Online Safety For Parishes
And The Importance Of Safeguarding Parish Contact Infomation
Online Safety & Best Practices
In today’s digital age, staying vigilant about online safety is more important than ever. Scammers and bad actors frequently use deceptive tactics, such as phishing emails, scam texts, and social engineering, to exploit individuals and organizations. By adopting cautious practices, we can protect ourselves, our parishes, and our communities from potential harm.
Recognizing and Avoiding Scams
- Think Before You Click: Be wary of unsolicited emails or texts, especially those asking for money, gift cards, or sensitive information.
- Verify the Sender: Even if an email or text appears to come from a known person or organization, verify through a trusted method (e.g., call the official phone number, not the one in the email or text). Communicate with your parish staff or wardens to verify the nature of the message, and report any suspicious calls, text or emails to them right away,
- Look for Red Flags: Poor grammar, vague language, urgent requests, or offers that seem too good to be true are often signs of scams.
- Important Note: you will never be solicited for money in private, individual messages, emails or phone calls. Any asks by clergy or the diocese will be part of a public facing campaign either in church or using verified, official channels, such as parish and diocesan email lists and mailings. Asks for financial support will never be asks to purchase gift cards. Often times these scams come from someone posing as clergy or a church leader wanting to thank staff by purchasing gift cards that they will redeem. This is a huge red flag that this party is attempting a scam.
- Do Not Respond: Avoid replying to suspicious messages or clicking on links—they may lead to malicious websites or confirm your contact information for further targeting.
- Trust Your Instincts: If you believe you have been contacted and that it is malicious, immediately block the sender, use tools by your email and phone provider to report spam or phishing, save a record of the message or attempted contact, and report it immediately.
- Be Aware of Phishing: Phishing is a term used for a link that is sent for a person to click on that then leads to a site that harvests information or somehow uses software to compromise a device or harvest information. Always be careful when clicking or opening links. This is often times a red flag for a potential scam.
Protecting Parish Contact Information
- Limit Access to Directories: Parish directories and personal contact information should only be shared with trusted members of your community. Consider password-protecting or securing digital directories. Do not make directories public facing. Do not display them on your parish website or in public places, such as bulletin/announcement boards.
- Ask for Consent: Before sharing someone’s contact information, ensure they’ve given explicit consent. This respects their privacy and avoids unwanted contact.
- Use Generic Contact Points: Instead of personal phone numbers or email addresses, provide generic parish contact information, such as a shared office email or phone number, on public-facing websites.
Respecting Parishioners’ Privacy
Protecting parishioners’ contact information is not only about avoiding scams—it’s also essential for respecting their privacy. Members of your parish may have personal situations that require additional discretion:
- Sensitivity to Privacy Needs: Some individuals may not wish to be contacted by former partners, acquaintances, or others they no longer associate with. Protecting their contact information ensures their safety and peace of mind.
- Privacy Over Publicity: Avoid publishing contact details in directories, bulletins, or online without explicit consent. Instead, use methods like anonymous email forwarding or centralized contact systems to connect members safely.
- Honor No-Contact Requests: If a parishioner has expressed the need for specific privacy boundaries, respect and enforce those boundaries within parish communications and directories.
Best Practices to Avoid Social Engineering
Social engineering is a means by which parties attempting to take advantage of people use non-digital or non-traditional means to obtain information to use maliciously. This can often times look like a new person attending a service of function (sometimes even more than once) and then asking for a copy of the church directory. These attacks exploit human trust. Follow these tips to stay safe:
- Be Skeptical of Urgent Requests: Scammers often pose as authority figures and claim an emergency to bypass your skepticism.
- Educate Your Community: Provide information for clergy, staff, and parishioners on recognizing common tactics.
- Verify Before Sharing: If you receive a request for sensitive information, verify its legitimacy before acting.
- Stay Aware: If someone new asks for access to your church directory, do not just give it immediately upon request. Have them give you their contact information and say someone from the parish will follow up with them. This will give you an opportunity to verify the legitimacy of the request. Sometimes just this step is enough to dissuade a potential scammer. If you think this may be a legitimate request, consider having a follow-up conversation with the person in questions. Contact them and ask them to come to the office and meet with someone on staff or with clergy to help determine whether they should be given the information they requested.
What to Do If You Suspect a Scam
- Report It: Notify your parish leadership and the diocesan office if you suspect or experience a scam targeting the church.
- Stay Calm: Avoid engaging with the scammer. Block their number or email address and delete the message. Use the tools provided by your email and phone provider to block and limit contact with the party in question, and make sure to report the attempted scam or phish to those platforms.
- Spread Awareness: Inform others in your community to prevent additional scams. Have procedures in place on how you will communicate to your parish community that there was an attempted breach of information and what they should do if they are contacted.
Safety First for Everyone
The Diocese of Central New York is committed to fostering a safe and welcoming environment. By practicing caution, respecting privacy, and educating our communities, we can safeguard against online threats and support a culture of safety and respect.
Please read and download this helpful article and share it with your parish with many of the tools mentioned here, as well as additional ones that can help safeguard your parish: https://cnyepiscopal.org/wp-content/uploads/2025/01/keep-your-directory-safe-from-scammers-_-instant-church-directory-blog.pdf
For additional resources or assistance, contact the diocesan office: [email protected]