Invitation to a scam: A Second Wave journalist clicked the wrong link. It nearly broke the bank.

As artificial intelligence and industrial-scale scam operations grow, online fraud is becoming harder to detect. Even those of us trained to pay attention to words can be caught off guard. In this personal account, a Second Wave journalist shares how one seemingly ordinary click nearly led to disaster — and what she learned about protecting herself.

Editor’s Note: Even the most cautious of fraud-wary and fact-checking journalists can get hooked by an email scam. We offer this account so you can beware of the level of sophistication and nuance these schemes can employ, along with a few tips on how to protect yourself.

Online scams happen when technology is used to trick, harm, or steal money and/or personal information. This can happen in various ways, like through emails, texts, phone calls, websites, or software. Photo: Shutterstock

The subject line read “Professional Reference Request.” 

The email was from a former pastor of my previous church, who now attends a church in Portage where I know a search is ongoing for a new pastor.

I have had enough leadership positions at the churches I have attended that this request did not raise the red flags it should have. 

There was none of the manufactured urgency or threatening language that would have triggered my suspicion. 

Just a simple request:

We are currently reviewing an applicant for a position within our organisation and understand that you have been nominated as one of their professional referees. We would appreciate the opportunity to learn more about your experience working with the applicant.

Your feedback regarding their previous position, responsibilities, performance, reliability, workplace conduct, key strengths, and overall suitability for the role would be particularly valuable to us.

For reference, we have included the applicant’s résumé along with our

Reference Verification Form (link)

We kindly ask that you complete the form and return it to us at your earliest convenience.

If you require any additional information or have questions about any part of the verification process, please do not hesitate to contact us.

Thank you for taking the time to assist us. We greatly appreciate your cooperation and the insight you can provide as we make our hiring decision.

Kind regards.

Now that I know this is a scam, I see that I might have noticed the odd wording or the potential typo in the phrase “you have been nominated as one of their professional referees.”

Instead, nothing set off alarm bells. 

I unwittingly clicked on the Reference Verification Form link. Next, the screen showed a multi-factor authentication prompt in which you matched the numbers on your screen to those on your phone. At first, none of the numbers matched, which should have been another clue this was a scam. Believing I simply needed to keep trying, I continued to click on the screen as the numbers kept changing. Eventually, a number matched. 

The scammers sent an invitation to random email addresses from Kathy Jennings’ email box. Notice that the invitation says it is from George Leroux, who is unknown to Jennings. Those who received the invitation said they could not open it.

My browser also saves my passwords, and it asked me then if I wanted to save a password, but the username was bizarre, like Xgenex something — nothing I would have created. I did not allow Chrome to save it.

The file on my screen then tried to redirect me to a page about real estate, and I finally caught on that a scam was in progress. I clicked out of everything as quickly as possible.

I contacted the person who the original email request was supposed to be from, sending a new email rather than hitting reply. He confirmed he had been hacked.  

Soon after that came the email: “Your ACH source Frederick Bletzacker has been successfully set up.” The scammer had set up an automatic withdrawal. 

With shaking hands, I tried to log into my bank, and because I was panicking, I typed in the wrong info and became convinced they had stolen my bank credentials. I immediately called the fraud number on the bank’s website. And got a phone tree. I kept yelling “Fraud” at every question the automated operator asked me. Then she said, “I can’t help you.” As I sat in stunned disbelief, staring at my phone, they transferred me to the fraud department. 

The kind gentleman on the other end of the cellphone connection talked me down, and together we realized that I could get into my account using the correct username and password. As I hung up, I realized the theft was not from my bank account. I looked at the ACH email again. It was generated not by my bank, but by my credit union.

When I went to its website and tried to log on, a red message was emblazoned across the top of the page: We’ve prevented a suspicious attempt to log in to your account. If you feel that this was a mistake, please call us or visit a branch.

Their fraud department had caught the scammer before any money left the account where I keep my emergency funds. I started to breathe normally again.

The next day I went to each of my three banks. I don’t know how my phone connected to my credit union account since I have never used my phone to access it. But the credit union was the only one that the bad guys had gotten close to hacking. I waited in the lobby where, fittingly, a video screen displayed a message warning that fraudsters were getting more sophisticated. It urged people to avoid doing a generic search for the credit union by name, but instead to always search for the credit union’s URL.

Within minutes, a nice woman with two awards from her employer that said she was a star gave me a seat in her office. She connected me to the fraud department and waited patiently while I answered their questions. Had I ever permitted Frederick Bletzacker to use my account? No. No, I had not. Had the scammers taken over control of my devices? Not exactly. I explained the whole episode while the fraud department took notes. In the end, they said they would open a new account for me once I sent them receipts that showed I had cleaned my phone and my computer so that my new account would not be immediately compromised. 

The visit to Best Buy to get those cleaned up cost $199. 

The evening of the breach and the next day, I received questions from friends and family asking if I had sent out an invitation. Those from my email contacts list who received the invite seemed random: my snowplow service, my cousin in Texas, my high school friend in Vermont, a co-worker in Detroit. One sent a reply to the invitation asking if it was legit, and the bot on the other end told them, yes, it’s safe to click on the invitation. Luckily, my tech-savvy friend knew better. 

Online scams happen when technology is used to trick, harm, or steal money and/or personal information. This can happen in various ways, like through emails, texts, phone calls, websites, or software. Photo: Shutterstock

An email that said it was from me also went to the person whose email started this whole chain of events. The subject line was Be Safe. It said: “Use this link for your computer to be safe.” The original emailer sent it to me asking what the link provided. Not knowing if this message was really from my former pastor, I did not respond. Looking back, I realized there are always clues. This email was dated Monday, Sept. 28, 2026. September 28 — the day this all was happening — was a Wednesday.

I am not certain of the correct etiquette for warning someone that you have inadvertently sent them an invitation that can hijack their email list. So, not knowing how many of these “invitations” the scam network had sent, I went to Facebook to warn as many people as I could to be wary. I also sent out an email to those I thought most likely to have received one.

Another bizarre aspect of this episode is that during this process, my email box filled up with at least 108 emails from what appeared to be every subscription account I own and some I have not accessed for years. They all wanted me to verify my account. 

I have since found out that these scams are on the rise. Recent polling conducted by Progress Michigan in partnership with Public Policy Polling shows that more than six in 10 Michiganders have experienced an online scam. 

A 2026 report by the Consumer Federation of America (CFA) found that Michiganders lost $381 million from online scams, driving an estimated true annual loss of $2.7 billion, or $654 per household.

“Michigan’s $2.7 billion scam industry isn’t just a tech problem — it’s a direct raid on our state’s working class,” says Justin Mendoza, executive director at Progress Michigan. “Digital predators are getting away with draining the hard-earned pensions of auto industry and public sector retirees. A lifetime of honest Michigan labor is being turned into a multi-billion-dollar goldmine for cybercriminals.”

Overall, the FBI’s 2025 Internet Crime Report shows cyber-enabled crimes defrauded Americans of nearly $21 billion, with cryptocurrency and artificial intelligence-related complaints among the costliest.

Online scams happen when technology is used to trick, harm, or steal money and/or personal information. This can happen in various ways, like through emails, texts, phone calls, websites, or software. Photo: UnSplash, Brett Jordan

The Internet Crime Complaint Center received more than 1 million complaints, an increase from 859,532 in 2024. Phishing or spoofing, extortion, and investment schemes were the most frequently reported complaints. Americans over 60 (like me) reported approximately $7.7 billion in losses, up 37% from 2024.

Scams involving pastors’ email contacts are part of this surge. Ministry Watch, which covers waste, fraud, and abuse among Christian ministries, reported in August 2025 that nearly 43% of North American cyberattacks target ministries and nonprofits. It happens because “churches operate in high-trust, low-tech environments.” Email addresses are publicly listed, volunteers handle tech or administrative work, and members tend to trust messages purportedly sent by leadership.

Through this, I have learned that no matter how many AARP scam alert stories I read, I am not as savvy about online attacks as I thought. I believe I have learned to read more closely any email that asks me to click a link. I know I have learned the importance of taking a deep breath before calling the fraud department and not allowing a phone tree to freak me out. 

Today, I take some comfort in the revelation that even though scammers are getting more sophisticated, new technologies to thwart these attacks are being developed and deployed. This time it was a close call. May I be more cautious next time.

Here are ways to protect yourself from phishing attacks offered by the Federal Trade Commission and by AARP.

Author

Kathy Jennings was the founding managing editor of Southwest Michigan’s Second Wave. She has more than 40 years of experience as a journalist, including 25 at the Kalamaaoo Gazette. She is a freelance writer and editor.

Our Sponsors

Gilmore Foundation

Our Media Partners

Battle Creek Community Foundation
BINDA Foundation
Southwest Journalism Media Collaborative
Southwest Michigan First
Milestone Senior Services
Consumers Energy

Don't miss out!

Everything Southwest Michigan, in your inbox every week.

Close the CTA

Already a subscriber? Enter your email to hide this popup in the future.