Phishing Attacks on Charities: Real Cases and a 10-Minute Team Checklist

Phishing is the most common cyber attack affecting UK charities, according to government figures, and it works because small teams trust each other and move fast, a culture fraudsters deliberately exploit. Three anonymised real cases, including a fake chair email and an invoice redirection, each had one simple control that would have stopped them. A 10-minute team training session run quarterly closes most of the gap between having a policy and staff actually spotting the email.

Why phishing works on charities

You’ve just opened an email from your chair asking for an urgent same-day transfer — or from a long-standing supplier with “updated bank details.” Before you act on it (or delete it and quietly move on), give this page ten minutes: charity phishing follows a small number of patterns, each with a cheap control that stops it cold. I run a small charity myself, so these emails land in my inbox too. Phishing works on charities because small finance teams, high trust between colleagues, publicly listed trustee names, and constant pressure to move money quickly for beneficiaries create the perfect conditions for a convincing fake email. Fraudsters research your website, your annual report and your social media, then impersonate someone you already trust.

Government data backs this up. The Cyber Security Breaches Survey 2024 found that 32% of UK charities reported a cyber security breach or attack in the previous 12 months, rising to 66% among high-income charities with £500,000 or more in annual income. Among charities that experienced a breach, phishing was involved in 83% of cases, making it by far the most common attack type. The Charity Commission has separately reported 603 fraud-related cases and 99 cyber crime cases opened with them in a single year.

Charities are attractive targets for three structural reasons:

  • Public trustee and staff information. Names, job titles and even email formats are often published in annual reports and on the Charity Commission register, making it easy to spoof a “chair” or “CEO” email.
  • Thin finance teams. Payments are frequently authorised by one or two people, so there is often no second pair of eyes to catch a fraudulent instruction.
  • A culture built on trust and urgency. Staff are trained to respond quickly to beneficiary and donor needs, which is exactly the instinct a well-crafted phishing email exploits.

That first bullet isn’t hypothetical: my own name and trustee role sit on the public Charity Commission register, exactly like yours — everything a fraudster needs to fake a plausible “chair” email.

None of this means charities are careless. It means the sector’s operating model is naturally exploitable, so controls have to be built in deliberately rather than assumed — the same build-it-in principle that runs through our charity compliance handbook. The three cases below show what that looks like in practice.

Case 1: the fake chair email (CEO fraud)

In this anonymised case, a mid-sized charity’s finance officer received an email that appeared to come from the chair of trustees, marked urgent, asking for a same-day bank transfer to “secure a partnership opportunity.” The email used the chair’s real name and writing style, sent from a lookalike domain one letter different from the charity’s own.

This is a classic example of CEO fraud, also called business email compromise. The attacker had likely studied the charity’s published trustee list and annual report to identify who could authorise payments and who they would plausibly hear from. The email created urgency (“before the bank closes today”), secrecy (“don’t loop in the rest of the board yet”) and authority (impersonating the most senior volunteer in the organisation) all at once, which is the standard playbook for this type of attack.

In this case, the finance officer paused because the domain looked slightly wrong on close inspection and the request broke from the charity’s usual payment pattern. They called the chair on a known number rather than replying to the email, and the fraud was stopped before any money moved.

The control that would have stopped it: a mandatory callback to a pre-verified phone number for any payment request that is urgent, unusual in size, or asks for secrecy, no exceptions for seniority. This single rule defeats almost every CEO fraud attempt, because the fraudster cannot control what happens on a phone call to a number they don’t have.

Case 2: invoice redirection

Invoice redirection fraud happens when a criminal intercepts or spoofs correspondence with a genuine supplier and sends new “updated” bank details, so the charity’s next legitimate payment goes straight into the fraudster’s account instead of the real supplier’s. It typically relies on the charity’s accounts payable process trusting emailed bank detail changes without independent verification.

In this anonymised case, a charity’s regular IT support supplier appeared to email finance with new bank details ahead of a routine quarterly invoice, citing “a change of banking provider.” The email thread looked genuine, including previous correspondence quoted below the new message, because the supplier’s own email account had likely been compromised earlier and the attacker was simply watching and inserting themselves into an existing conversation.

The payment, running into several thousand pounds, was processed against the new details. The charity only discovered the fraud when the real supplier chased for non-payment weeks later. By then the funds had been moved on and recovery was extremely limited, a common outcome in invoice redirection cases reported to Action Fraud.

The control that would have stopped it: never change a supplier’s bank details based on an email alone. Any change to payment details must be verified by phone, using a number already held on file, never a number provided in the email itself. This is one of the cheapest and most effective controls a charity can put in place, and it costs nothing beyond staff discipline.

Case 3: the donor-data phish

A donor-data phish targets the systems or staff who hold supporter and donor records, typically through a fake “your account is locked, click to verify” email sent to a fundraising or database administrator, aiming to harvest login credentials for the CRM or donation platform. Once inside, attackers can export donor data, redirect direct debit details, or use the trusted domain to send further phishing emails to the charity’s own supporters.

In this anonymised case, a fundraising assistant received what looked like a routine notification from the charity’s CRM provider warning that their password would expire and needed to be reset via a linked page. The page was a convincing clone of the real login screen. The assistant entered their credentials, and the attacker used them to access donor records, including names, addresses and giving history for several thousand supporters.

Because personal data was involved, this incident triggered obligations under UK data protection law as well as charity regulation. A significant data breach or loss involving personal data is one of the categories the Charity Commission expects to see reported as a serious incident, and depending on the risk to individuals it may also need to be reported to the Information Commissioner’s Office within 72 hours. Our data breach playbook sets out those first decisions, and our data protection self-check checklist tests how exposed your own records are.

The control that would have stopped it: multi-factor authentication (MFA) on every system that holds donor or beneficiary data, plus staff training to never enter credentials via a link in an email, always navigate to the platform directly instead. MFA alone would have made the stolen password useless to the attacker.

The 10-minute team training (checklist)

A 10-minute quarterly training session, run live by a manager rather than sent as a slide deck, is enough to meaningfully cut phishing risk because most successful attacks succeed through a single moment of unchecked trust, not a lack of general awareness. The goal is to build one habit: pause and verify before acting on anything involving money, passwords or personal data. I put this checklist together myself — it’s the drill I use with my own small team: ten minutes because that’s what a volunteer team will actually sit through, live because people remember what they watched happen.

Run this checklist as a live 10-minute session with your whole team, not just finance:

Minute What to cover
0-2 Show one real (anonymised) phishing email your organisation or sector has received. Point out the urgency language, the slightly-wrong domain, and the request for secrecy or speed.
2-4 Restate the callback rule: any request to change bank details, move money urgently, or bypass normal sign-off must be verified by phone using a number already on file, never a number from the email.
4-6 Remind staff never to enter a password via a link in an email. Always go to the website or platform directly by typing the address or using a saved bookmark.
6-8 Confirm who to tell immediately if something looks wrong, and make clear there is no blame for reporting a mistake or a near-miss quickly.
8-10 Show the two-step reporting process: forward suspicious emails to report@phishing.gov.uk, and tell your line manager or IT lead so the incident can be assessed for wider reporting duties.

Run this every quarter, and after any real incident anywhere in the sector that’s been in the news. Repetition, not length, is what changes staff behaviour. For a fuller organisation-wide framework covering passwords, devices and data, see our cyber security guide for charities.

From experience: The phishing defence that actually holds in a small charity isn’t software, it’s a sentence everyone can recite. At my own charity: no payment and no bank-detail change happens on the strength of an email alone — every such request gets a call to a number we already hold, whoever it appears to come from, including me. Write that sentence into your financial controls and repeat it each quarter; it removes the one thing every phishing email needs — an unchecked moment of trust.

Reporting: Action Fraud, NCSC, serious incident rules

UK charities should report suspicious emails to the NCSC’s Suspicious Email Reporting Service at report@phishing.gov.uk, report actual fraud or financial loss to Action Fraud (or Police Scotland on 101 if based in Scotland), and separately assess whether the incident meets the Charity Commission’s threshold for a serious incident report, which is a distinct legal duty for trustees.

These three reporting routes serve different purposes and are not interchangeable:

  • NCSC (report@phishing.gov.uk): for reporting the suspicious email itself, even if no money or data was lost, so the NCSC can attempt to take down the malicious site or address.
  • Action Fraud: for reporting a crime, meaning money was actually transferred, data was actually accessed, or an attempt was made to defraud the charity, regardless of whether it succeeded — and our fraud playbook covers what to run in parallel while the report is live.
  • Charity Commission serious incident report: a regulatory duty for trustees, separate from reporting the crime itself. Fraud, theft, cyber-crime and significant data breaches are all listed among the categories the Commission expects to see reported, as set out in its serious incident reporting guidance. Even where police are already involved, trustees should not wait for an arrest or conviction before reporting to the Commission.

As a trustee, I’d add one thing: agree in advance who files the report and who calls Action Fraud — the worst time to design that is the afternoon you need it.

Underpinning all of this is the Charity Commission’s CC8 guidance on internal financial controls, which sets out the segregation of duties, authorisation procedures and payment verification steps trustees are expected to have in place to protect charity funds from fraud. If your charity does not currently have a written policy on verifying payment changes and reporting suspected fraud, CC8 is the right starting point. For the fuller picture on building resilient financial controls across your organisation, see our guide to fraud controls for charities and our dedicated post on serious incident reporting.

What to do next

Cutting your charity’s phishing risk does not require a big budget or a new system, it requires four concrete actions taken this month. Start with the callback rule, and build from there.

  1. Write down a callback rule. One sentence, agreed by trustees: any request to move money or change bank details must be verified by phone using a number already on file.
  2. Turn on MFA everywhere it holds donor or beneficiary data, starting with your CRM, email and banking platform.
  3. Run the 10-minute checklist above with your whole team this quarter, not just finance.
  4. Review your CC8 controls against the Charity Commission’s internal financial controls guidance and note any gaps for your next trustee meeting.

Want compliance and fraud-control checks built into your charity’s everyday systems? Join the CharityIQ compliance module waitlist →

Frequently asked questions

CEO fraud is a phishing attack where a criminal impersonates a trustee, chair or senior leader, usually by email, to pressure a member of staff into making an urgent, secret bank transfer. It relies on authority and urgency overriding normal checks, and is defeated by a mandatory phone callback to a verified number before any payment is made.

Do not click any links, open attachments, or reply. Forward the email to report@phishing.gov.uk, then tell a manager or IT lead immediately so the charity can assess whether further action, such as an Action Fraud report, is needed. Acting fast limits the damage.

Not every phishing email needs reporting to the Commission, but if it results in fraud, theft, cyber-crime, or a significant data breach, trustees have a duty to submit a serious incident report. This is separate from reporting the crime to Action Fraud or the police.

Invoice redirection fraud is when a criminal, often via a compromised supplier email account, sends a charity fake updated bank details for a genuine invoice, redirecting a real payment into their own account. It is stopped by always verifying bank detail changes by phone using a number already on file, never one supplied in the email.

A small charity does not need a budget to run effective training. The 10-minute quarterly checklist in this article costs only staff time, and free resources such as the NCSC's phishing guidance and reporting service require no paid tools or software to use.

Yes. In invoice redirection and donor-data phishing, attackers often compromise a real supplier or platform account first, then send convincing messages from within a genuine, already-trusted email thread, which is why verifying by phone rather than by reply is essential.