About Us

Parishioner Online Safety

Phishing Alert

 

October 7, 2026 — Scammers have recently sent a phishing email purporting to be Mother Sally requesting a reply to a "discreet matter." This is a scam. Please do not respond to this email.

St. Paul's relies on email as a form of communication to stay connected with our parish. Although it is essential in a digital world, email can also be dangerous. Cybercriminals are taking advantage of email-based communication by creating and delivering impersonation-based scams to our parishioners.

Nobody at St. Paul's will ask you to buy gift cards, wire money, or anything else that involves financial requests via email or text.  This includes clergy, Vestry, lay ministry leadership, and administrators. When in doubt, always and immediately contact our church office to report potentially suspicious email requests.


Protect Yourself from Fraudulent Messages

 

Unfortunately, spoofing, phishing, and whaling scam emails and text messages are increasingly common, and members of trusted institutions, like St. Paul's, are frequently targeted for these campaigns because people are more likely to open an email when they think it has been sent by a legitimate or familiar source. It's important to stay alert and protect yourself. Here's what you need to know to stay safe.

 

What are Spoofing, Phishing, and Whaling?

Spoofing: This is when an attacker disguises themself as a trusted source by faking information like an email address, phone number, or website — to make it seem legitimate.

Example: an email appears to come from "yourboss@company.com" but really comes from a scammer at "yourb0ss@companny.com"

 

Phishing: A cybercrime where scammers send emails or texts pretending to be from legitimate organizations to trick you into revealing personal information such as passwords, bank accounts, or credit card numbers.

Example: An email that looks like it's from your bank asking you to "verify" your account details.

 

Whaling: A specific form of phishing that targets high-profile individuals (like clergy or other leadership) or impersonates them to deceive others into providing sensitive information, sending money, or clicking malicious links.

Example: A fake email sent to a company's CFO requesting a secret wire transfer.

 

Common Signs of a Scam

  • Messages privately requesting money or gift cards.
  • False urgency, the message demands immediate action or threatens penalties if you don't "act now."
  • Odd language or tone that doesn't sound like the person you know.
  • Requests for sensitive information (passwords, Social Security numbers, banking details)
  • Unexpected links or attachments. Never click, but hover over links and email addresses to reveal odd URLs or gibberish sender addresses.
  • Emails or texts from addresses that seem close to, but are not, official St. Paul's domains (like staff.stpaulshbg@gmail.com instead of a verified address). Carefully examine the email address, URL, and spelling used in any correspondence. Scammers use slight differences to trick your eye and gain your trust.

 

What to Do If You Receive a Suspicious Message

  1. Do not respond
  2. Do not click any links or open attachments
  3. Verify independently — call the St. Paul's office or the sender using official contact information.
  4. Report the scam to your email provider by marking them as junk or spam and for email scams impersonating St. Paul's staff, also notify us here or by phone at (707) 433-2107.

 

Useful Resources for Learning More

How to Recognize and Avoid Phishing Scams — Federal Trade Commission

How to Recognize and Report Spam Text Messages — Federal Trade Commission

Phishing and Spoofing — FBI Internet Crime Complaint Center

 


CONTACT US


ST. PAUL'S EPISCOPAL CHURCH

209 Matheson St
Healdsburg, CA 95448

(707)433-2107

CLICK HERE TO CONTACT US

QUICK LINKS


  GIVE
  YOUTUBE
  FACEBOOK
  CALENDAR