These updates are shared to help raise the situational awareness of Faith-Based organizations to best defend against and mitigate the impacts from all-hazards threats including physical security, cybersecurity, and natural disasters.
More than $1.6 million was stolen from the United Methodist Church New England Conference after criminals posed as bank representatives and gained access to the conference’s online banking system. The cybersecurity incident occurred on August 5, and the stolen funds came from the conference’s operating account through multiple wire transfers to assorted global accounts. In an August 13 letter, New England Bishop Thomas Bickerton said the conference is working with the FBI, Secret Service, their insurance carrier, and specially assigned legal counsel with cybercrime expertise. As of the letter, approximately $200,000 had been recovered. Bickerton said the conference is reviewing internal financial and staff policies to prevent further crimes, while emphasizing that ministries and financial obligations will continue uninterrupted.
Analyst Comments: This incident highlights the financial exposure facing faith-based organizations and houses of worship that manage operating accounts, donor funds, payroll, insurance payments, grants, and vendor transactions. Social engineering can quickly become a major financial loss when banking access and payment approvals are compromised. The loss illustrates the importance of prevention-focused financial controls.
First Amendment auditors are individuals who film public-facing spaces, including houses of worship, to test how people respond and sometimes to generate online content. In the incident described in this Times of Israel blog, a man filmed a synagogue from public property for about 90 minutes, including the building, congregants, vehicles, and security personnel, while refusing to explain his purpose beyond claiming a constitutional right to film. The article emphasizes that while filming from a public sidewalk is generally lawful, U.S. synagogues still need to treat prolonged or unusual surveillance seriously because legally protected photography and hostile surveillance can initially appear similar.
The recommended response is calm observation rather than confrontation: avoid arguing, do not disclose security procedures, protect the property line, document behavior, and escalate based on specific actions such as trespassing, threats, door testing, following congregants, or repeated appearances.
Analyst Comments: This incident highlights a challenge for houses of worship: activity that may be lawful, such as filming from a public sidewalk, but still creates concern when it involves behavior like pre-attack reconnaissance. Houses of worship benefit from having a plan for First Amendment Auditors, including who communicates with the individual, when police are contacted, how incidents are documented, and how
The Gate 15 Security Sprint is a weekly rundown of the week’s notable all-hazards security news, risks and threats and some of the key focus areas for organizations to consider behind the headlines. Gate 15 team members discuss physical security, cybersecurity, natural hazards, health threats and other issues across our environment.
In this week’s Weekly Security Sprint Dave and Andy discuss, Iran hackers: Minnesota ‘warning’ ignored, ‘critical events’ to hit 3 U.S. infrastructure sectors, A Tale of Two SOCs: Insights from Two Red Team Assessments, and Institutional Wilful Blindness, NCSC Cyber Series.
Information on other Gate 15 podcasts can be found at Podcasts (gate15.global).
The FB-ISAO’s sponsor Gate 15 publishes a daily newsletter called the SUN. Curated from their open source intelligence collection process, the SUN informs leaders and analysts with the critical news of the day and provides a holistic look at the current global, all-hazards threat environment. Ahead of the daily news cycle, the SUN allows current situational awareness into the topics that will impact your organization.