For Nonprofits: Defend Your Donor Data Phishing Simulator
Read 3 phishing emails targeting nonprofit staff and learn how to identify the red flags before they cost your organization.
Hi Karen,
I’m heading into a board finance committee meeting and they’ve asked me to pull together our current employee census before we finalize the audit. Could you send over full names, SSNs, and salaries
Request for sensitive data via email
Full SSNs and salary data should never be requested or sent over unencrypted email — legitimate audit requests go through a documented, secure process.
for all active staff as a spreadsheet? Needs to be before 3pm today.
Urgency + deadline pressure
A hard same-day deadline is designed to short-circuit your normal verification process and get you to act before you think it through.
Please don’t loop in anyone else on this yet
Instruction to bypass normal process
”Don’t loop in anyone else” is a classic isolation tactic used in business email compromise (BEC) scams to prevent a second person from catching the fraud.
— I want to review it with the board chair first.
Thanks so much,
Jennifer
Dear Grant Recipient,
Generic greeting, no specific grant reference
“Dear Grant Recipient” and a vague dollar figure, rather than your specific program officer’s name and grant number, signal a mass-sent phishing attempt rather than a real funder communication.
Our records show your organization’s Q3 disbursement of $42,000 is on hold pending verification of your banking information.
To avoid delay or forfeiture of these funds
Threat of losing funding
Threatening forfeiture or reallocation of funds is a pressure tactic designed to make recipients act fast instead of verifying the request through a known contact at the funder.
, please confirm your organization’s routing and account number within 48 hours using the secure link below.
Verify Banking Information →
Request for banking details via email link
Legitimate funders verify or update payment information through a secure, previously established portal login — never through a link in an unsolicited email.
https://grants-portal-secure-verify.com/confirm/np-4471
Failure to respond within 48 hours may result in reallocation of these funds to another grantee.
Dear Responsible Party,
As part of our annual charitable solicitation registration review, we require verification of your organization’s financial records for the fiscal year ending December 31, 2025.
Please upload the following documents to our secure compliance portal:
• Form 990 or 990-EZ (most recent filing)
• Bank statements (January–December 2025)
• Donor records exceeding $5,000
• Board of Directors meeting minutes
Bulk sensitive document request
Bank statements, unredacted large-donor records, and board minutes are far more than any registration renewal legitimately requires — and would never be requested via an emailed upload link.
Access Secure Upload Portal →
Unofficial upload portal link
Hovering over the link reveals a domain that does not match any real state charity regulator — legitimate renewals happen through the state’s official online filing system, not a link emailed to you.
https://charities-bureau-registration.org/upload/np-CH-2026-00931
Failure to respond within 10 business days may result in suspension of your organization’s charitable solicitation registration.
Threat of registration suspension
Threatening the loss of your organization’s legal ability to fundraise creates urgency that pressures staff to upload sensitive files without verifying the request through the actual state agency.
Keep Your Team Safe
Protect Your Organization
If you'd like to learn how APS supports workforce security for nonprofit organizations, schedule a demo with our team.
Schedule a DemoNo commitment required