Staying Safe Online

Staying Safe Online in the Age of AI: Simple Rules for a Trusting Church

9/14/2026
By NYAC Communications, Lisa Isom (Director of Communications) and Joy Duckett Cain (Communications Contributor)

A woman holding in front of her a cutout of the shape of the front of a church.Who hasn’t heard disconcerting reports of innocent and thoughtful people who’ve fallen prey to clever (and sometimes not so clever) requests for gift cards and other items of value? When we first published an article on how to stay safe online, those requests arrived mostly by email and were often riddled with typos and other tell-tale signs of fraud.

Today they arrive by text, by phone, by social media message, and by voice. And thanks to artificial intelligence, they no longer have typos.
The “can you do me a favor” message, staged to appear as if it originates from a trusted source in a dire situation, should still be IGNORED, MARKED AS SPAM, and IMMEDIATELY DELETED without engaging the sender in any way. That advice has not changed. What has changed is how convincing the message can be and how many doors scammers now knock on.

The numbers tell the story. The Federal Trade Commission reports that Americans lost a record $15.9 billion to scams in 2025, up from $12.5 billion the year before. The FBI’s Internet Crime Complaint Center logged more than one million complaints last year, with losses approaching $21 billion, and people age 60 and older reported the largest losses of any age group, roughly $7.7 billion. And for the first time, the FBI counted complaints that involved artificial intelligence: more than 22,000 of them, with losses topping $893 million. Those are only the cases where victims realized AI was involved.

Your Bishop, Your DS and Your Pastor Do Not Need Gift Cards

Churches Make Easy Targets. We are a high-trust community. We answer the phone. We reply to the email. When someone in our congregation says they’re in trouble, our first instinct is to help, not to interrogate. That instinct is one of the most beautiful things about the church, and scammers know it. They also know where to find victims when pastors’ names, photos and email addresses sit on church websites and Facebook pages. Our worship services are livestreamed, which means our pastors’ voices are online for anyone to copy. Our bishop and district superintendents are public figures with public schedules. Everything a scammer needs to impersonate a church leader is a search away, and the culture of generosity that makes us who we are is exactly what they are counting on.

This is the scam that lands in our church-related inboxes most often, and it works because it sounds plausible. The message reads something like this: “I’m in a meeting and can’t talk. I need a favor. Can you pick up some gift cards for a family in crisis? I’ll reimburse you. Please keep this between us.” Here is the truth: Bishop Merrill does not send emails or texts asking for financial help. Neither do Conference district superintendents, conference staff, nor your pastors.

Our Church Leaders Will NEVER:

  • Ask you to buy gift cards, cryptocurrency or anything else on their behalf and send them the numbers or a photo of the card.
  • Ask you to wire money or send a payment through Zelle, Venmo, Cash App or a similar service.
  • Tell you not to call because they are too busy, in a meeting or traveling.
  • Ask you to keep a financial request quiet or “between us.”
  • Ask for your password, bank information, Social Security number or a login code.

Legitimate needs in our conferences are met through the church, not through individuals running errands. Real requests for giving come through official channels: the conference website, our official publications, your church’s own communications, and our official social media accounts. If the request came any other way, treat it as a scam until proven otherwise. Secrecy and urgency are not how the church operates; this should be viewed as a huge red flag.

How AI Changed the Game for Scammers

For years, the best defense against a fraudulent email was a careful read. Odd grammar, a strange greeting, and a misspelled name.

Generative AI (computer programs that can write, draw, speak or produce video on command, learning from vast amounts of existing content to create convincing new material) means we all must be more vigilant online. In the right hands, Generative AI is a great tool to draft letters and summarize reports. In the wrong hands it writes a flawless scam email, clones a pastor’s voice from a livestream, or produces a video of someone you trust saying words they never said, computer programs that can write, draw, speak or produce video on command, and learning from vast amounts of existing content to create convincing new material. A scammer can now produce hundreds of polished, personalized messages an hour, each one referencing your church by name and signed by your pastor.

Here Is What Else the Technology Makes Possible:

  • Social engineering. Many of today’s scams don’t break into your computer. They talk their way into your trust. Scammers study your church’s website, Facebook page and livestreams, then use what they learn to sound like an insider: the name of your pastor, the mission trip you just announced, and the family that lost their home last month.
    AI lets them do this research and write the script in seconds. The details feel like proof that the message is real. They are proof only that the scammer did their homework. The federal Cybersecurity and Infrastructure Security Agency offers a clear explanation of how these attacks work and what to do if you suspect one: Avoiding Social Engineering and Phishing Attacks.
  • Voice cloning. With as little as a few seconds of recorded audio, scammers can produce a voice that sounds like your grandchild, your pastor or your district superintendent. The FTC’s guidance is blunt: don’t trust the voice. Hang up and call the person back on a number you already have.
  • Deepfake videos. Video calls with AI-generated faces have already been used to trick employees into wiring money. If a video call is the only proof that someone is who they say they are, it isn’t proof.
  • Spoofed caller ID. The number on your screen can be faked, including the real number of your church office or a family member. Caller ID tells you nothing about who is actually calling.
  • Fake QR codes. Scammers hide harmful links inside QR codes sent by text or email or pasted over legitimate codes in public places. The FTC warns that a scanned code can open a spoofed site that looks real or quietly install malware.
  • Text messages and social media. Your “bishop,” your “pastor,” your “District Superintendent,” or some other church-related contact who texts you asking for gift cards for families in need is now one of the most common scams reported to police departments around the country. Social media is where nearly a third of reported fraud now begins.
  • New ways to pay. Gift cards remain a scammer favorite, but requests now also come for payment apps, wire transfers and cryptocurrency, including instructions to feed cash into a crypto ATM. All of these are hard or impossible to reverse. That is the point.

Four Simple Rules for Staying Safe

Please start your plan to be hyper-vigilant by noting these four simple ways to avoid being scammed:

  1. Verify on a separate channel every time. If a message, call or voice sounds like someone you know and asks for money, information or urgency, stop. Do not reply to the message. Do not call the number the caller gives you. Pick up the telephone and call the person on a number you already have, or call the church or conference office directly. Contact information for conference staff is on our website. A real pastor will be glad you checked. A scammer will be gone.
  2. Look closely at the sender. The display name on a message can say anything at all; the actual email address underneath it is harder to fake. Look closely. Official Arkansas Annual Conference emails come from an address ending in @arumc.org. Watch for lookalikes with a letter swapped or a word added, and know that even a legitimate-looking address can be spoofed, so this check is a first filter, not a guarantee. For church offices, a related note: generic role addresses such as secretary@ or pastor@ are the easiest for scammers to guess and the hardest for recipients to verify, since no single person stands behind them. Make sure staff and clergy communicate from official church-domain accounts tied to an explicitly named individual, and treat any financial request from a role address or from a personal Gmail or Yahoo account as a reason to pick up the phone immediately.
  3. Never click, scan, download, or share on impulse. Do not click links or open attachments in messages you were not expecting. Do not scan a QR code that arrives by text or email. Ask yourself two questions: Was I expecting this? Does it ask me to act right now? An unexpected request plus a demand for speed is the signature of a scam. Mark it as spam and delete it.
  4. Talk about it. Scammers count on shame and silence. Talk with your family about a simple safe word that anyone claiming to be in an emergency must say. Share this article with the members of your congregation who are least likely to see it online. If you were targeted, tell your pastor and your church office so others can be warned. There is no embarrassment in being targeted. These operations are professional, and they are aimed at all of us.

If You Have Already Been Scammed: Act Quickly.

If you paid with a gift card, call the card company right away using the number on the back of the card and ask them to freeze the funds. Keep the card and the receipt. If you sent money through your bank or a payment app, call the bank immediately. Then report what happened to the FTC at ReportFraud.ftc.gov and to the FBI at ic3.gov. Every report helps investigators see the pattern, and some victims do recover their money. Finally, let your church know. Your experience may protect the next person.

Email scammers and online criminals evolve to survive, so do your best to stay informed. Our conference works diligently to intercept and eliminate fraudulent messages, but it is impossible to stop them all. We need you to stay vigilant and aware whenever you engage online. Gift cards are for gifts, not for payments, and the voice on the phone may not be the person you think it is.

Resources for a Safer Church

Technology Scams and the Church

From the General Council on Finance and Administration (GCFA)

GCFA, our UMC connection’s finance and administration agency, publishes cybersecurity guidance written for churches and offers hands-on support through UMC Support.

GCFA Support Services

AI and New Technology

Gift Cards and Payments

Where to Report

Print It, Post It, Pass It On

Every resource below comes from an official U.S. government site or from The United Methodist Church’s own finance agency. All are free to download, print and share, with no fee, no login and no personal information required. FTC materials are in the public domain, so you may add your church or our official Conference logo. Better still, most can be ordered in bulk at no cost, shipping included.

Federal Trade Commission Pass It On (ftc.gov/PassItOn)

Fact sheets, bookmarks and ready-made PowerPoint presentations on thirteen scam topics, including business and government impersonators, charity fraud, identity theft, and grandkid and family scams. Written for older adults as partners rather than victims, which makes it well suited to an adult Sunday school class or a fellowship group. Download at www.consumer.ftc.gov/features/pass-it-on/resources The FTC ships print materials at no charge, including postage, in quantities from 5 to 500. Allow about four weeks.

The Pass It On Sample Pack is a good place to start for a church office or a district gathering.  www.bulkorder.ftc.gov

Stop Gift Card Scams Toolkit

Printable signs, a laminated counter card, bookmarks and stickers warning that anyone demanding payment by gift card is a scammer. Several files include space to drop in your own logo. Post one in the church office or near the fellowship hall bulletin board. https://consumer.ftc.gov/articles/stop-gift-card-scams

Avoiding Social Engineering and Phishing Attacks

A printable explainer from the federal Cybersecurity and Infrastructure Security Agency covering email, phone and text scams, and what to do if you think you responded to one. www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks

GCFA Cybersecurity Resources for Churches

The denomination’s finance agency publishes church-specific guidance you can print for a trustees or finance committee meeting, including an email security checklist and a piece on establishing a safe word for verifying urgent requests. www.gcfa.org/blog/categories/cybersecurity-compliance