Faith-Based Daily Awareness Post 21 July 2026

Faith-Based Security Headlines

These updates are shared to help raise the situational awareness of Faith-Based organizations to best defend against and mitigate the impacts from all-hazards threats including physical security, cybersecurity, and natural disasters.

 

How Churches Can Prevent AI Scams, Impersonation, and Payment Fraud

 

Artificial intelligence (AI) is changing faith-based operations, but it also making fraud more difficult to detect. AI-generated emails, voice messages, invoices, receipts, and text messages can appear legitimate enough to fool even experienced staff. Criminals are increasingly using these tools to impersonate faith leaders, vendors, or other trusted individuals to request urgent payments, reimbursements, or sensitive information. Because Houses of Worship (HOWs) often rely on trust, quick approvals, and informal communication among staff and volunteers, they can be particularly vulnerable to these scams. The article emphasizes that HOWs can reduce their risk by strengthening financial controls, requiring multi-factor authentication (MFA), verifying payment requests through a second communication method, separating financial responsibilities, limiting access to sensitive systems, and training staff to pause and verify unusual requests.

 

Analyst Comments: AI-enabled fraud is becoming more convincing, making it increasingly difficult to identify fraudulent requests based on appearance or tone alone. Faith-based organizations often operate in environments built on trust and collaboration, which attackers may exploit through impersonation and social engineering tactics.

 

Faith-based organizations can:

  • Require multi-factor authentication (MFA) for church email, financial, and administrative accounts.
  • Verify requests involving payments, gift cards, payroll changes, or sensitive information through a second communication method before acting.
  • Establish clear financial approval and reimbursement procedures that separate responsibilities and reduce the risk of a single individual authorizing transactions.
  • Provide regular awareness training for staff and volunteers so they recognize AI-generated phishing emails, fake voice messages, and impersonation attempts.
  • Develop and practice an incident response plan so leadership knows how to respond quickly if fraud or account compromise occurs.

 

KY: St. Martha Catholic Church claimed by Qilin ransomware group

 

On July 18, 2026, St.Martha Catholic Church was listed on the Qilin ransomware group’s leak site, with attackers claiming they exfiltrated internal files during a ransomware attack before encrypting the church’s systems. At the time of the listing no sample files or specific records had been published, and the full scope of the incident, including the number of individuals affected and the types of information involved, remained unknown.

 

The incident serves as a reminder that churches often maintain sensitive information about congregants, families, volunteers, donors, and ministry activities, making them attractive targets for ransomware groups. If internal files are stolen, they may contain personal information, financial records, correspondence, or other sensitive data that can be used in future identify theft, fraud, or targeted phishing campaigns. The article also notes that ransomware operators frequently steal data before encrypting systems, using the threat of publishing stolen information to pressure organizations into paying a ransom.

 

Analyst Comments: This incident reinforces that ransomware continues to pose a significant risk to faith-based organizations, regardless of their size or available resources. Modern ransomware attacks frequently involve data theft alongside system encryption, allowing threat actors to pressure victims by threatening to publish sensitive information if ransom is not paid.

 

Faith-based organizations can:

  • Maintain offline, regularly tested backups to support recovery without relying on ransom payments.
  • Implement multi-factor authentication (MFA), promptly apply security updates, and secure remote access.
  • Train staff and volunteers to recognize phishing and other social engineering tactics commonly used to gain initial access.
  • Develop and regularly exercise a ransomware incident response plan that includes procedures for data breaches and communications.

 

Preparing for both operational disruption and potential data exposure can improve an organization’s ability to recover while helping protect the trust placed in it by its congregation and community.

 

ICYMI: FB-ISAO’s 2025 Threat Data Report | Vandalism, Violence, Arson, Active Shooters, Cyber Attacks, and More: Understanding Today’s Threats to Houses of Worship Across All Faith Communities

 

Houses of worship and faith‑based organizations are facing increasing levels of hostility, from vandalism and arson to active‑shooter events, bomb threats, hate‑motivated violence, and cyber-attacks on their systems and data. Join the Faith-Based Information Sharing and Analysis Organization for a focused review of the much-anticipated cumulative threat data on attacks and incidents impacting churches, synagogues, mosques, temples, and other houses of worship during 2025.

 

During this session, Ed Heyman and Ross Moore will:

  • Walk through key statistics from recent incidents impacting houses of worship and faith‑based organizations, including vandalism, arson, threats, and violence.
  • Highlight notable hate‑motivated and extremist attacks against religious institutions and how those trends are evolving across time and different faith traditions.
  • Review recent cyber incidents affecting faith‑based organizations – such as ransomware campaigns and online harassment – and discuss common entry points and vulnerabilities.
  • Discuss practical implications for security planning, training, and partnership with law enforcement, emergency management, and community organizations.
  • Point to free tools, templates, and grant programs that can help congregations strengthen their security posture and preparedness without overwhelming budgets or staff.

 

This presentation is designed for clergy, executive leaders, safety, security, and intelligence team members, board members, and anyone responsible for protecting the people, facilities, and ministries of a faith‑based organization. No advanced technical background is required; the focus is on clear, plain‑language insight into current threats and realistic steps faith communities can take to reduce risk.

 

The webinar will take place on 22 July 2026 at 12:00 PM ET, when we’ll unpack what the data is telling us and what leaders should be watching now. Participants will leave with a clearer understanding of current trends, risk drivers, and practical steps to strengthen security, preparedness, and resilience in their own communities.

 

Register here  : This is a members-only event.

 

More Security-Focused Content

The FB-ISAO’s sponsor Gate 15 publishes a daily newsletter called the SUN. Curated from their open source intelligence collection process, the SUN informs leaders and analysts with the critical news of the day and provides a holistic look at the current global, all-hazards threat environment. Ahead of the daily news cycle, the SUN allows current situational awareness into the topics that will impact your organization.