Fake charity donation scams spike every giving season, and finance and reception staff are the two teams most likely to hit "pay" before anyone checks the request. This guide gives you a step-by-step training sequence to build fake charity scam awareness training into your existing security program in 2026, not a slide deck nobody opens.
TL;DR
- Fake charity scam awareness training works best split by role: finance verifies, reception screens calls, everyone reports.
- Run one live simulation using a fabricated donation request before End of Financial Year or Christmas appeals hit inboxes.
- Cyber Aware customers get the best recall when training ties to a two-minute reporting habit, not a once-a-year module.
- Retest recall at 30 days — scam recognition drops fast without a second touch.
Why this matters
Charity impersonation scams ride real donation cycles — bushfire appeals, flood relief, EOFY giving, Christmas hampers — because urgency and goodwill lower a staff member's guard faster than a fake invoice ever could. The scam email or call looks like it's asking for $50 or $500, not $50,000, so it slips past the fraud thresholds most finance teams actually watch. Phishing simulation programs that treat charity scams as a subset of general phishing miss the specific psychological trigger: staff want to help, and that instinct is exactly what the scam exploits.
Cyber Aware sees this pattern across organisations that already run broader security awareness training — general phishing recognition doesn't automatically transfer to donation requests, because the emotional cue is different. Training has to name the scam type explicitly, or staff file it under "not my job to question a good cause."
What you'll need
- A list of the charity names your organisation has donated to or sponsored in the past 24 months
- Sample fake donation emails (search recent Scamwatch alerts or your own quarantined spam folder)
- 15 minutes of finance team time and 15 minutes of reception/frontline time — run these separately
- A verification rule already agreed with finance leadership before training starts
- Your existing security awareness training for employees platform or LMS to log completion
The steps
1. Map the charity scam patterns staff will actually see
Before you write a single slide, list the three or four formats fake charity requests take at your organisation: spoofed emails asking for a "one-off corporate donation," phone calls requesting card details over the line, fake QR codes on flyers left in break rooms, and LinkedIn messages from "charity partners." Training that covers a generic "charity scam" concept without naming the actual channel gets forgotten within a week.
Common mistake: building training around email only, then getting caught by a phone-based ask two months later.
2. Set a verification rule before you write training
Decide the rule first: no donation request over $200 gets approved without an independent call-back to a number sourced outside the original message. Write this down as policy, not as a training suggestion — staff need a rule to point to, not a vague reminder to "be careful." Charity registration lookups (ACNC in Australia) take under two minutes and should be part of the rule.
Common mistake: leaving verification as a soft suggestion instead of a mandatory step tied to a dollar threshold.
3. Run a live simulation using a fabricated donation request
Send a realistic but fake charity donation email to finance and reception in the same week you train them — timing it to a real giving season (EOFY, Christmas, a recent natural disaster) makes it far more convincing and far more useful as a data point. Track who clicks, who calls the number in the email, and who forwards it to IT or reports it. This single exercise tells you more about real-world readiness than any quiz.
Expected outcome: a click/report ratio you can compare against your organisation's baseline from general phishing simulations.
4. Train finance and reception teams separately
Finance sees the invoice-style ask; reception and frontline staff see the phone call or the person at the door with a collection tin and a QR code. Combine these groups into one generic session and the training feels irrelevant to half the room. Run two 15-minute sessions instead, each built around the exact scenario that team will hit. This mirrors how payroll teams get trained to stop CEO fraud emails — role-specific beats generic every time.
Common mistake: one all-staff session that spends equal time on scenarios only 10% of the room will ever face.
5. Build a two-minute reporting habit
Give staff a single reporting path — a Slack channel, a forwarding address, a button in their email client — and tell them the goal is speed, not certainty. A staff member who reports a suspicious donation request within two minutes, even if it turns out legitimate, should never be made to feel they wasted anyone's time. This is the same principle behind verifying supplier bank detail changes: the habit of pausing and checking matters more than getting every call right.
Expected outcome: report volume goes up in the first month, which is the correct signal — it means staff are pausing before paying.
6. Retest recall at 30 days
Run a second, different fake charity simulation 30 days after the first training session. Recognition drops fast without reinforcement — a single training event rarely holds past a few weeks. If click-through or call-back rates on the second test are worse than the first, the training didn't land and needs a format change, not a repeat of the same slides.
Common mistake: treating one training session and one simulation as "done" for the year.
Troubleshooting
- Staff keep saying "but it looked so real" — show them the actual header/sender mismatch on the sample email during training, not just the visual layout.
- Reception can't verify a phone caller mid-call — give them a scripted line: "I'll need to call you back on a number I look up myself" and make hanging up the expected, praised behaviour.
- Finance approves under the $200 threshold without checking — lower the threshold or add a second reviewer for any new payee, regardless of amount.
- Volunteers or casual staff weren't included in training — charity-adjacent scams often target event staff and volunteers first; extend training to casual and temporary staff and seasonal hires.
- No one reports near-misses, only confirmed scams — reward reporting volume in the first quarter, not accuracy, to build the habit.
Tools and resources
- Charity registration lookup (ACNC in Australia) for verifying any charity name before payment
- A fake donation email template built from a real, recent Scamwatch-style alert
- Cyber Aware's gamified security awareness training format, which performs better for one-off scenario training than a static module
- A logged verification rule (dollar threshold + call-back requirement) stored somewhere staff can find it fast
One detail worth building into this rule set: the way legitimate charities collect money online has changed the scam surface, not shrunk it. Fake donation links now mimic the layout of real fundraising pages closely enough that visual inspection alone fails, which is exactly why nonprofits that care about donor trust standardise on legitimate donation forms with verifiable domains and payment processors staff can actually check against — training your team to recognise the real pattern makes the fake ones easier to spot by contrast.
Build this training into your program
See how Cyber Aware structures role-based scam training for 2026.
What to do next
Once fake charity scam awareness training is running, extend the same verification-first approach to the scams that share its urgency trigger — fake invoice fraud, CEO fraud emails, and supplier bank detail changes all rely on the same "act now, ask later" pressure. Charity scams should sit inside your broader security awareness calendar, retested every giving season rather than run once and forgotten.
FAQ
What is fake charity scam awareness training?
It is role-specific training that teaches finance, reception and frontline staff to verify donation requests before paying or transferring funds. It differs from general phishing training because it targets the emotional urgency of a good cause rather than a technical threat.
How often should charity scam training run?
Run it at least twice a year, timed to major giving seasons such as EOFY and Christmas in 2026. A single annual session loses effectiveness within 30 days without a follow-up simulation.
Is phone-based charity fraud more common than email?
Both channels are active, and reception staff often face phone-based asks first because they answer unsolicited calls more than finance teams do. Training needs to cover both channels separately, not just email.
What dollar threshold should trigger charity donation verification?
Many organisations set the threshold at $200, requiring an independent call-back before approval above that amount. The exact figure should match your existing invoice fraud policy rather than sit as a separate rule.
Should volunteers get the same training as employees?
Yes — volunteers and casual staff are frequently the first point of contact for charity-adjacent scams at events and front desks. Leaving them out of training creates the weakest link in the chain.
How do you measure if charity scam training worked?
Run a fake donation simulation before and after training and compare click-through and call-back rates. A drop in clicks combined with a rise in reports is the signal training is working.
Can general phishing training replace charity scam training?
No — general phishing training rarely covers the emotional trigger specific to charity requests, so recognition doesn't transfer automatically. Charity scams need to be named explicitly in training content.
One last thing
The single highest-leverage change most organisations can make in 2026 isn't more training content — it's moving the verification rule from "suggested" to "mandatory with a dollar threshold." Training teaches recognition; a hard rule stops the payment even when recognition fails.