Cybersecurity threats to charities

Cybersecurity attacks on charities

Rise of the machines and cybersecurity threats to charities.

I usually try and keep my topics light and airy… upbeat with a touch of quirk. Alas, I need to put all that to one side for a short while so we can talk about bot generated email addresses and other cybersecurity threats to charities.

If you’re reading this I’m going to assume you are a nice person, who does what they do because they believe in good things. Unfortunately not everyone is like us and there are some people out there who like to generate chaos and mayhem. Let’s call them Bad Players.

We’ve all heard of the big brash things that are done: major system hacks, denial of service attacks and so on, but there’s a much more insidious programme of work going on that isn’t as noticeable but it is there and it does have consequences. Below are just a few of the ways charities (especially small ones) are finding themselves unwitting players in this most twisted of plays.

Testing stolen credit cards.

Bots will work through the list of cards using the web donation forms of charities, making small donations. It’s likely that the values of the donations have moved away from small £1 as these are noticeable by the charities, the processors and the person who’s missing a card. Much more likely to be £10 or so. Hiding in plain sight.

Signing up to your keep in touch forms.

Maybe the Bots like some light reading in between sending 100 million emails to the White House, deepfaking a celebrity in the nude and playing a head to head hack-a-thon with GCHQ. Or maybe they are testing your form for vulnerabilities, seeding your list so your email domain is blacklisted or making it look like your site is fake.

Scraping sites for info that can be used to generate phishing attacks.

This one is fun. You know that bit where you have “who we are” and under each picture you have individual contact details, well, these can be used to create email addresses that look like they come from your organisation and add an air of respectability to that phishing attack they’re planning. But it’s OK because all those people that handed over their details and their money, thought it was you asking.

These next two are both very technical…

If website pages and plugins aren’t kept up to date, hackers can inject naughty code into them, which redirect users to naughty places.  If it’s a redirect to an adult site, that is the least of your worries (you’ll never hear that said again!). Often it will redirect to scam sites, which are a much less pleasant experience

It’s also now possible to spoof an email domain without an actual hack. The same applies, the recipient thinks it’s you, clicks on a link and bam, before you know it they are somewhere they don’t want to be, and asking why their local hospice is sending them those sorts of pictures.

Cybersecurity threats to charities.

A recent commentary in MoneyWeek (August 2025) reported that 42% of UK SMEs experienced some kind of cyber breach in the previous year. Over the last few years, the trend of targeting smaller businesses, including those with turnover under £1 million, has been steadily increasing. The true scale may be even higher, as many incidents go unreported due to a lack of detection or awareness.

If you’ve read this far and think “that’s interesting but…” take a moment. According to the Charity Finance Group, 97% of UK charities have an income of £1 million or under.

Now that is a very big target market for our Bad Players.