07/06/2026
Dear Church,
There is a Trojan horse floating around in an email that appears to be an invitation to an event or party. It will appear to come from a person you know and an email address you recognize, but the sending was automated and the intent is malicious.
Once you click the link, it will send to some or maybe all of the people in your address book. It might send to those with whom you’ve recently exchanged emails. The possibility exists that it can propagate through texts as well. If this was only a nuisance, I might just let it pass over, but if you can be convinced to click a link and “accept an invitation,” then you have potentially let a scammer steal your credit card and/or bank account information.
Several church members have received this email, and more than one has clicked it. At least one person’s financial account has been compromised already.
As good Christian folks, we often fail to see the evil and danger because we would not seek to hurt others. And when you see an email from a church member, you’re automatically disposed to trust it. Understand that scammers want to take advantage of your trusting nature (which is a good thing) but then use it for evil. Here are a few tips:
* Only click links in emails that you have requested or are expecting. This goes for “business” or “bank” emails too as professional swindlers will go to great lengths to copy the real thing. There are a few ways to make sure the links and emails are legitimate, but for now I won’t attempt to run a cybersecurity class. I want you to default to skepticism rather than trust.
* If a friend sends you an email or text or private message which tempts you to click, open or look at something, use a different means of communication to verify with that friend that he/she has sent something legitimate. A Facebook message that asks you to click may have come from an account of a good friend, even your best friend, who has clicked on such a link from another friend. Or your friend’s account may have been compromised, so sending a message through the same medium asking, “is this legit?” is going to be answered “yes,” because the scammer is impersonating your friend by means of a stolen account. If you get a weird email, call or text the sender to verify. You may be the first one who has alerted the sender that something is afoot.
* Speaking of instant messaging through Facebook, Instagram, SnapChat, etc., always assume that the ultra-beautiful or ultra-rich face that is on the account is not a true representation of the person on the other end of the communique. Leonardo diCaprio, Angelina Jolie, Melania Trump, or Elon Musk is not sitting around bored hoping that you’ll chat with him/her.
* In today’s world of AI, you can receive a phone call and the voice on the other end is a perfect match with a loved one’s voice. Families should set a password that only they know, so when you get a strange or frantic message from a parent, child, or grandchild that sounds like an emergency request for money, bail, etc., you are able to ask the password or say an uncommon phrase that will cause the other person to say a corresponding phrase to verify that the call is real. (AI can’t copy that.) Example: “Hey Grandma, this is Corey, I’ve been in an accident and need you to CashApp/Zelle/Venmo/wire me $400 real fast.” You ask, “What’s the weather like there?” which seems rather ridiculous in light of a potential emergency. But the correct answer to the challenge (since you previously agreed on it) is “The rain in Spain falls mainly on the plain.” Any other response is the wrong one and you know the call is AI. (Now, you can’t use that one because I’ve used it; create your own!)
Be careful out there, church.