Employee Owned Since 2022  |  Serving Chicagoland since 1996Support: 630-523-0220Sales: 630-526-8030Remote support

Cybersecurity whitepaper | Non Profit Organizations

Stopping Email Fraud and Gift Card Scams at Nonprofits

Simple verification habits that stop impersonation and payment fraud before money leaves

  • Published September 25, 2026
  • 4 min read

Some of the most costly attacks on nonprofits involve no malware at all. Instead, a criminal sends a convincing email and asks someone to move money. Gift card scams, fake vendor invoices, and payroll redirects all rely on trust, urgency, and busy staff.

How gift card scams target nonprofit staff

The classic version starts with a short email that appears to come from the executive director. It asks a program coordinator or volunteer if they have a minute for a quick favor. Once they reply, the “director” asks them to buy gift cards for a client event or staff appreciation.

Next, the scammer asks for photos of the card numbers. After that, the scammer drains the cards within minutes.

These requests work because they sound plausible. Nonprofits really do buy gift cards for clients and volunteers. Also, new staff want to help leaders and may hesitate to question them.

Other common payment fraud schemes

Gift cards are only one tactic. Criminals also go after larger sums through several patterns.

  • Vendor invoice changes: A message from a “vendor” says their bank details changed and asks you to update payment information.
  • Payroll redirects: An email from an “employee” asks HR to switch their direct deposit to a new account.
  • Grant payment fraud: At a foundation, a fake grantee asks you to send an award to a different account.
  • Board impersonation: A message appears to come from the board treasurer and requests an urgent wire.

In many cases, the attacker has actually broken into a real mailbox. So the message may come from a genuine address, with real past conversations attached.

Set verification rules that do not depend on email

The most effective defense is a simple rule. Never approve a payment change or unusual request using only the channel it arrived through. Instead, call the person back at a number you already have on file.

Put these rules in writing, and share them with staff, volunteers, and board members.

  1. Leaders never ask anyone to buy gift cards by email or text.
  2. Any change to vendor or grantee bank details requires a phone call to a known contact.
  3. Direct deposit changes require the employee to confirm in person or through the HR system.
  4. Wires and large payments need approval from two people.
  5. Urgent or secret requests trigger extra checks, not faster action.
  6. Anyone can pause a payment to verify it, without penalty.

Add technical protections to your email

Policies catch what technology misses, but technology still reduces the volume of scams. First, publish SPF, DKIM, and DMARC records for your domain. These records make it harder for criminals to send mail that pretends to come from your exact address.

Next, tag messages from outside your organization with a visible banner. That label helps staff notice when the “executive director” actually writes from a free email account.

In addition, watch for lookalike domains that swap one letter or add a word. Advanced email filtering can flag these, and MFA makes it much harder for attackers to take over real mailboxes.

Teach staff the warning signs

Scam messages share common traits. They create urgency, ask for secrecy, and push the reader to act before checking. Many also arrive when the supposed sender is traveling or in meetings.

So walk staff through a few real examples during team meetings. Point out the mismatched reply address, the unusual tone, and the request that skips normal approval steps.

Also, include volunteers and board members in these conversations. Scammers often find their names on your website and annual report, then target them directly.

Make reporting fast and blame free

People who fall for scams often wait before they speak up, because they feel embarrassed. Unfortunately, every hour matters when you try to recover funds.

So tell staff exactly whom to call, and thank them when they report. If money has already left, contact your bank immediately and ask about a recall. Then notify your IT provider, your cyber insurance carrier, and law enforcement.

How WEBIT helps

WEBIT helps nonprofits set up SPF, DKIM, DMARC, external email tagging, and MFA across Microsoft 365. Our Security Advanced add-on adds email security, Microsoft 365 threat detection and response, and security awareness training that covers gift card scams and invoice fraud.

Our unlimited help desk also gives staff a quick place to ask, “Is this real?” Visit our nonprofit IT page, or reach out to talk through your payment controls.

Key takeaways

  • Email fraud relies on trust and urgency, not malware.
  • Verify every payment change through a separate, known channel.
  • Leaders should state plainly that they never request gift cards by email or text.
  • SPF, DKIM, DMARC, and external tags reduce spoofed messages.
  • Fast, blame-free reporting improves your chances of recovering funds.

Talk to an owner

Want help putting this guide into practice? A 30-minute discovery call gets you honest advice for your environment.

Schedule a discovery call

Non Profit Organizations IT services

See how WEBIT supports non profit organizations organizations across Chicagoland.

Explore Non Profit Organizations IT →

More Non Profit Organizations whitepapers

Browse the full library of guides for your industry.

All Non Profit Organizations whitepapers →

Two new clients per month. Maximum.

Ready to talk to an owner?

Every conversation starts with an honest look at where you are today. No pressure, no pitch deck, and no obligation.