The National Anti-Scam Centre is warning Australian churches about a fraud that turns ordinary parish trust into a bulk purchase order. Scammers are impersonating pastors, parish administrators and other church leaders, then pressuring treasurers and finance volunteers to buy prepaid cards in large quantities and send back the redemption codes, according to an ABC News report on the scheme.

The pattern is familiar to anyone who has watched business email compromise move through schools, clubs and charities. A message arrives from what looks like a known church email address or phone number. The sender says they are in a meeting, travelling, or handling a confidential matter and cannot take a call. They need gift cards urgently — for staff rewards, emergency support, a donation, or a supplier. The treasurer is asked to buy several cards, scratch the back, photograph the codes and send them quickly.

What is confirmed

The ABC reported on 23 September that scammers are targeting churches in a gift card scam. The National Anti-Scam Centre, which runs Scamwatch, has been warning about impersonation scams that rely on urgency and trusted identities. The mechanics in the church cases fit that model: the offender does not need to break into a bank account. They only need a treasurer to believe the request is real and act before making a routine verification call.

Once the codes are sent, the cards can be drained almost immediately. Prepaid cards are attractive to criminal groups because they are easy to buy in bulk, easy to transfer and hard to trace once the balance is spent. A church that realises the mistake an hour later may find the cards empty.

Why treasurers are the target

Church finance roles are often volunteer-run. Treasurers may handle reimbursements, donations and petty cash alongside full-time jobs. They know their clergy and office staff well, and they are used to acting on requests from people they trust. That combination is exactly what impersonators exploit.

In many congregations, payment approvals are informal. A single treasurer may have access to a card, a bank account and an email inbox. When a message appears to come from the senior minister and carries a tone of confidentiality, the normal instinct to ask a second person can feel disloyal or unnecessary. The scammer supplies the urgency: “I need this before the meeting ends,” or “Please don’t discuss it with anyone yet.”

How to verify before buying

The National Anti-Scam Centre’s consistent advice is to stop and verify through a separate channel. Do not reply to the message. Do not use the phone number or email address in it. Call the person on a number already stored in the church directory, or walk down the hall and ask them face to face. If the request is real, a short delay will not break it. If it is fake, that call is the moment the scam collapses.

Churches can also tighten internal controls without turning the office into a bank. Require two people to approve any prepaid card purchase or electronic transfer above a modest threshold. Ban code sharing by email, text or photograph. Treat any urgent request that includes a change of bank details or payment method as a red flag. Keep a current list of approved suppliers and verify new payment instructions by phone using a known contact.

Scamwatch recommends reporting scams quickly. If money has been lost, the treasurer should contact their bank immediately, then report to Scamwatch and their local police. If a church email account has been compromised, the IT provider or email host should be brought in to secure the account and check for forwarding rules. The faster those steps happen, the better the chance of freezing funds, though prepaid card losses are often difficult to recover.

Who carries the loss

Liability in Australian scam cases is rarely straightforward. A bank may argue the payment was authorised by the customer. A prepaid card issuer may say the codes were valid when used. A church may find its insurer asking whether volunteers followed reasonable financial controls. The outcome can turn on the bank’s terms, the speed of the report, the type of payment and whether the transaction was processed by a human or an automated system.

That is why prevention matters more than after-the-fact argument. Once a code is shared, the money is usually gone. The strongest protection is a culture where a treasurer can say “I will call you back” without hesitation — and where every urgent bulk order gets a second look.

What is still unknown

Public reporting so far has not set out how many Australian churches have been hit, how much money has been lost, or whether a specific investigation has been opened. The National Anti-Scam Centre has the national picture through Scamwatch reports, but individual cases may sit with state police or the banks. Churches that have received a suspicious request should report it even if no money was lost; those reports help agencies map the campaign and warn other treasurers.

The scam is not sophisticated in a technical sense. It relies on trust, urgency and a payment method that moves value the moment a code is read aloud or photographed. For church treasurers, the defence is simple but must be deliberate: verify before you buy, and never treat an urgent prepaid card request as routine.