For charities, trust is one of their most valuable assets. Unfortunately, it’s also what makes them an attractive target for cybercriminals. Since the beginning of 2025, Scamwatch has received more than 1,500 reports of donation scams, with Australians reporting over $547,000 in losses. As attackers become more sophisticated, many are no longer relying on simple phishing emails or fake social media posts. Instead, they’re creating convincing fundraising websites and fake campaigns that closely imitate trusted nonprofit organisations.
A Campaign That Never Existed
At first glance, there doesn’t seem to be anything unusual about this website. It features professional branding (which has been blocked out to protect our client’s privacy), high-quality imagery, navigation menus, a contact page, cookie banner, terms and conditions, donation functionality, and dozens of luxury auction items available for bidding. Everything about the website suggests it’s promoting a legitimate fundraising campaign.
The website claimed to be hosting an exclusive charity auction linked to a major international sporting event, offering supporters the opportunity to bid on luxury holidays, VIP sporting experiences, and signed memorabilia.
The problem was this campaign never existed, and the website had no affiliation with our client.
Rather than cloning an existing fundraiser, the attackers created an entirely fictional campaign using our client’s branding. They combined the identity of a very well trusted charity with the reputation of a globally recognised sporting event, then built a convincing fundraising website around it.
What makes this particularly effective is that none of the individual elements feel out of place. Charities regularly run fundraising campaigns and charity auctions. Sporting organisations frequently partner with charities, and exclusive experiences are commonly auctioned to raise money. A professionally designed website only reinforces the illusion that the campaign is legitimate.
Individually, none of these elements are suspicious. Together, they create a campaign that feels entirely believable, making it far more likely that supporters will trust what they’re seeing.
Check the Website Domain Name
One of the easiest ways to identify a fake charity website is by checking the domain name.
Branding can be copied. Images can be copied. Website layouts, logos and wording can all be replicated to look like the real thing. The domain, however, cannot be exactly copied.
Before making a donation, take a moment to check that the website address matches the charity’s official domain. Be cautious of lookalike domains, unexpected spelling variations, additional words or unfamiliar domain extensions. If something doesn’t look right, don’t enter any personal or payment information.
For Australian charities, it’s also worth verifying that the organisation is registered with the Australian Charities and Not-for-profits Commission (ACNC). The ACNC Charity Register allows you to search for registered charities and access links to their official website, making it easier to confirm you’re donating through the correct organisation.
A few extra seconds checking the domain and verifying the charity can help ensure your donation reaches the cause you intended to support.
Why This Matters for Charities
A fake charity website doesn’t just put donations at risk. It can also damage the trust that charities work so hard to build with their supporters.
When donors come across fraudulent websites using a charity’s name and branding, it can create confusion about which website is real. Even if they don’t lose money, supporters may become hesitant to donate in the future or question the authenticity of legitimate fundraising campaigns. Charities may also see an increase in enquiries from concerned supporters, reputational damage, and additional time spent responding to incidents instead of focusing on their mission.
It’s also important to remember that these attacks are rarely isolated. Cybercriminals don’t typically create a single fake website and stop there. They often register multiple lookalike domains, impersonate organisations across social media, reuse the same infrastructure, and launch new campaigns as older ones are identified and removed.
Understanding the wider campaign, rather than just the individual website, helps organisations identify related infrastructure, uncover additional impersonation domains, and disrupt threats before they spread further. Instead of responding to one fake website at a time, charities can take a more proactive approach to protecting both their brand and their supporters.
Protecting Your Charity from Brand Impersonation
The sooner a fraudulent website or impersonation campaign is identified, the sooner it can be investigated and disrupted before more supporters are affected.
unphish continuously monitors for brand impersonation across domains, websites, social media, mobile applications and other online channels, helping organisations identify fraudulent campaigns before they gain momentum.
(unphish’s threat intelligence showing how threats are connected)
But detecting a single fake website is only part of the picture. unphish’s Campaign Clustering and Intelligence capabilities help uncover the wider campaign by identifying related domains, websites and infrastructure that may be linked to the same threat actor. This provides organisations with greater visibility into how an attack is evolving, rather than treating each incident as an isolated case.
Combined with threat intelligence, investigation tools and evidence-backed enforcement, organisations can identify coordinated attacks earlier, disrupt them more effectively, and better protect both their brand and their supporters.
To learn more about how unphish helps charities detect and disrupt brand impersonation, get in touch with our team.
