The call came to the church treasurer on a Tuesday afternoon. It sounded exactly like the pastor , the same voice, the same cadence, the same way of starting sentences. The pastor was traveling, the voice explained, and needed the treasurer to wire $4,200 to cover an emergency. The treasurer almost did it.
She did not because she had a rule: any financial request over $500 required a callback to a number she already had, not a number provided in the request. She called the pastor’s cell phone. He had no idea what she was talking about.
That rule saved the church $4,200. It also illustrates the only reliable defense against AI voice fraud: verification through a separate channel.
What Deepfakes Are (Plain Language)
A deepfake is AI-generated content , audio, video, or image , that realistically impersonates a real person. The technology has become dramatically more accessible and convincing in the past two years. Creating a convincing AI voice clone now requires only a few minutes of audio from a publicly available source , a sermon recording, a YouTube video, a podcast appearance.
For churches, the threat is primarily audio deepfakes used in fraud. A bad actor finds a recording of your pastor’s voice, uses AI to clone it, and then calls a staff member or volunteer with an urgent request. The voice sounds real because it is built from real audio. The request is fake.
Video deepfakes , fake video calls that show a realistic image of the pastor , are less common but increasingly possible. The FBI has documented cases where video deepfakes were used to impersonate executives in business fraud. The same technology is available to anyone targeting a church.
How Deepfake Fraud Targets Small Churches
Small churches are attractive targets for AI-enabled fraud for three reasons.
Trust. Congregation members and staff trust communications that appear to come from their pastor. That trust is the foundation of church community. It is also a vulnerability when someone exploits it.
Fewer verification steps. Large organizations have multi-step approval processes for financial transactions. Small churches often do not. A single phone call from someone who sounds like the pastor may be sufficient to authorize a transfer.
Public audio availability. Most pastors have publicly available audio , sermon recordings, podcast appearances, YouTube videos. That audio is the raw material for a voice clone. The more public audio exists, the easier the clone is to create.
The FBI’s Internet Crime Complaint Center has reported a significant increase in AI-enabled fraud targeting nonprofit organizations including churches. The Association of Certified Fraud Examiners estimates that organizations lose 5 percent of annual revenue to fraud, and AI tools are making fraud easier and more convincing.
The Most Common Scenarios
The Emergency Wire Transfer
A voice message or call that sounds like the pastor, explaining that they are traveling and need an urgent wire transfer to cover an emergency. The request is for an amount large enough to matter but small enough to seem plausible. There is pressure to act quickly and not to verify through other channels.
The Gift Card Request
A text or email that appears to come from the pastor, asking a staff member or volunteer to purchase gift cards and send the codes. This is one of the most common fraud patterns targeting churches and nonprofits. The gift card request is almost always fraudulent.
The Fake Donation Request
A message that appears to come from a church leader, asking congregation members to donate to an emergency fund through a link or account that the church does not control. This targets congregation members directly rather than staff.
The Vendor Impersonation
A message that appears to come from a vendor the church works with, requesting a change to payment information. The new account belongs to the fraudster. This is less common in small churches but is increasing as AI makes impersonation easier.
How to Verify Before You Trust
The only reliable defense against deepfake fraud is verification through a separate channel. This means:
- Never authorize a financial transaction based solely on a digital request, regardless of how convincing the voice or message sounds.
- Call back on a number you already have for the person making the request , not a number provided in the suspicious message.
- Establish a code word that only the pastor and key staff know. Any legitimate urgent request should include the code word. Any request without it is suspect.
- Set a dollar threshold below which staff can act on a single communication, and above which a callback is required. Even a $500 threshold catches most fraud attempts.
- Be suspicious of urgency. Legitimate urgent requests can wait 60 seconds for a verification call. Fraudulent requests cannot, because verification will expose them.
The free MinistryPlace Church AI Policy Template includes a section on deepfake fraud prevention, including a verification protocol template you can adapt for your church. No email required.
What to Include in Your Church AI Policy
Your church AI policy should address deepfake fraud directly. At minimum, include:
- A verification protocol for any financial request received digitally, regardless of the apparent source
- A clear statement that no financial transaction will be authorized based solely on a digital request
- A list of approved communication channels for sensitive requests (in-person or verified phone call, not text or email alone)
- A reporting process for suspected deepfake attempts (who to notify, how to document)
- A training requirement so all staff and financial volunteers understand the protocol
The protocol does not need to be complicated. “Any financial request over $X requires a callback to a number we already have” is sufficient for most small churches. The key is that the protocol exists, is written down, and is known by everyone who handles church finances.
What to Do If Your Church Is Targeted
If you receive a suspected deepfake communication or if a fraud attempt succeeds:
- Do not send money if you have not already. If you have, contact your bank immediately , some transfers can be reversed if caught quickly.
- Report the attempt to the FBI’s Internet Crime Complaint Center (ic3.gov). This creates a record and helps law enforcement track patterns.
- Notify your congregation so they are not targeted individually with the same impersonation.
- Review and update your verification protocol.
- Consider whether your publicly available audio (sermon recordings, etc.) should be restricted or watermarked.
Includes a complete church AI policy framework, data privacy addendum, staff training guide, and vendor evaluation checklist. Everything a small church needs to use AI responsibly and protect against AI-enabled threats.
Frequently Asked Questions
What is a deepfake and how does it affect churches?
A deepfake is AI-generated audio, video, or image content that realistically impersonates a real person. For churches, the most common threat is AI-generated voice messages or emails that impersonate the pastor or a church leader to request money, gift cards, or sensitive information. These attacks are increasingly convincing and are targeting small organizations, including churches, because they often lack the verification protocols that larger organizations have.
How can I tell if a voice message or video call is a deepfake?
Common signs include: the request is urgent and unusual, the communication came through an unexpected channel, the voice or image quality is slightly off, the request asks for money, gift cards, or sensitive information, and there is pressure not to verify through other channels. The most reliable test is to hang up and call the person back on a number you already have for them, not a number provided in the suspicious message.
What should a church include in its AI policy about deepfakes?
Your church AI policy should include: a verification protocol for any financial request received digitally, a list of approved communication channels for sensitive requests, a clear statement that no financial transaction will be authorized based solely on a digital request, and a reporting process for suspected deepfake attempts.
Has deepfake fraud actually targeted churches?
Yes. Church fraud using AI-generated voice and email impersonation has been documented by the FBI and the Association of Certified Fraud Examiners. Small churches are particularly vulnerable because they often have fewer verification steps for financial transactions and because congregation members trust communications that appear to come from their pastor.