How to train staff to recognise fake charity donation scams

Train staff and volunteers to recognise fake charity donation scams with ACNC checks, safe payment routes, phishing exercises, reporting and response steps.

Fake charity donation scams exploit generosity, urgency and trust. A message may use the name of a real charity, a disaster appeal, a familiar fundraising event or a convincing social-media profile. The requested donation can look small, but the real target may be a card number, a bank login, a one-time code or enough personal information to commit identity fraud.

This guide explains how to train staff and volunteers to recognise fake charity donation scams in 2026. It covers the behaviours to teach, role-based scenarios, safe phishing exercises, reporting, incident response and the measures that show whether the programme is working. Start with a cyber security gap assessment if the organisation does not yet know who handles donations, fundraising links, social accounts or payment approvals.

TL;DR

Why charity scams work

Charity scams do not need to look careless. The scammer can copy a genuine organisation’s name, logo, language, campaign photos and donation story. A message can arrive after a flood, fire, public tragedy or major event when people are already primed to help. A short deadline or a claim that donations are being matched adds pressure without proving that the appeal is real.

Scammers may contact people by email, SMS, phone, social media, crowdfunding pages, QR codes, collection tins, street approaches or fake websites. They may ask for a bank transfer, card payment, cryptocurrency, gift card, voucher or personal details. A staff member can therefore encounter the scam while working in fundraising, customer service, finance, marketing, events or a shared social-media account.

Scamwatch’s donation-scam guidance says scammers impersonate genuine charities and may claim to collect money after natural disasters or major events. An ACNC warning reported that Scamwatch had calculated $1.4 million in losses to fake charity scams officially reported over the previous five years, while noting the real figure was likely higher. The lesson for an organisation is direct: generosity needs a verification process just as payment changes do.

The behaviour to teach

Use a simple rule that people can remember under emotional pressure: stop, check, donate safely, report.

Stop

Do not donate, reply, click, scan, download, share or forward a request just because it uses a familiar name or an urgent story. Pause when a message asks for an immediate payment, a new bank account, a one-time code, a password, identity documents or more personal information than a donation requires.

Do not let a colleague’s recommendation replace verification. A genuine person can forward a compromised account or an unverified appeal. Treat the appeal as untrusted until the charity and the payment route are confirmed independently.

Check

Use a trusted route that was not supplied by the message. Type the charity’s known website address yourself, use a saved contact already held in the organisation’s records or find the organisation in the ACNC Charity Register and charity information pages. Compare the legal name, website, contact details, appeal purpose and payment instructions.

A register check is useful, but it is not the only check. A scammer may impersonate a registered charity or create a fake appeal in its name. If the appeal is for a particular disaster or event, confirm that the charity itself is running it and that the payment route is on the charity’s known website.

Donate safely

Use the organisation’s official donation page or another payment route confirmed through an independent contact. Do not use bank details, QR codes, shortened links or phone numbers supplied only by an unsolicited message. For workplace donations, follow the approved procurement or finance process and record who verified the appeal.

Keep the amount, purpose, recipient, date and approval evidence. The evidence protects the organisation’s finances and gives investigators useful information if the appeal is later found to be fraudulent.

Report

Give staff and volunteers one easy internal reporting route. The report should reach an owner who can assess the message, protect the organisation’s accounts and warn other people if the same appeal is circulating. Make it clear that reporting a suspicious appeal is the correct behaviour even when it turns out to be legitimate.

Scamwatch provides a route to report scams in Australia. Internal reporting still matters because the organisation may need to remove a post, alert donors, stop a payment, protect a social account or investigate whether a staff member entered information.

Who needs the training

Employees

All employees need the baseline: do not treat an unexpected appeal as authenticated, verify through a known route and report it. The baseline should include email, SMS, social-media and QR-code examples because staff may receive appeals on personal devices while working.

Volunteers and casual workers

Volunteers often operate event stalls, community pages, collection drives and peer-to-peer fundraising accounts. Give them a short, mobile-friendly lesson and a reporting route that does not depend on a corporate email address. Explain who can approve a fundraising post, who can handle cash and what to do if a donor asks whether an appeal is genuine.

Finance and accounts payable

Finance teams need payment-diversion practice. A request to change the bank details for a charity partner, pay an event supplier or reimburse a fundraiser should be verified through a known contact and the normal approval process. Staff should know that urgency, a familiar signature and a plausible invoice are not proof of identity.

Fundraising and marketing

Fundraising and marketing teams manage the channels scammers want to abuse. Their training should cover social-account security, approval of campaign URLs, QR-code creation, link changes, impersonation reports and the process for taking down a fraudulent appeal.

Customer service and community teams

Customer-facing teams may receive questions from donors who saw a suspicious post or message. Give them a script: acknowledge the concern, do not repeat the suspicious link, direct the person to the organisation’s known website and escalate the report to the campaign owner.

Executives and event approvers

Executives and event approvers need practice resisting authority and deadline pressure. A senior person may receive a request to approve an emergency donation, publish an appeal immediately or bypass the normal payment check. The safe decision is to pause, verify through an independent route and record the exception if one is approved.

Scenarios to include in the programme

A disaster appeal from a known charity name

A message arrives after a natural disaster and includes a photo, a short donation link and a request to share it with all staff. The correct response is to avoid the link, open the charity’s known website independently, confirm whether the appeal exists and report the original message.

A cloned fundraising page

A peer-to-peer fundraiser appears to use the name and logo of a genuine organisation but has a slightly different web address. Staff should compare the page with the known charity site, avoid entering payment details and tell the fundraising or security owner.

A QR code at an event

A collection poster or event message directs donors to a QR code. Teach people that scanning is opening a link, not verifying it. The code should be checked against the approved event materials and official donation page before it is displayed or used.

A social-media direct message

A direct message claims to be from the charity’s community team and asks for a donation, gift card or urgent transfer. Staff should not reply or move the conversation to another channel. They should capture the evidence, report the account through the internal route and verify the campaign through the known website.

A supplier or partner payment change

A real charity partner appears to request a new bank account for an event payment. The accounts team should stop the change, call the known contact using a number already held in the supplier record and use a second-person approval for the change.

A donor asks for confirmation

A donor forwards an appeal and asks whether the organisation is collecting funds. The employee should not guess. They should use the approved internal source, send the donor to the known website and log the suspicious message for review.

What the training should cover

Authenticity is not the same as familiarity

Explain that a charity name, logo, staff photo, copied post, reply thread or caller ID can be imitated. Staff should authenticate the appeal through a route they selected independently. The question is not whether the message looks professional; it is whether the organisation has confirmed the specific appeal and the payment destination.

Payment routes are part of the decision

Teach people to stop when an appeal requests an unusual payment method or a personal transfer. The organisation should publish approved donation and event-payment routes and define who can approve a change. A staff member should never need to invent a verification method while a donor or supplier is waiting.

Personal data can be the real target

A fake appeal may ask for a full name, address, date of birth, identity document, tax details, bank login or one-time code. The lesson should state which information the organisation will never request through an unsolicited message and where staff should report a request for it.

Account security protects the appeal

Fundraising staff should use strong unique passwords, multi-factor authentication where available and approved admin roles for social, website and payment accounts. Awareness training does not replace access controls, but it helps the people who publish appeals recognise a fake login page or an unexpected permission request.

Reporting is a positive behaviour

If staff are punished for raising a false alarm, they will wait longer next time. Explain what happens after a report, how quickly it will be reviewed and how the reporter will receive a verdict. A report that turns out to be legitimate still shows that the person followed the control.

Building safe phishing exercises

A charity-scam simulation should practise verification and reporting without creating a real payment or exploiting a personal tragedy. Do not use a live disaster, a real donor list, a real charity’s current appeal or language that could distress staff. Do not collect real card details, passwords, identity information or one-time codes.

Use a fictional campaign name, a safe exercise domain and a landing page that explains the lesson immediately after a click. If the organisation wants to test social-media or QR behaviour, obtain approval from the channel owner and make sure the exercise cannot be mistaken for a public appeal.

Cyber Aware’s phishing workflow can support controlled practice when the scenario, audience and follow-up are approved. The exercise should have one primary behaviour: report the appeal, verify through the known website or stop the payment. A scenario that tests every possible warning sign will produce a noisy result and a weak lesson.

A role-based learning path

Lesson 1: recognise the emotional hook

Show how a genuine-looking name, urgent story, public event and easy payment route combine to create pressure. Ask staff to choose the next safe action and explain why independent verification matters.

Lesson 2: verify the charity and appeal

Demonstrate the known website route, the ACNC register check and the internal source for approved campaigns. Make the safe route visible in the organisation’s policy and event materials.

Lesson 3: verify payment and data requests

Use finance and fundraising examples to show when a second approver, known callback and existing supplier record are required. Explain that a small payment is still a payment and a small data request can still enable identity theft.

Lesson 4: report and preserve evidence

Show how to report the original message, capture the URL or account name and tell the internal owner. Explain when to delete the message and when the incident process requires evidence to be retained.

The security awareness training programme should be assigned by role wherever possible. A volunteer who publishes a social post should not receive exactly the same follow-up as an accounts-payable approver.

A 30-day rollout

Days 1–7: map the donation process

List official donation pages, fundraising accounts, event owners, finance approvers, social-media administrators, reporting routes and emergency contacts. Record which roles can publish links, accept money, change bank details or handle donor information.

Days 8–14: teach the baseline

Assign a short lesson to all employees and volunteers. Publish the internal rule: stop unexpected appeals, check through a known route, use the approved payment path and report anything suspicious. Test the reporting mailbox or button with a benign example.

Days 15–21: practise by role

Run one safe exercise for a fundraising or finance cohort and one for a general employee cohort. Keep the scenarios different but the core behaviour consistent. Review whether staff knew where to verify the appeal and whether the report reached the right owner.

Days 22–30: improve the control

Use human risk reporting to group results by role, manager, campaign and channel. Fix broken links, unclear approval steps, missing owners and slow reporting before expanding the exercise. Repeat the highest-risk scenario later with a comparable cohort.

What to measure

Do not use completion as the headline outcome. A 100% completion rate can coexist with staff who still publish an unverified fundraising link. Measure what people do when a plausible appeal asks them to act quickly.

What to do after a donation scam

If money was sent, contact the bank or card provider immediately and ask what can be stopped or recalled. If card details, bank credentials, passwords, identity documents or one-time codes were shared, use the organisation’s incident process, secure the affected account through a known route and escalate to the relevant provider.

Preserve the message, URL, account name, phone number, payment receipt, transaction reference and screenshots. Do not continue the conversation with the scammer or use contact details supplied by the suspicious message. Warn people who may have received the same appeal, but do not forward the malicious link.

Report the incident through the organisation’s internal route and to Scamwatch. If a social or fundraising account was impersonated, report it to the platform and tell the charity or campaign owner through a known contact.

Approaches to avoid

A generic annual module

A generic phishing lesson may not tell a fundraiser how to verify a disaster appeal or an accounts team how to stop a bank-detail change. Use the baseline, then add role-based examples.

A public humiliation exercise

Do not publish individual names or use a real tragedy as a trap. Constructive, private feedback builds reporting behaviour; shame suppresses it.

A register-only check

The ACNC register is a useful verification source, but a registered charity can still be impersonated. Confirm the specific appeal and payment destination through the charity’s known website or contact route.

Unowned reporting

A report button, mailbox or social-media flag without an owner creates delay. Assign triage, campaign removal, finance escalation and donor communications before the first exercise.

Treating small donations as low risk

Small payments can scale across many donors and can be used to test stolen card details. The safe control applies to the route and the request, not only to the amount.

FAQ

How can staff verify a charity donation request?

Use a trusted route selected independently: the charity’s known website, the ACNC register and information already held by the organisation. Confirm that the specific appeal exists and use the payment route published by the charity, not the one supplied only by an unsolicited message.

Should staff donate through a link sent by email or SMS?

They should not use an unexpected link as the verification route. Open the known charity website or official app independently, find the appeal there and donate only through the confirmed payment page.

What should volunteers learn?

Volunteers should learn how to identify emotional pressure, verify a campaign, use approved event materials, protect social accounts, avoid requesting unnecessary data and report suspicious appeals without delay.

Can a phishing simulation use a real charity name?

It should not. Use a fictional appeal and a safe exercise page so the programme does not create public confusion, damage a real charity’s reputation or exploit a current disaster.

How should finance teams handle a changed charity bank account?

Pause the change, verify it with a known contact using details already held in the supplier record and follow the normal approval process. Do not rely on the email thread or the number in the request.

What is the most important metric?

For a first programme, use safe verification and report rate together. The goal is for people to avoid the suspicious route, raise the concern quickly and give the owner enough evidence to act.

Final checklist

Before the next appeal or fundraising campaign, confirm that the organisation has a known donation page, approved payment routes, named social-account owners, a register-check process, a reporting route, a finance callback rule, a donor-warning template and a plan for compromised accounts. Then practise the behaviour with a safe scenario.

The strongest charity-scam training does not ask staff to become fraud investigators. It gives them permission to pause, a trusted way to check, an approved way to donate and a reporting route that responds.

Sources

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.