issue can create a “ripple effect” across normal church operations.
Churches in Tangipahoa Parish, Louisiana, are increasingly being targeted for copper theft, with thieves stealing wiring and equipment from air-conditioning systems. At Antioch Baptist Church in Tickfaw, suspects were caught on surveillance video stealing copper wire on Mother’s Day, causing approximately $20,000 in damage; the church had also previously lost its entire air-conditioning unit to theft. Another local church was reportedly targeted three times during the summer before two suspects were arrested. Sheriff Gerald Sticker said churches can be particularly vulnerable because they are frequently unoccupied. Authorities are working to disrupt the market for stolen metals through a new state law requiring identification, fingerprinting, and delayed payment for copper sales.
Analyst Comments: Reports like these matter because copper theft can quickly become more than a property crime for a church. Damage to HVAC, electrical, or other building systems can create thousands of dollars in unexpected costs, disrupt worship and ministry activities, and leave facilities vulnerable while repairs are being made. The repeated targeting of churches in the same area also demonstrates how thieves may return to locations they know are accessible and frequently unoccupied.
Faith-based organizations can reduce exposure by looking at the areas where valuable materials and equipment are located, particularly HVAC units, electrical infrastructure, and exterior equipment. Placing lighting, cameras, fencing or physical barriers where appropriate, and regularly checking facilities when they are unoccupied can make theft more difficult and increase the likelihood of identifying suspicious activity. Churches can also coordinate with local law enforcement and neighboring congregations to share information when similar thefts are occurring in the area.
The FB-ISAO’s sponsor Gate 15 publishes a daily newsletter called the SUN. Curated from their open source intelligence collection process, the SUN informs leaders and analysts with the critical news of the day and provides a holistic look at the current global, all-hazards threat environment. Ahead of the daily news cycle, the SUN allows current situational awareness into the topics that will impact your organization.