top of page
Search

Pause Before you Click: Email Scam Safety for Nonprofits

Aug 19
4 min read

Nonprofits are built on trust. We trust our volunteers, our board members, our donors and the community partners who help us carry out our mission.

Unfortunately, scammers know that.


They also know that nonprofit leaders are busy, volunteers may use personal email accounts and financial decisions are often made quickly between meetings. That makes nonprofit organizations attractive targets for phishing emails and other online scams.


A fraudulent email may look as though it came from your president, treasurer, bank, payment processor, donor or even another club member. It may include a familiar name, logo or photograph. Some scammers also use artificial intelligence to create messages that sound surprisingly convincing.


The goal is simple: make you react before you have time to think.


The Urgent Email From the “President”


One common scam begins with a message that appears to come from the organization’s president:


“Are you available? I need you to handle something confidential for me.”


Once you reply, the sender may ask you to purchase gift cards, transfer money, change payment information or send sensitive documents.


Another message may claim that an invoice is overdue, a donation failed, an account will be closed or someone needs emergency assistance.


The story changes, but the pressure remains the same: Act immediately. Don’t ask questions.

That is your signal to stop.


Watch for These Warning Signs


A suspicious email may:

  • Create an unusual sense of urgency.

  • Ask you to keep the request confidential.

  • Request gift cards, wire transfers or cryptocurrency.

  • Ask you to change a vendor’s banking information.

  • Include an unexpected invoice or attachment.

  • Ask for passwords, verification codes or financial information.

  • Contain a link that does not match the organization named in the message.

  • Come from an address that is slightly different from the real one.

  • Use an unusual greeting, tone or writing style.

  • Claim that something terrible will happen if you do not respond immediately.


Remember that a familiar name in the “From” line does not prove the message is genuine. Email addresses and display names can be copied or disguised.


Use the S.T.O.P. Rule


When an email asks you to send money, share information or open an unexpected attachment, remember one word: STOP.


S — Slow Down


Scammers want a quick emotional reaction. Take a breath and give yourself time to examine the request.


T — Test the Information


Look carefully at the sender’s complete email address. Hover over links without clicking them to see where they lead. Check for spelling changes, extra letters or unfamiliar domains.


O — Obtain Confirmation


Contact the person or company using a telephone number, email address or website you already know is legitimate. Do not use the contact information supplied in the suspicious message.


If your president supposedly needs $500 in gift cards, call her. She will not mind. If the message is legitimate, you have protected the organization by confirming it. If it is fraudulent, you may have prevented a serious loss.


P — Protect and Report


Do not reply, click, download or forward the message to other volunteers as an ordinary email. Report it through your email provider’s phishing-reporting feature and notify the appropriate leader in your organization.


The Federal Trade Commission also accepts scam reports at ReportFraud.ftc.gov.


Every Nonprofit Needs a Two-Person Rule


Technology helps, but good procedures provide another important layer of protection.

No one person—not even the president or treasurer—should be able to request and complete an unusual financial transaction without independent confirmation.


Create a written policy requiring:

  • Two people to approve significant payments or transfers.

  • Verbal confirmation before changing banking or payment information.

  • A second communication method for unusual requests.

  • Board approval for expenditures over an established amount.

  • Immediate reporting of suspicious emails.

  • Regular review of who can access financial, donor and administrative accounts.


These safeguards are not about mistrust. They protect the volunteer, the organization and the people your mission serves.


Strengthen Your Email Accounts


Every board member and volunteer with access to organizational information should:

  • Use a strong, unique password for each account.

  • Turn on multifactor authentication.

  • Never share a password or one-time verification code.

  • Keep computers, phones, browsers and security software updated.

  • Remove account access when someone leaves a position.

  • Avoid conducting sensitive nonprofit business over public Wi-Fi.

  • Use official organizational email accounts whenever possible.

  • Review account recovery phone numbers and email addresses regularly.


Multifactor authentication is especially important. If a password is stolen, that additional verification step may prevent the scammer from entering the account.


What If You Already Clicked?


First, do not be embarrassed. Intelligent, experienced people are caught by scams every day. Shame only causes delays, and delays can make the damage worse.


Act immediately:

  1. Disconnect the device from the internet if you downloaded a suspicious file.

  2. Contact your organization’s technology support person.

  3. Change the affected password from a trusted device.

  4. Turn on multifactor authentication if it is not already active.

  5. Contact the bank or payment provider if money or financial information was involved.

  6. Notify the organization’s president and treasurer.

  7. Run an updated security scan on the device.

  8. Preserve the suspicious message and document what happened.

  9. Report the incident to the appropriate authorities.


If personal identifying information was exposed, visit IdentityTheft.gov for a recovery plan. The FTC also provides guidance on recognizing and avoiding phishing scams.


Make It Safe to Ask


One of the best protections a nonprofit can create is a culture in which people feel comfortable saying:


“I’m not sure about this email. Would you please look at it with me?”


Never make someone feel foolish for asking. Celebrate the pause. Thank the person who double-checks a payment request. Discuss suspicious messages at board meetings so everyone learns what to watch for.


Online safety does not require every volunteer to become a computer expert. It requires a few good habits, clear financial procedures and permission to slow down.


The next time an urgent email arrives, remember:

Pause. Check. Call. Confirm.


Your mission is too important to risk on one hurried click.



 
 
 

Comments


No Collections Here

Sort your projects into collections. Click on "Manage Collections" to get started

bottom of page