Organizational Preparation · Policy

Deepfake, Impersonation & Fraud Response Kit

Authoritative sources and church-ready response patterns

The sources below are primarily from U.S. government agencies. They are highly credible foundations, but most are not written specifically for churches. However, the content could be used to help develop congregational procedures, and church-specific templates.

Foundational resource for the entire kit

NSA/FBI/CISA — Contextualizing Deepfake Threats to Organizations

This is the strongest single technical foundation. It addresses synthetic audio, video, images, executive impersonation, financial fraud, reputational attacks, authentication, preparation, detection, and organizational response. (NSA)

FinCEN — Alert on Fraud Schemes Involving Deepfake Media

This Treasury Department alert supplies deepfake-fraud typologies, warning indicators, identity-verification concerns, and suspicious behaviors. It is particularly useful for developing financial controls and an incident checklist. (FinCEN.gov)

1. Call-back verification protocol

Best primary source

FTC — Fighting Back Against Harmful Voice Cloning

The FTC explicitly recommends calling the person who supposedly contacted you using a phone number you already know belongs to that person—not a number supplied in the suspicious message. When the person cannot be reached, the FTC recommends checking through another trusted person. (Consumer Advice)

Detailed public guidance

FTC — Scammers Use Fake Emergencies to Steal Your Money

This provides a fuller verification sequence: slow down, resist urgency, call a known number, consult another trusted person, and disregard demands for secrecy. It is especially suitable for converting into a congregational handout. (Consumer Advice)

Organizational verification standard

FBI Internet Crime Complaint Center — Business Email Compromise

The FBI recommends using a secondary communications channel or another authentication method to verify requests involving account information and financial transactions. (Internet Crime Complaint Center)

Recommended church adaptation

The Church AI Toolkit should turn these principles into a rule such as:

No emergency request involving money, credentials, confidential records, gift cards, cryptocurrency, account changes, or sensitive pastoral information will be acted upon until the requester has been independently contacted through a previously verified channel.

The protocol should include a protected directory of verified telephone numbers for clergy, treasurers, bishops, denominational officials, missionaries, staff members, and financial institutions.

2. Dual authorization for financial transfers

Strongest authoritative source

Office of the Comptroller of the Currency — Payment Systems, Comptroller’s Handbook

The OCC states that sound payment controls include segregation of duties and dual controls, and that weak implementation of these controls significantly increases operational risk. Although written for banks, this is the strongest federal foundation for a church’s two-person authorization rule. (OCC.gov)

Additional internal-control guidance

Office of the Comptroller of the Currency — Internal Control, Comptroller’s Handbook

This guidance supports dual signatures for transactions above designated limits and separation between authorization, custody, recording, and reconciliation responsibilities. (OCC.gov)

Fraud-specific companion

FBI IC3 — Business Email Compromise: The $55 Billion Scam

This resource explains verification of account-change requests, independent communications channels, email-address inspection, and immediate bank contact when a fraudulent transfer is discovered. (Internet Crime Complaint Center)

Recommended church policy

The toolkit should recommend:

  • Two unrelated authorized people approve every electronic transfer above a defined threshold.

  • The person initiating a payment cannot be its sole approver.

  • New payees and changes to bank information require independent call-back verification.

  • No approval may rely solely on email, text, social media, voicemail, or a video call.

  • Emergency exceptions must be documented and reviewed by the finance committee.

  • Bank reconciliation should be performed by someone who did not initiate or approve the payment.

3. Guidance for verifying pastoral emergency requests

Introduction to AI Guide with a focus on Counter Fraud

Introduction to AI Guide with a focus on Counter Fraud (HTML) - GOV.UK

This UK Government document highlights the evolving arms race between counter-fraud practitioners and cybercriminals in the age of Artificial Intelligence. This short guide contains guidance for building knowledge and awareness.

Best congregant-facing resource

FTC — Scammers Use AI to Enhance Family Emergency Schemes

The FTC warns that hearing a familiar voice is no longer reliable proof of identity. It recommends contacting the apparent requester through a known number and checking the story with another trusted person. (Consumer Advice)

Broader emergency-scam guidance

FTC — Scammers Use Fake Emergencies to Steal Your Money

This is particularly valuable because it identifies the pastoral and psychological pressures a scammer may exploit: urgency, secrecy, fear, authority, emotional distress, and the claim that only the recipient can help. (Consumer Advice)

Organizational threat background

NSA/FBI/CISA — Deepfake Threats to Organizations

Use this to explain why a realistic voice, image, video meeting, or recording cannot by itself authenticate a pastor, bishop, missionary, denominational officer, or church executive. (NSA)

Recommended pastoral verification sequence

The toolkit should use a memorable process such as PAUSE:

P — Pause. Do not act under pressure.
A — Authenticate independently. Call a known number.
U — Use another trusted person. Contact a spouse, staff member, supervisor, bishop’s office, or family member.
S — Stop unusual payment methods. Never respond with gift cards, cryptocurrency, cash couriers, or newly supplied accounts.
E — Escalate and report. Inform the church’s designated fraud-response leader.

A genuine pastoral emergency should survive reasonable verification. A demand for secrecy or immediate payment should be treated as a warning indicator, not as evidence of urgency. (Consumer Advice)

4. Clergy impersonation incident checklist

Threat identification and mitigation

NSA/FBI/CISA — Contextualizing Deepfake Threats to Organizations

This should be the principal source for recognizing synthetic voice, video, image, brand, executive, and communications threats. (NSA)

Incident-plan structure

CISA — Incident Response Plan Basics

This provides the organizational structure for responding before, during, and after a suspected incident, including assigned roles, escalation, documentation, containment, recovery, and review. (CISA)

Church-specific security context

CISA — Faith-Based Community Resources

CISA — Houses of Worship Security Self-Assessment

These provide an established security-planning structure specifically for houses of worship. The AI toolkit should add deepfake, impersonation, compromised accounts, payment fraud, and synthetic-media questions to that structure. (CISA)

Reporting and financial recovery

FBI IC3 — Business Email Compromise Incident Response

When money has been transferred, the FBI recommends immediately contacting the originating financial institution to request a recall or reversal and promptly filing a detailed IC3 complaint. (Internet Crime Complaint Center)

The checklist should capture

  1. Date, time, platform, account, telephone number, and URL.

  2. Screenshots, audio, video, email headers, text messages, and transaction records.

  3. Who discovered the impersonation.

  4. Who may have received or acted upon it.

  5. Whether money, credentials, data, or pastoral information was disclosed.

  6. Whether an official account was compromised or a separate fake account was created.

  7. Immediate password changes and session termination.

  8. Bank, insurer, denomination, platform, law-enforcement, and legal notifications.

  9. Public communications issued.

  10. Post-incident review and corrective action.

Do not delete the original evidence before preserving it. Do not repeatedly forward harmful material when a screenshot, secure copy, or URL will suffice.

5. Congregational fraud bulletin

Best bulletin-ready FTC resource

FTC — Fighting Back Against Harmful Voice Cloning

This is concise, understandable, and suitable for adapting into a bulletin insert, newsletter item, senior-adult ministry resource, or social-media post. (Consumer Advice)

Best bulletin-ready emergency-scam resource

FTC — Fake Emergency Scams

This supplies recognizable warning signs and a simple “slow down and verify” message. (Consumer Advice)

Best staff and finance resource

FBI IC3 — Business Email Compromise

Use this for bulletins directed to treasurers, vestries, sessions, councils, trustees, finance committees, office staff, and ministry executives. (Internet Crime Complaint Center)

General phishing awareness

CISA — Teach Employees to Avoid Phishing

CISA’s material supports staff education about suspicious links, unexpected requests, manipulated sender information, and incident reporting. (CISA)

Suggested bulletin message

A church bulletin should prominently state:

Our clergy and staff will never ask you by an unexpected email, text, social-media message, video, or telephone call to purchase gift cards, transfer cryptocurrency, disclose passwords, or send emergency money without independent verification. Voices, photographs, and videos can now be convincingly imitated. Stop, call the church through its published telephone number, and verify before responding.

6. Tabletop exercise for staff and trustees

Best federal exercise library

CISA — Tabletop Exercise Packages

CISA provides customizable scenarios involving phishing, ransomware, insider threats, and other cyber incidents. These packages are the strongest starting point for designing a church deepfake exercise. (CISA)

Additional exercise model

CISA — JCDC Cyber Incident Exercise Discussion Packages

These exercises are designed to help participants identify threats, vulnerabilities, organizational responsibilities, and response decisions. (CISA)

Incident response foundation

CISA — Incident Response Plan Basics

Use this to assign the exercise roles: incident lead, clergy representative, finance lead, communications lead, IT support, safeguarding representative, legal or insurance contact, and denominational liaison. (CISA)

Recommended church exercise scenario

At 9:10 a.m. on Sunday, the treasurer receives a voice message that appears to be from the senior pastor. The caller says a missionary family faces an urgent medical emergency and requests a $14,500 wire transfer to a new account. At 9:20 a.m., a convincing video of the pastor repeats the request. At 9:35 a.m., congregants report receiving similar text messages. At 10:00 a.m., a fake Facebook page announces that the church is collecting emergency donations.

The exercise should test:

  • Verification and decision authority

  • Payment suspension

  • Evidence preservation

  • Bank notification

  • Account security

  • Platform reporting

  • Communications with members

  • Denominational notification

  • Law-enforcement reporting

  • Pastoral care for victims

  • Post-incident review

7. Communications template for fake video, audio, email, or social-media accounts

Crisis-communication principles

FEMA — NIMS Basic Guidance for Public Information Officers

FEMA’s guidance supports communicating with empathy, clarity, accuracy, consistency, coordinated messaging, and practical instructions for the affected public. (FEMA)

Incident communication planning

CISA — Election Infrastructure Incident Response Communications Guide

Although written for election offices, this guide is highly adaptable because it addresses incident communications, public trust, coordinated messaging, notification, and misinformation during a high-consequence event. (CISA)

Notification templates

CISA — Cyber Incident Detection and Notification Planning Templates

These can be adapted for internal staff notices, leadership notifications, public warnings, and follow-up communications. (CISA)

Recommended communication structure

A church response should contain:

  1. What happened: “We are aware of an unauthorized message/account/video impersonating…”

  2. What is known: State only confirmed information.

  3. What is not yet known: Avoid speculation.

  4. What people should not do: Do not reply, send money, click links, or forward the content.

  5. How to verify church communications: Published website, telephone number, office email, and official accounts.

  6. What affected people should do: Contact the bank, change credentials, preserve evidence, and report.

  7. What the church is doing: Platform report, account security, bank contact, law-enforcement report, and member notification.

  8. When the next update will appear: Use one authoritative communication channel.

  9. Pastoral care: Provide a safe contact for anyone who lost money, feels ashamed, or needs support.

The statement should avoid amplifying the fraudulent content by unnecessarily reposting the fake video, audio, or message.

Official platform impersonation-reporting links

These should be embedded directly in the incident checklist.

Official fraud-reporting links

The Justice Department directs consumer and identity-fraud reports to the FTC, internet-fraud reports to IC3, and other suspected criminal matters to the appropriate law-enforcement agency. (Department of Justice)

For an unauthorized financial transfer, the first action should be immediate contact with the church’s bank to request a recall, reversal, hold, or other recovery action, followed promptly by an IC3 complaint. (Internet Crime Complaint Center)

  • Deepfakes & Fraud
  • Policy
  • Safeguarding