Church Cybersecurity Risks: 6 Trends Leaders Need to Watch

AI-powered scams, vulnerable software, third-party vendors, and sensitive data are changing the cybersecurity landscape for churches. Here’s what leaders should watch.

Church cybersecurity risks extend far beyond suspicious emails. AI, human error, vulnerable software, data privacy, vendors, and insurance are changing the threat landscape.

And, while cybersecurity can sound like an IT problem, it is increasingly a financial, legal, operational, and governance issue for churches.

Key takeaways:

  • AI is making fraudulent communications harder to recognize.
  • Software vulnerabilities are becoming a bigger entry point for attackers.
  • Staff members remain an important line of defense.
  • Churches hold sensitive information that needs protection.
  • Third-party vendors can create additional cybersecurity exposure.
  • Cyberliability insurance should complement—not replace—strong cybersecurity practices.

What are the biggest cybersecurity risks churches should watch? Church leaders should pay particular attention to AI-enhanced fraud, phishing and social engineering, software vulnerabilities, sensitive data, third-party vendors, and the financial consequences of cyber incidents.


Protect your church with guidance for churches

Cybersecurity is only one of the legal, financial, tax, and risk-management challenges church leaders face.

Church Law & Tax members get deeper access to trusted guidance from attorneys, CPAs, risk-management professionals, and church technology experts.


1. AI is changing church cybersecurity risks

Bottom line: Artificial intelligence can make cyberattacks faster and more convincing. Churches should no longer assume obvious spelling errors or strange wording will expose a fraudulent message.

For years, spotting phishing emails sometimes meant looking for obvious mistakes, but that method is becoming less reliable.

Generative AI can help attackers produce polished emails, text messages, and other communications. Moreover, attackers can imitate familiar communication styles and create convincing requests.

Church IT consultant Jonathan Smith, a Church Law & Tax editorial advisor, warns that AI has made low-tech attacks appear increasingly credible.

In Why 2FA Matters More than Ever in the Age of AI, Smith recommends using two-factor authentication (2FA) or multifactor authentication (MFA) wherever possible.

The federal government’s guidance is similar. 

The Cybersecurity and Infrastructure Security Agency’s (CISA) Secure Our World initiative recommends four foundational practices: recognize phishing, use strong passwords, turn on MFA, and update software. For churches, MFA is particularly important for accounts involving:

  • Email;
  • Online banking;
  • Giving platforms;
  • Payroll;
  • Church management systems;
  • Cloud storage;
  • Social media; and
  • Website administration.

However, MFA isn’t foolproof. Staff members must understand that an unexpected authentication request can itself be a warning.

Go deeper: Why 2FA Matters More than Ever in the Age of AI

Bottom line: Cybersecurity isn’t only about firewalls and software. A church employee who clicks the wrong link or approves the wrong transaction can bypass strong technical safeguards.

A pastor emails the finance office asking for an urgent payment.

A vendor suddenly changes its banking information.

A staff member receives a text requesting gift cards.

These situations may look routine and it’s why they can be so risky.

Church Law & Tax has examined scams involving churches where attackers used normal human behavior, rather than sophisticated computer hacking.

As Hacking a Church Is About Exploiting Its Weakest Link explains, generative AI can make these attempts even harder to identify. 

Therefore, churches need controls around high-risk actions.

For example:

  • Independently verify requests to change banking information, ideally by initiating a live conversation or through a separate communication channel with the requesting person.
  • Require additional approval for large transfers.
  • Never send passwords or authentication codes by email.
  • Train employees to challenge unusual requests.
  • Create a clear process for reporting suspicious communications.

The Federal Trade Commission (FTC) also recommends regular employee training and phishing simulations. In addition, organizations should give employees a simple way to report suspicious messages. 

Technology matters. However, so does the person sitting at the keyboard.

Go deeper: Hacking a Church Is About Exploiting Its Weakest Link

3. Your church needs a human firewall

Bottom line: Staff training should be an ongoing part of church cybersecurity. Employees should know how attackers operate and what to do when something doesn’t look right.

One cybersecurity seminar isn’t enough—threats change and church volunteers often have access to the same systems that employees have–but without the same training

Churches should create what cybersecurity professionals sometimes call a human firewall.

That means building habits that make people part of the church’s cybersecurity defenses.

Church Law & Tax has documented how attackers can learn the rhythms of a church and use those routines against employees.

For instance, a fraudulent request appearing to come from a pastor can arrive shortly before a worship service—when staff members are busy and less likely to stop and verify it.

Training should address:

  • Phishing emails;
  • Fraudulent text messages;
  • Unexpected MFA requests;
  • Gift card scams;
  • Payment-change requests;
  • Password security;
  • Suspicious attachments; and
  • Reporting procedures.

Most importantly, employees should feel comfortable slowing down a transaction.

A five-minute verification can be far less costly than recovering from fraud.

Go deeper: Church Cybersecurity Starts With the Human Firewall


Stay ahead of risks affecting your church

Cyber threats, laws, tax rules, and church management practices continue to change.

Get practical Church Law & Tax guidance delivered directly to your inbox with our free weekly newsletters.


4. Attackers are increasingly exploiting vulnerable technology

Bottom line: Training alone won’t protect a church. Software updates, access controls, backups, and basic technology management have become equally important.

One significant trend deserves church leaders’ attention.

Verizon’s 2026 Data Breach Investigations Report  (DBIR) found that 31 percent of breaches began with exploitation of software vulnerabilities. For the first time in the report’s 19-year history, that surpassed stolen credentials as the leading breach entry point. 

In other words, the person using the computer isn’t always the vulnerability.

Sometimes the computer is.

AI is also helping attackers find and exploit weaknesses faster, according to Verizon’s analysis. 

Consequently, churches should regularly:

  • Install security updates and patches;
  • Replace unsupported software;
  • Back up critical information;
  • Restrict administrator privileges;
  • Remove accounts belonging to former employees;
  • Review who can access sensitive systems; and
  • Inventory important hardware, software, and cloud services.

The FTC likewise recommends regularly updating security software, encrypting sensitive data, controlling access, and maintaining backups. 

Churches needing a broader framework can also use the NIST Cybersecurity Framework 2.0 Small Business Quick-Start Guide. NIST specifically says the resource can assist smaller organizations, including nonprofits. 

Go deeper: Is Your Data Security Up to Speed? A Checklist for Churches

5. Sensitive church data creates privacy and liability concerns

Bottom line: Churches collect more sensitive information than leaders sometimes realize. Protecting that information requires knowing what the church has, where it is stored, and who can access it.

Think about the information flowing through a typical church.

It may include:

  • Donor names and giving histories;
  • Employee Social Security numbers;
  • Payroll information;
  • Background-check information;
  • Children’s ministry records;
  • Member contact information;
  • Counseling information;
  • Prayer requests; and
  • Bank and payment information.

That information can create risk even without a sophisticated cyberattack.

For instance, something as routine as publishing a prayer request can raise privacy concerns.

Attorney and CPA Richard Hammar notes that churches can reduce the risk associated with public prayer lists by obtaining consent before identifying individuals and their needs online. Express consent is stronger than assuming consent because someone didn’t opt out. Cybersecurity and privacy, therefore, increasingly overlap.

Churches should ask:

Do we need this information?

Where are we storing it?

Who has access to it?

How long are we keeping it?

What happens if someone obtains it?

Those questions also matter after a breach.

The FTC notes that every state, the District of Columbia, Puerto Rico, and the Virgin Islands have laws addressing notification following certain security breaches involving personal information. Specific obligations depend on the information involved and applicable law. 

Therefore, churches experiencing a data breach should promptly consult qualified legal and cybersecurity professionals about their response and notification obligations.

Go deeper: Are Public Prayer Lists an Invasion of Privacy?

6. Third-party vendors are part of your cybersecurity perimeter

Bottom line: Outsourcing technology doesn’t outsource risk. Churches should understand how vendors access, store, and protect church information.

Churches depend heavily on outside platforms.

Giving processors, payroll providers, accounting systems, church management platforms, email providers, background-check companies, cloud storage services, and other vendors may possess church information.

That creates another potential entry point.

The 2026 Verizon DBIR found third-party involvement in breaches increased substantially. Verizon reported that breaches involving third parties accounted for 48 percent of breaches in its dataset. 

That doesn’t mean churches should abandon cloud services. But it does mean vendor selection becomes a very important part of a church cybersecurity plan.

Before granting a vendor access to church systems or sensitive information, consider asking:

  • Does the vendor require MFA?
  • How does it encrypt sensitive information?
  • Who can access the church’s data?
  • Does it use subcontractors?
  • How does it respond to a breach?
  • How quickly will it notify the church?
  • What protocols will the vendor follow to comply with notify federal and state authorities?
  • What happens to church data when the relationship ends?

The FTC recommends including security requirements in vendor contracts and limiting vendor access to only the information needed to perform the work. 

7. Cyberliability insurance is becoming part of risk management

Bottom line: A general liability policy should not be assumed to cover cyber incidents. Churches should review available cyberliability coverage and understand exclusions, limits, and conditions.

Even strong cybersecurity cannot eliminate every threat, which is why cyberliability insurance should be considered..

Cyber coverage can address expenses that traditional insurance may not cover.

Depending on the policy, first-party coverage can potentially address costs involving:

  • Data recovery;
  • Forensic investigations;
  • Business interruption;
  • Required notifications;
  • Crisis management;
  • Cyberextortion; and
  • Fraud.

Third-party coverage can potentially address liability arising from claims made by others after an incident. 

However, policies differ considerably.

Church Law & Tax’s review of cyberliability insurance also cautions churches against assuming their general liability policy covers cyber-related claims. Coverage limits, exclusions, premiums, and policy requirements all deserve careful attention. 

Before purchasing or renewing coverage, ask the church’s insurance professional:

  • What cyber events are covered?
  • What exclusions apply?
  • What are the coverage limits?
  • Is ransomware covered?
  • Does coverage include data recovery?
  • Are notification expenses covered?
  • Does the policy provide access to cybersecurity or legal professionals after an incident?
  • What cybersecurity controls must the church maintain for coverage to apply?

Insurance transfers some financial risk. It doesn’t replace prevention.

Go deeper: Navigating Cyberliability Insurance

A church cybersecurity checklist

Church leaders don’t need to become cybersecurity engineers. However, they should know whether fundamental safeguards are in place.

Risk areaQuestion church leaders should ask
MFADo all critical systems support and require multifactor authentication?
StaffDo employees know how to recognize and report suspicious requests?
SoftwareAre systems patched and updated promptly?
AccessCan only necessary people access sensitive information?
DataDo we know what sensitive information we collect and where it is stored?
BackupsCan critical systems and data be restored after an attack?
VendorsHave we reviewed the security practices of key providers?
PaymentsDo financial transactions require appropriate verification and approval?
ResponseDo we know who to contact immediately after a suspected breach?
InsuranceDo we understand what our policies do—and don’t—cover?

Cybersecurity doesn’t have to begin with an expensive new technology platform.

Start by identifying the church’s most important information and systems. Then determine what would happen if those systems became unavailable or that information was stolen.

From there, prioritize the biggest risks.

Frequently asked questions about church cybersecurity risks

What are the biggest cybersecurity risks facing churches?

Churches face risks from phishing, social engineering, compromised credentials, software vulnerabilities, ransomware, data breaches, and third-party vendors. AI is also helping attackers create more convincing scams and accelerate some attacks. 

Should churches require multifactor authentication?

MFA is one of the foundational cybersecurity practices recommended by both CISA and the FTC. Churches should strongly consider requiring it for systems containing financial, personal, administrative, or other sensitive information. 

Does a church need cyberliability insurance?

A church should evaluate its specific cyber risks with a knowledgeable insurance professional. General liability insurance should not automatically be assumed to cover cyber incidents, and cyber policies vary in their coverage, exclusions, and limits. 

What should a church do first to improve cybersecurity?

Start with the fundamentals. Identify critical systems and sensitive data, require MFA, update software, use strong unique passwords, maintain backups, train staff, review vendor access, and establish an incident-response plan. The NIST Cybersecurity Framework provides a structured approach built around Govern, Identify, Protect, Detect, Respond, and Recover. 

Make cybersecurity part of church risk management

Church cybersecurity risks are changing, but the fundamentals remain remarkably consistent. Protect accounts, update technology, train people, safeguard sensitive information, evaluate vendors, prepare for incidents, and understand your insurance. Most importantly, church boards and leaders should treat cybersecurity as an organizational risk—not simply something delegated to the person who manages the computers.

This resource was created with a combination of AI and human review.

The editorial team of Church Law & Tax is made up of Matthew Branaugh, attorney-at-law, and Rick Spruill, digital content manager.

This content is designed to provide accurate and authoritative information in regard to the subject matter covered. It is sold with the understanding that the publisher is not engaged in rendering legal, accounting, or other professional service. If legal advice or other expert assistance is required, the services of a competent professional person should be sought. "From a Declaration of Principles jointly adopted by a Committee of the American Bar Association and a Committee of Publishers and Associations." Due to the nature of the U.S. legal system, laws and regulations constantly change. The editors encourage readers to carefully search the site for all content related to the topic of interest and consult qualified local counsel to verify the status of specific statutes, laws, regulations, and precedential court holdings.

Ask Richie

👋 Hello! I'm Richie, your AI assistant. How can I help you today?
ajax-loader-largecaret-downcloseHamburger Menuicon_amazonApple PodcastsBio Iconicon_cards_grid_caretChild Abuse Reporting Laws by State IconChurchSalary Iconicon_facebookGoogle Podcastsicon_instagramLegal Library IconLegal Library Iconicon_linkedinLock IconMegaphone IconOnline Learning IconPodcast IconRecent Legal Developments IconRecommended Reading IconRSS IconSubmiticon_select-arrowSpotify IconAlaska State MapAlabama State MapArkansas State MapArizona State MapCalifornia State MapColorado State MapConnecticut State MapWashington DC State MapDelaware State MapFederal MapFlorida State MapGeorgia State MapHawaii State MapIowa State MapIdaho State MapIllinois State MapIndiana State MapKansas State MapKentucky State MapLouisiana State MapMassachusetts State MapMaryland State MapMaine State MapMichigan State MapMinnesota State MapMissouri State MapMississippi State MapMontana State MapMulti State MapNorth Carolina State MapNorth Dakota State MapNebraska State MapNew Hampshire State MapNew Jersey State MapNew Mexico IconNevada State MapNew York State MapOhio State MapOklahoma State MapOregon State MapPennsylvania State MapRhode Island State MapSouth Carolina State MapSouth Dakota State MapTennessee State MapTexas State MapUtah State MapVirginia State MapVermont State MapWashington State MapWisconsin State MapWest Virginia State MapWyoming State IconShopping Cart IconTax Calendar Iconicon_twitteryoutubepauseplay
caret-downclosefacebook-squarehamburgerinstagram-squarelinkedin-squarepauseplaytwitter-square