Organizational Preparation · Policy
Deepfake, Impersonation & Fraud Response Kit
Authoritative sources and church-ready response patterns
The sources below are primarily from U.S. government agencies. They are highly credible foundations, but most are not written specifically for churches. However, the content could be used to help develop congregational procedures, and church-specific templates.
Foundational resource for the entire kit
NSA/FBI/CISA — Contextualizing Deepfake Threats to Organizations
This is the strongest single technical foundation. It addresses synthetic audio, video, images, executive impersonation, financial fraud, reputational attacks, authentication, preparation, detection, and organizational response. (NSA)
FinCEN — Alert on Fraud Schemes Involving Deepfake Media
This Treasury Department alert supplies deepfake-fraud typologies, warning indicators, identity-verification concerns, and suspicious behaviors. It is particularly useful for developing financial controls and an incident checklist. (FinCEN.gov)
1. Call-back verification protocol
Best primary source
FTC — Fighting Back Against Harmful Voice Cloning
The FTC explicitly recommends calling the person who supposedly contacted you using a phone number you already know belongs to that person—not a number supplied in the suspicious message. When the person cannot be reached, the FTC recommends checking through another trusted person. (Consumer Advice)
Detailed public guidance
FTC — Scammers Use Fake Emergencies to Steal Your Money
This provides a fuller verification sequence: slow down, resist urgency, call a known number, consult another trusted person, and disregard demands for secrecy. It is especially suitable for converting into a congregational handout. (Consumer Advice)
Organizational verification standard
FBI Internet Crime Complaint Center — Business Email Compromise
The FBI recommends using a secondary communications channel or another authentication method to verify requests involving account information and financial transactions. (Internet Crime Complaint Center)
Recommended church adaptation
The Church AI Toolkit should turn these principles into a rule such as:
No emergency request involving money, credentials, confidential records, gift cards, cryptocurrency, account changes, or sensitive pastoral information will be acted upon until the requester has been independently contacted through a previously verified channel.
The protocol should include a protected directory of verified telephone numbers for clergy, treasurers, bishops, denominational officials, missionaries, staff members, and financial institutions.
2. Dual authorization for financial transfers
Strongest authoritative source
Office of the Comptroller of the Currency — Payment Systems, Comptroller’s Handbook
The OCC states that sound payment controls include segregation of duties and dual controls, and that weak implementation of these controls significantly increases operational risk. Although written for banks, this is the strongest federal foundation for a church’s two-person authorization rule. (OCC.gov)
Additional internal-control guidance
Office of the Comptroller of the Currency — Internal Control, Comptroller’s Handbook
This guidance supports dual signatures for transactions above designated limits and separation between authorization, custody, recording, and reconciliation responsibilities. (OCC.gov)
Fraud-specific companion
FBI IC3 — Business Email Compromise: The $55 Billion Scam
This resource explains verification of account-change requests, independent communications channels, email-address inspection, and immediate bank contact when a fraudulent transfer is discovered. (Internet Crime Complaint Center)
Recommended church policy
The toolkit should recommend:
Two unrelated authorized people approve every electronic transfer above a defined threshold.
The person initiating a payment cannot be its sole approver.
New payees and changes to bank information require independent call-back verification.
No approval may rely solely on email, text, social media, voicemail, or a video call.
Emergency exceptions must be documented and reviewed by the finance committee.
Bank reconciliation should be performed by someone who did not initiate or approve the payment.
3. Guidance for verifying pastoral emergency requests
Introduction to AI Guide with a focus on Counter Fraud
Introduction to AI Guide with a focus on Counter Fraud (HTML) - GOV.UK
This UK Government document highlights the evolving arms race between counter-fraud practitioners and cybercriminals in the age of Artificial Intelligence. This short guide contains guidance for building knowledge and awareness.
Best congregant-facing resource
FTC — Scammers Use AI to Enhance Family Emergency Schemes
The FTC warns that hearing a familiar voice is no longer reliable proof of identity. It recommends contacting the apparent requester through a known number and checking the story with another trusted person. (Consumer Advice)
Broader emergency-scam guidance
FTC — Scammers Use Fake Emergencies to Steal Your Money
This is particularly valuable because it identifies the pastoral and psychological pressures a scammer may exploit: urgency, secrecy, fear, authority, emotional distress, and the claim that only the recipient can help. (Consumer Advice)
Organizational threat background
NSA/FBI/CISA — Deepfake Threats to Organizations
Use this to explain why a realistic voice, image, video meeting, or recording cannot by itself authenticate a pastor, bishop, missionary, denominational officer, or church executive. (NSA)
Recommended pastoral verification sequence
The toolkit should use a memorable process such as PAUSE:
P — Pause. Do not act under pressure.
A — Authenticate independently. Call a known number.
U — Use another trusted person. Contact a spouse, staff member,
supervisor, bishop’s office, or family member.
S — Stop unusual payment methods. Never respond with gift cards,
cryptocurrency, cash couriers, or newly supplied accounts.
E — Escalate and report. Inform the church’s designated
fraud-response leader.
A genuine pastoral emergency should survive reasonable verification. A demand for secrecy or immediate payment should be treated as a warning indicator, not as evidence of urgency. (Consumer Advice)
4. Clergy impersonation incident checklist
Threat identification and mitigation
NSA/FBI/CISA — Contextualizing Deepfake Threats to Organizations
This should be the principal source for recognizing synthetic voice, video, image, brand, executive, and communications threats. (NSA)
Incident-plan structure
CISA — Incident Response Plan Basics
This provides the organizational structure for responding before, during, and after a suspected incident, including assigned roles, escalation, documentation, containment, recovery, and review. (CISA)
Church-specific security context
CISA — Faith-Based Community Resources
CISA — Houses of Worship Security Self-Assessment
These provide an established security-planning structure specifically for houses of worship. The AI toolkit should add deepfake, impersonation, compromised accounts, payment fraud, and synthetic-media questions to that structure. (CISA)
Reporting and financial recovery
FBI IC3 — Business Email Compromise Incident Response
When money has been transferred, the FBI recommends immediately contacting the originating financial institution to request a recall or reversal and promptly filing a detailed IC3 complaint. (Internet Crime Complaint Center)
The checklist should capture
Date, time, platform, account, telephone number, and URL.
Screenshots, audio, video, email headers, text messages, and transaction records.
Who discovered the impersonation.
Who may have received or acted upon it.
Whether money, credentials, data, or pastoral information was disclosed.
Whether an official account was compromised or a separate fake account was created.
Immediate password changes and session termination.
Bank, insurer, denomination, platform, law-enforcement, and legal notifications.
Public communications issued.
Post-incident review and corrective action.
Do not delete the original evidence before preserving it. Do not repeatedly forward harmful material when a screenshot, secure copy, or URL will suffice.
5. Congregational fraud bulletin
Best bulletin-ready FTC resource
FTC — Fighting Back Against Harmful Voice Cloning
This is concise, understandable, and suitable for adapting into a bulletin insert, newsletter item, senior-adult ministry resource, or social-media post. (Consumer Advice)
Best bulletin-ready emergency-scam resource
This supplies recognizable warning signs and a simple “slow down and verify” message. (Consumer Advice)
Best staff and finance resource
FBI IC3 — Business Email Compromise
Use this for bulletins directed to treasurers, vestries, sessions, councils, trustees, finance committees, office staff, and ministry executives. (Internet Crime Complaint Center)
General phishing awareness
CISA — Teach Employees to Avoid Phishing
CISA’s material supports staff education about suspicious links, unexpected requests, manipulated sender information, and incident reporting. (CISA)
Suggested bulletin message
A church bulletin should prominently state:
Our clergy and staff will never ask you by an unexpected email, text, social-media message, video, or telephone call to purchase gift cards, transfer cryptocurrency, disclose passwords, or send emergency money without independent verification. Voices, photographs, and videos can now be convincingly imitated. Stop, call the church through its published telephone number, and verify before responding.
6. Tabletop exercise for staff and trustees
Best federal exercise library
CISA — Tabletop Exercise Packages
CISA provides customizable scenarios involving phishing, ransomware, insider threats, and other cyber incidents. These packages are the strongest starting point for designing a church deepfake exercise. (CISA)
Additional exercise model
CISA — JCDC Cyber Incident Exercise Discussion Packages
These exercises are designed to help participants identify threats, vulnerabilities, organizational responsibilities, and response decisions. (CISA)
Incident response foundation
CISA — Incident Response Plan Basics
Use this to assign the exercise roles: incident lead, clergy representative, finance lead, communications lead, IT support, safeguarding representative, legal or insurance contact, and denominational liaison. (CISA)
Recommended church exercise scenario
At 9:10 a.m. on Sunday, the treasurer receives a voice message that appears to be from the senior pastor. The caller says a missionary family faces an urgent medical emergency and requests a $14,500 wire transfer to a new account. At 9:20 a.m., a convincing video of the pastor repeats the request. At 9:35 a.m., congregants report receiving similar text messages. At 10:00 a.m., a fake Facebook page announces that the church is collecting emergency donations.
The exercise should test:
Verification and decision authority
Payment suspension
Evidence preservation
Bank notification
Account security
Platform reporting
Communications with members
Denominational notification
Law-enforcement reporting
Pastoral care for victims
Post-incident review
7. Communications template for fake video, audio, email, or social-media accounts
Crisis-communication principles
FEMA — NIMS Basic Guidance for Public Information Officers
FEMA’s guidance supports communicating with empathy, clarity, accuracy, consistency, coordinated messaging, and practical instructions for the affected public. (FEMA)
Incident communication planning
CISA — Election Infrastructure Incident Response Communications Guide
Although written for election offices, this guide is highly adaptable because it addresses incident communications, public trust, coordinated messaging, notification, and misinformation during a high-consequence event. (CISA)
Notification templates
CISA — Cyber Incident Detection and Notification Planning Templates
These can be adapted for internal staff notices, leadership notifications, public warnings, and follow-up communications. (CISA)
Recommended communication structure
A church response should contain:
What happened: “We are aware of an unauthorized message/account/video impersonating…”
What is known: State only confirmed information.
What is not yet known: Avoid speculation.
What people should not do: Do not reply, send money, click links, or forward the content.
How to verify church communications: Published website, telephone number, office email, and official accounts.
What affected people should do: Contact the bank, change credentials, preserve evidence, and report.
What the church is doing: Platform report, account security, bank contact, law-enforcement report, and member notification.
When the next update will appear: Use one authoritative communication channel.
Pastoral care: Provide a safe contact for anyone who lost money, feels ashamed, or needs support.
The statement should avoid amplifying the fraudulent content by unnecessarily reposting the fake video, audio, or message.
Official platform impersonation-reporting links
These should be embedded directly in the incident checklist.
Facebook — Report a Profile or Page Pretending to Be You or Someone Else (Facebook)
Instagram and Threads — Impersonation Report Form (Instagram Help Center)
YouTube — Impersonation Policy and Reporting — YouTube’s policy expressly covers AI-generated voice or likeness used to falsely imply ownership, authorization, speech, or endorsement. (Google Help)
X — Report a Church, Organization, or Brand Being Impersonated (Help Center)
Official fraud-reporting links
The Justice Department directs consumer and identity-fraud reports to the FTC, internet-fraud reports to IC3, and other suspected criminal matters to the appropriate law-enforcement agency. (Department of Justice)
For an unauthorized financial transfer, the first action should be immediate contact with the church’s bank to request a recall, reversal, hold, or other recovery action, followed promptly by an IC3 complaint. (Internet Crime Complaint Center)