Every not-for-profit spends years earning the same thing: a name people believe in. Donors give because they trust where the money goes. Beneficiaries reach out because they trust the people on the other end. Volunteers show up because they trust the mission. That trust is the whole engine of the sector, and it’s exactly what scammers have learned to steal.
However, here is what’s becoming an uncomfortable truth across multiple industries. A criminal doesn’t need to breach your servers, crack your passwords, or slip malware past your firewall. Why bother, when they can simply put on your face and walk into public wearing it? The most damaging attacks aimed at charities today don’t happen inside your systems at all. They happen out on the open web, where trusted brands from institutions that are often over 100 years old do the convincing for them.
The near-perfect crime
Consider a cloned donation page. A scammer copies your real one (your logo, your colours, your campaign language) and registers a domain a whisker away from yours. An extra hyphen. A missing letter. Then they drive traffic to it through phishing emails or paid advertising, and wait.
A supporter arrives, sees your branding and generously enters their card details. The money lands in a criminal’s account. Their card is now compromised too. And your real campaign never sees the donation.
What makes this so insidious is that it may be one of the closest things to a perfect crime. Think about who gets defrauded and how. Someone who buys a fake product online eventually notices the parcel never arrives, and complains. But someone who donates isn’t expecting anything back in the mail. There’s no missing delivery, no follow-up, no moment where the penny drops. They gave, they felt good, and they moved on – never knowing the money didn’t reach you. The only people who might have caught it are the two parties kept furthest from the transaction: the donor who trusted your name, and you.
Impersonators reaching real people
While fake donation pages are the financial version of this problem, there’s also a human version.
Scammers stand up counterfeit “official” social accounts, copy your branding, and reach out directly to the people who trust you most. Sometimes that means running bogus fundraisers under your name. Sometimes it means messaging supporters in your voice. And unfortunately it often means contacting vulnerable people posing as a caseworker, a support officer, someone from the team, or even offering loans.
For organisations working with people in financial hardship or crisis, an impersonator wearing your name is both a fraud risk and a safety risk to the very people you exist to protect. The trust that lets you do good is the same trust that, in the wrong hands, does harm.
Why charities are hit hardest
None of this is unique to the NFP world, but three things make the sector especially exposed.
Your brand is recognisable and widely trusted, which is precisely what impersonation depends on. Your supporters are emotionally primed to act. During a big appeal, people want to click and give quickly, and as we know urgency is a cyber criminal’s best friend. And most charities simply don’t have a mature cyber security team watching for lookalike domains or fake profiles, let alone the resources to get them taken down fast.
The result is a wide-open window, and it opens widest exactly when you’re most active. Major campaigns and disaster-relief moments are peak season for impersonation. Your genuine messaging volume spikes, supporters are expecting to hear from you, and the noise gives the fakes cover.
Protecting the name you built
The good news is that this is a solvable problem, and it starts with visibility. You can’t take down what you can’t see.
That means actively monitoring for brand impersonation across the open web and social media before a campaign rather than after the damage is done, moving quickly to have fakes removed, and making it easy for supporters to confirm they’re on your real page. It also means treating brand protection as part of the mission rather than an afterthought. Every fake page taken down is a donor’s money that reaches you, and a vulnerable person who stays safe.
Your name is the most valuable thing your organisation owns. It’s worth defending as fiercely as you built it.
