Faith-Based Daily Awareness Post 6 October 2026

Faith-Based Security Headlines

These updates are shared to help raise the situational awareness of Faith-Based organizations to best defend against and mitigate the impacts from all-hazards threats including physical security, cybersecurity, and natural disasters.

 

Lincolnwood man ‘exploited the trust of the Orthodox Jewish religious community’ in alleged fraud scheme

 

The U.S. Securities and Exchange Commission has accused 27-year-old Lincolnwood resident Jacob Garfinkel and his Skokie-based company, 5G Funding, of misleading investors in a merchant cash advance operation that primarily solicited members of Orthodox Jewish communities in Illinois, New York, and New Jersey. The SEC alleges that Garfinkel raised approximately $4.5 million by claiming the business was highly profitable and that investors would share in its returns, while misrepresenting his experience and compensation, collecting $1.1 million in origination fees, and diverting about $1 million for personal expenses and transfers to related parties. The complaint says some of the diverted money was used for a home down payment, gambling, cars, and watches. Less than $1.7 million was returned, leaving investors with alleged losses of roughly $2.8 million; 22 of the 23 investors reportedly lost between $15,000 and $670,000. Garfinkel denies wrongdoing. The SEC is seeking repayment, civil penalties, and restrictions on his future sale of securities, while a possible parallel criminal investigation has not been publicly confirmed.

 

Analyst Comments: This case illustrates how affinity-based investment schemes can exploit trusted community relationships and reduce skepticism toward unverified financial claims. Faith-based organizations and community leaders should consider reinforcing the following messages to their congregants:

  • Treat personal, religious, or community trust as separate from financial due diligence.
  • Independently verify business performance, claimed investment experience, fees, and the intended use of funds.
  • Be cautious of opportunities promoted primarily through friends, neighbors, or word-of-mouth referrals.

 

Leaders should also establish clear reporting channels so suspected fraud can be reported privately and promptly without stigma or community pressure.

 

Prime Big Deal Days: scammers stock up early as Amazon impersonation attacks nearly triple

 

There will likely be a sharp increase in Amazon-themed phishing and impersonation attacks ahead of Prime Big Deal Days on October 6–7, 2026. KnowBe4 found that Amazon impersonation attacks increased 188% between late August and September, while Check Point identified a 42% increase in newly registered Amazon- and Prime Day-related domains since July. Attackers are using fake login pages, storefronts, delivery notifications, billing alerts, and promotional offers to steal credentials and payment information or distribute malware.

 

Threat actors are also using techniques to evade email security tools, including modified sender information, hidden characters, and cloned websites. Generative AI is making these scams harder to identify by enabling polished and personalized phishing messages without common spelling or grammar errors. The activity also affects financial services and retail organizations. Users should access Amazon directly through its official website or app, avoid unsolicited links, verify URLs and senders, enable MFA or passkeys, and be cautious of urgent account, delivery, or payment warnings.

 

Analyst Comments: The increase in Amazon impersonation activity highlights the continued effectiveness of trusted-brand phishing, particularly during high-volume shopping events.

 

Organizations may consider:

  • Reminding employees to access Amazon and other retail accounts directly through official websites or apps.
  • Encouraging employees to avoid clicking links in unsolicited emails or text messages, especially on work devices.
  • Reinforcing MFA or passkey use for business and personal accounts.
  • Reviewing procedures for reporting suspected phishing attempts.
  • Monitoring for suspicious or newly registered domains impersonating trusted brands.
  • Providing awareness training on AI-generated phishing messages and other realistic impersonation tactics.

More Security-Focused Content

The FB-ISAO’s sponsor Gate 15 publishes a daily newsletter called the SUN. Curated from their open source intelligence collection process, the SUN informs leaders and analysts with the critical news of the day and provides a holistic look at the current global, all-hazards threat environment. Ahead of the daily news cycle, the SUN allows current situational awareness into the topics that will impact your organization.