Skip to main content
Products Back
Solutions Back
Resources Back
Success Services Back
For Partners Back
Security Awareness

For Nonprofits: Defend Your Donor Data Phishing Simulator

Read 3 phishing emails targeting nonprofit staff and learn how to identify the red flags before they cost your organization.

How This Works

Below are three realistic phishing emails modeled after attacks that target nonprofits and mission-driven organizations. Read through each email and click the numbered indicators to explore each red flag. Every indicator reveals an explanation of what makes that element suspicious and how to recognize it in your own inbox.
Email 1 of 3
Fake Executive Impersonation (Business Email Compromise)
Urgent — Need Employee SSNs Before End of Day
J
Jennifer Ramos, Executive Director <jennifer.ramos.nonprofit@gmail.com>
Spoofed sender

The email comes from a personal Gmail account, not the organization’s domain. Executive leadership’s real email will always come from the organization’s official domain — always verify the actual address, not just the display name.

to HR & Payroll Manager · Mon, Jan 13, 2025 at 8:02 AM

Hi Karen,

I’m heading into a board finance committee meeting and they’ve asked me to pull together our current employee census before we finalize the audit. Could you send over full names, SSNs, and salaries


Request for sensitive data via email

Full SSNs and salary data should never be requested or sent over unencrypted email — legitimate audit requests go through a documented, secure process.

for all active staff as a spreadsheet? Needs to be before 3pm today.


Urgency + deadline pressure

A hard same-day deadline is designed to short-circuit your normal verification process and get you to act before you think it through.

Please don’t loop in anyone else on this yet


Instruction to bypass normal process

”Don’t loop in anyone else” is a classic isolation tactic used in business email compromise (BEC) scams to prevent a second person from catching the fraud.

— I want to review it with the board chair first.

Thanks so much,

Jennifer

Sent from my iPhone
Email 2 of 3
Fake Grant / Funder Portal
Action Required: Confirm Banking Details to Receive Grant Disbursement
G
Grants Portal Notification <no-reply@grants-portal-secure-verify.com>
Look-alike domain

“grants-portal-secure-verify.com” is not a real foundation, federal, or state grants-management domain — legitimate funders and portals (like Grants.gov) use their own established, verifiable domains.

to Grants & Finance Administrator · Fri, Jan 10, 2025 at 6:47 AM

Dear Grant Recipient,


Generic greeting, no specific grant reference

“Dear Grant Recipient” and a vague dollar figure, rather than your specific program officer’s name and grant number, signal a mass-sent phishing attempt rather than a real funder communication.

Our records show your organization’s Q3 disbursement of $42,000 is on hold pending verification of your banking information.

To avoid delay or forfeiture of these funds


Threat of losing funding

Threatening forfeiture or reallocation of funds is a pressure tactic designed to make recipients act fast instead of verifying the request through a known contact at the funder.

, please confirm your organization’s routing and account number within 48 hours using the secure link below.

Verify Banking Information →


Request for banking details via email link

Legitimate funders verify or update payment information through a secure, previously established portal login — never through a link in an unsolicited email.

https://grants-portal-secure-verify.com/confirm/np-4471

Failure to respond within 48 hours may result in reallocation of these funds to another grantee.

Grants Portal Support Team
Email 3 of 3
Fake State Charity Registration Notice
Notice: Charitable Solicitation Registration Renewal — Response Required
S
State Charities Bureau — Compliance Division” <compliance@charities-bureau-registration.org>
Spoofed regulator domain

State charity regulators and Attorneys General offices use official .gov domains — a “.org” domain claiming to be a government compliance division is a strong impersonation signal.

to Executive Director · Wed, Jan 8, 2025 at 2:15 PM

Dear Responsible Party,

As part of our annual charitable solicitation registration review, we require verification of your organization’s financial records for the fiscal year ending December 31, 2025.

Please upload the following documents to our secure compliance portal:
• Form 990 or 990-EZ (most recent filing)
• Bank statements (January–December 2025)
• Donor records exceeding $5,000
• Board of Directors meeting minutes


Bulk sensitive document request

Bank statements, unredacted large-donor records, and board minutes are far more than any registration renewal legitimately requires — and would never be requested via an emailed upload link.

Access Secure Upload Portal →


Unofficial upload portal link

Hovering over the link reveals a domain that does not match any real state charity regulator — legitimate renewals happen through the state’s official online filing system, not a link emailed to you.

https://charities-bureau-registration.org/upload/np-CH-2026-00931

Failure to respond within 10 business days may result in suspension of your organization’s charitable solicitation registration.


Threat of registration suspension

Threatening the loss of your organization’s legal ability to fundraise creates urgency that pressures staff to upload sensitive files without verifying the request through the actual state agency.

State Charities Bureau, Compliance Division
Icons32x32 (2) data risk icon (3)

Keep Your Team Safe

Download a one-page reference checklist your staff can use to identify phishing emails — designed for church and nonprofit organizations.
Phishing Email Red Flag Checklist · PDF · Free

Protect Your Organization

If you'd like to learn how APS supports workforce security for nonprofit organizations, schedule a demo with our team.

Schedule a Demo

No commitment required