Key Points:
- The New England Conference is working to recover after a cybersecurity incident resulted in the theft of $1.6 million.
- Conference leaders are also taking steps to help fellow United Methodists prevent wire fraud.
- The conference especially warns church staff members of how fraudulent actors often get into computer systems by creating a false sense of crisis.
The United Methodist Church’s New England Conference is working to recover after a cybercrime incident resulted in the theft of about $1.6 million earlier this month.
The theft occurred on Aug. 5. Now, the conference is working with the FBI, Secret Service, IT investigators and lawyers trained in cyber theft in the investigation.
“Everyone is aware that it will not be an easy task to recover from this loss. Yet we remain committed to the difficult work that lies ahead,” wrote Bishop Thomas J. Bickerton and Lonnie Chafin in a joint Aug. 13 email to the conference. Bickerton leads both the New England and New York conferences, and Chafin is both conferences’ treasurer.
Conference leaders also hope to help other ministries avoid similar acts of wire fraud. Shortly after the incident, Bickerton sent a letter notifying the Council of Bishops, while simultaneously, Chafin sent a letter to fellow conference treasurers alerting them to the fraud.
In a subsequent conference email on Aug. 25, Bickerton likened the conference’s task of rebuilding to Nehemiah’s experience of rebuilding Jerusalem’s broken walls after his people’s return from exile.
“The story of Nehemiah reminds us that rebuilding broken walls takes more than just prayer and contemplation, more than just course correction and deep analysis,” Bickerton wrote. “Rebuilding what has been lost requires leadership and shared responsibility.”
He is asking for church members to increase their giving to help the conference adjust to the financial loss and to attend cybercrime training to increase awareness and take necessary precautions.
Help stop cybercrime
Both the General Council on Finance and Administration and United Methodist Communications have resources to help church leaders enhance their cybersecurity and prevent church scams.
“New Englanders are resilient and determined people,” Bickerton wrote. “I know that you step up when you witness exploitation and injustice. I know that you respond when a clear need exists. And today, that need exists within our own family, within the connection that binds us together in mutual mission and ministry.”
In the Aug. 25 email, Bickerton said the conference has learned that three other companies faced the same type of crime the same week as the conference’s ordeal.
“With assistance from the authorities, we have gone through every detail of the events of that day,” he said. “We have re-examined our procedures and protocols. We clearly understand the aspects of this crime that are outside our control. And, we have been honest about the things we could have done better.”
The conference has retained an accounting firm for oversight of all disbursements and to redesign internal controls. Conference leaders have also engaged a forensic IT investigative firm that is exploring the range of activities engaged by the thieves.
The IT firm’s initial report has confirmed that there has been no breach of any personal information taken from the conference database.
“We have discovered that these perpetrators are highly professional and sophisticated and that training in cybersecurity and awareness is essential throughout the connection,” Bickerton stated.
Chafin told fellow treasurers that fraudulent actors posing as bank representatives were able to gain access by creating a false sense of crisis. He urged more training to help staff not only recognize potential threats but also be wary of a false sense of urgency.
All told, Chafin said, the criminal actors attempted 40 wire transactions from a single conference bank account. Each transaction was slightly less than $50,000, the limit the conference had established in its banking system. The bank stopped eight transactions. But 32 went through, resulting in the loss of about $1.6 million.
Subscribe to our
e-newsletter
Chafin said the money was sent to 32 different bank accounts in 25 countries, and then immediately transferred to other accounts to keep the funds out of law enforcement’s reach.
Adding to the sense of loss, over the past 18 months, the New England Conference has been working to improve its financial position and integrity. At their annual conference in June, New England clergy and lay voters approved a 2027 budget totaling $6.8 million, a 3.7% increase over 2026.
Both Bickerton and Chafin are also financial leaders in the denomination. Bickerton serves on the board of the denomination’s General Council on Finance and Administration. Chafin just completed a term as president of the National Association of Annual Conference Treasurers.
In this challenging period of investigation and recovery, Bickerton and Chafin both asked fellow United Methodists for their prayers.
“In the days ahead, please pray for our staff as they shoulder the burden of this matter,” the two wrote in the Aug. 13 email. “Pray as well that we might be able to quickly find our way once again to focus solely on the mission and ministry of the church to which we have been called.”
Hahn is assistant news editor for UM News. Contact her at (615) 742-5470 or newsdesk@umnews.org. To read more United Methodist news, subscribe to the free Daily or Friday Digests.