Scam Awareness: How to Recognize a Scammer’s Cover Story

Today's scammers don't rely on luck. Scam awareness is essential because scammers often research their targets through social media, company websites, public records, and previous data breaches before reaching out. They gather details that make their requests seem legitimate and familiar.
A cybercriminal may pretend to be:
A coworker needing urgent help
A supervisor requesting a quick favor
A vendor following up on a payment
A church leader needing gift cards purchased
A financial institution verifying account information
Technical support trying to "fix" a problem
The story may sound believable, but that's exactly the point.
Watch for These Red Flags
🚩 Urgency
"I need this done right now."
"Don't wait for approval."
"This is an emergency."
🚩 Bypassing Normal Processes
Requests that ignore established procedures
Pressure to avoid verification steps
Demands for secrecy
🚩 Unusual Requests
Gift card purchases
Wire transfers
Password sharing
MFA approval requests
Sensitive information requests
🚩 Details That Don't Quite Match
Unexpected email addresses
Slightly altered names or domains
Communication styles that seem unusual
Inconsistent explanations
How to Protect Yourself
Stop and Think
When a request creates pressure or urgency, take a moment before responding. Most legitimate business requests can withstand a brief verification process.
Verify Through a Trusted Method
If someone requests money, sensitive information, password resets, or account changes:
Call them using a known phone number
Contact them through a verified Teams message or email
Confirm the request through established channels
Follow Established Procedures
Policies and approval processes exist for a reason. Cybercriminals frequently try to convince people that "this one time" the rules can be skipped.
Report Suspicious Activity
If a message, phone call, or request appears suspicious:
Use the Report Phishing button if available
Contact the Service Desk
Forward the message to the Security Team
Remember: Verify, Then Verify Again
The best defense against social engineering is healthy skepticism. Even when a request appears to come from a trusted source, take a moment to validate the story before taking action.
Cybersecurity is everyone's responsibility, and a few extra seconds spent verifying a request can prevent significant financial loss, account compromise, or data exposure.
Questions on how to protect your ministry? Reach out to Rob Jett at rjett@gcfa.org.

