By David Chernitzky, CEO, Armour Cybersecurity · Serving Toronto and organizations across North America · Last updated August 26, 2026
Quick Answer
Nonprofit BEC attacks exploit the authority structure of charitable organizations. Executive directors and board chairs have significant financial decision-making power, and the informal culture of many nonprofits means requests from senior leadership are acted on without the verification procedures that commercial organizations build into their financial flows that attackers target. Attackers have mapped this gap and use it to redirect donations, intercept grant payments, and divert vendor wires with consistent success.
Key Takeaways
- BEC attacks against nonprofits impersonate executive directors, board chairs, and development directors to redirect financial flows with the authority of senior leadership.
- Donation platforms and grant payment systems are attractive targets because the financial flows are significant and the verification culture in nonprofits is often informal.
- Fake charity and donation scams that impersonate legitimate organizations divert donor funds before they reach the genuine nonprofit, eroding trust and fundraising capacity.
- Email authentication controls and out-of-band financial verification procedures are the primary defences, and both are achievable within nonprofit budget constraints.
- The reputational damage from a BEC attack that results in donor fund loss compounds the direct financial loss and affects future fundraising capacity.
Why Are Nonprofits Particularly Vulnerable to BEC?
Business email compromise attacks work by exploiting trust in professional relationships and authority hierarchies. In a commercial organization, wire transfers and vendor payments typically pass through a multi-step approval process with defined controls. In many nonprofits, the executive director or a small senior team has broad authority to authorize payments, and requests from those individuals are acted on quickly by staff who want to be responsive to leadership.
This authority structure, combined with the informal culture of many nonprofits and the genuine urgency of mission-driven work, creates conditions that BEC attacks are optimized to exploit. A request that appears to come from the executive director, framed as urgent, requesting a payment or fund transfer before an upcoming board meeting or grant deadline, lands in an environment where the combination of authority and urgency produces compliance rather than scrutiny.
Nonprofits also operate with less financial control infrastructure than commercial organizations of comparable size. Small finance teams, part-time bookkeepers, volunteer treasurers, and boards that meet quarterly rather than continuously create gaps in financial oversight that BEC attackers identify through research before launching their campaigns.
What BEC Patterns Target Nonprofits Specifically?
Executive Director Impersonation
The most common pattern against nonprofits involves impersonating the executive director in an email to a finance manager, development officer, or board member. The email requests an urgent wire transfer to a new vendor, asks for a change to payment details for an existing vendor, or requests a gift card purchase for a donor recognition purpose. The email arrives from a spoofed address or a lookalike domain that appears to be from the executive director’s legitimate account at a casual glance.
The success of this pattern depends on two factors: the email appears credible, and the recipient acts without verifying through a separate channel. Adding a phone verification requirement for any financial request arriving by email, using a known phone number rather than a number provided in the email, interrupts this pattern at the critical moment regardless of how convincing the email appears.
Board Chair and Major Donor Impersonation
Larger nonprofits with active major donor programmes face a related pattern: impersonation of board members or major donors to redirect gifts or establish fraudulent payment relationships. An attacker who has researched the organization’s major donor list and board composition can construct an email that references real relationships, real projects, and real amounts in ways that make the fraud difficult to detect without out-of-band verification.
Development officers who receive what appears to be a communication from a major donor changing their giving instructions, or a board member who appears to be facilitating an introduction to a new significant donor, are interacting with an attack that has been specifically constructed for their organization. Generic security awareness training does not prepare staff for this level of targeting. Training that includes realistic scenarios specific to the nonprofit development context is more effective.
Fake Charity and Donation Scams
Beyond attacks on the nonprofit’s own financial flows, the organization’s brand and donor relationships are targets. Fake charity scams that register lookalike domain names, create fraudulent donation pages that mimic the legitimate organization’s branding, and solicit donations through social media and email campaigns divert donor funds before they reach the genuine organization.
Donors who give to a fake charity website believe they have given to the legitimate organization. The genuine nonprofit loses those funds and, when the fraud is discovered, faces the reputational damage of being associated with a scam. Monitoring for brand impersonation, including lookalike domain registrations and fraudulent social media profiles, provides early warning that allows the organization to alert donors and pursue takedowns before significant funds are diverted.
Grant Payment Interception
Government and institutional grant payments represent significant concentrated financial flows for many nonprofits. BEC attacks that target grant administrators or finance staff to redirect incoming grant payments use the same pattern as commercial wire fraud: intercept communications about an expected payment, substitute fraudulent banking details, and collect the redirected funds. The tight timelines of grant disbursements and the significant amounts involved make this pattern particularly damaging when successful.
What Controls Prevent BEC at Nonprofits?
Email authentication is the foundation. DKIM, SPF, and DMARC records configured to enforcement policy prevent attackers from sending emails that appear to originate from the nonprofit’s own domain. Many nonprofits have partial email authentication that does not reach DMARC enforcement, leaving the domain available for spoofing in external emails. A full email authentication configuration closes this gap and is a standard part of Armour’s email security programme.
Multi-factor authentication on all organizational email accounts eliminates the risk of credential phishing that gives attackers authentic access to a senior leader’s inbox. A BEC attack conducted from the actual executive director’s inbox, rather than a spoofed address, is significantly harder to detect. MFA on organizational email is the control that prevents inbox compromise from becoming the vector for BEC.
Financial verification procedures that require phone confirmation to a pre-established number for any payment request arriving by email, or any change to existing payment details, interrupt the BEC workflow regardless of how convincing the email appears. The phone call must go to a number the organization already has on file, not to a number provided in the suspicious email. This procedural control costs nothing and stops the majority of BEC attacks.
Brand monitoring that watches for lookalike domain registrations, fraudulent social media profiles, and fake donation pages provides early warning that the organization’s identity is being impersonated. When a fraudulent domain is detected early, takedown requests to the registrar and hosting provider, combined with donor alerts, can limit the damage before significant funds are diverted. Armour combines these controls in its nonprofit cybersecurity services, sized and priced for how charities and NGOs actually operate.
What Happens After a BEC Attack Succeeds?
When a BEC attack results in a fraudulent transfer, the immediate response determines how much is recoverable. The first action is to contact the sending financial institution to initiate a wire recall. Funds that have not yet been withdrawn from the receiving account may be recoverable if the bank is contacted within hours. Both the FBI’s Internet Crime Complaint Center and the RCMP’s Canadian Anti-Fraud Centre accept BEC complaints and can coordinate with financial institutions to attempt fund recovery.
The organization must notify affected donors if their data was accessed as part of the attack. If the compromise of an inbox that enabled the BEC attack also gave the attacker access to donor records or beneficiary information, breach notification obligations under PIPEDA and applicable provincial or state laws apply. Legal counsel and a cybersecurity advisor should be engaged promptly to assess the full scope.
The reputational management dimension is significant for nonprofits. Board notification, donor communication, and in some cases public communication about the incident require careful handling. How the organization communicates the incident, what it says about the controls it has implemented in response, and how it demonstrates its commitment to protecting donor trust determines whether the reputational damage is contained or compounds.
Across the 260+ organizations Armour Cybersecurity protects in 52+ industries, the nonprofits that lose money to BEC almost never lose it to a clever technical exploit. They lose it to a plausible email and a missing phone call. The ones that do not lose it made one unglamorous rule impossible to skip: no wire moves and no payment detail changes on the strength of an email alone, ever, without a callback to a number already on file, and they put DMARC at enforcement and MFA on every mailbox so the attacker cannot send from the real domain or sit inside the real inbox in the first place, which together turn the sector’s most expensive fraud into a call that ends with someone saying I never sent that.
Frequently Asked Questions
We are a small nonprofit with three staff. Can we really implement BEC controls?
Yes. The most effective BEC controls for small nonprofits are procedural rather than technical. A clear policy that no payment will be made on the basis of an email request alone, that all wire transfers require a phone call to a pre-established number, and that changes to vendor payment details require two-person approval addresses the majority of BEC risk without requiring enterprise IT infrastructure. MFA on email accounts adds the technical layer. Both are achievable by the smallest organizations.
How do we train volunteers to recognize BEC attempts?
Volunteer security awareness training needs to be shorter, more practical, and more scenario-specific than corporate security training. A fifteen-minute session that covers the specific scenarios volunteers are likely to encounter, donation redirect requests, urgent wire transfer requests that arrive by email, and messages that create pressure to act before verifying, with clear guidance on what to do when they encounter them, is more effective than a lengthy general awareness programme that does not connect to the volunteer’s actual role.
Does cyber insurance cover BEC losses for nonprofits?
Social engineering and BEC coverage varies across cyber insurance policies. Many policies require specific endorsements for social engineering fraud, and some require documented controls, including callback verification procedures, as a condition of coverage. Nonprofits should review their specific policy terms for BEC coverage before an incident, with guidance from a cyber insurance advisor. The gap between assumed and actual coverage is common and consequential.
Can we recover funds lost to a fake charity scam targeting our donors?
Recovery of funds donated to a fraudulent site impersonating your organization is primarily a law enforcement matter. Reporting to the FBI’s Internet Crime Complaint Center, the Canadian Anti-Fraud Centre, and the registrar of the fraudulent domain initiates the process. Civil action against the perpetrators is possible but depends on identifying them, which is not always achievable. The more effective response is monitoring to detect impersonation early and alert donors before significant funds are diverted.
The Bottom Line
Nonprofit BEC is not a sophisticated hack. It is a plausible email that borrows the authority of an executive director or board chair and lands in a culture built to be responsive and trusting, which is exactly the environment fraud is engineered for. The money moves because someone acted on an email instead of picking up the phone. The defence is proportionate and affordable: DMARC at enforcement and MFA on every mailbox so the domain and the inboxes cannot be used against the organization, and one non-negotiable rule that no wire and no payment-detail change happens on an email alone without a callback to a number already on file. Armour Cybersecurity helps nonprofits and NGOs protect donor and grant financial flows with nonprofit cybersecurity services that combine email security, monitoring, and incident response sized for the sector, so an urgent email asking for money becomes a thirty-second phone call rather than an irreversible loss.
About the author
David Chernitzky is the CEO and Co-Founder of Armour Cybersecurity, a Toronto-based firm that protects organizations across North America from advanced cyber threats. He brings more than 25 years of cybersecurity and military cyber intelligence experience, having served as an officer in an elite technology unit before co-founding Armour. Armour’s team of military-intelligence veterans and senior advisors serves 260+ clients across 52+ industries with a 97% client retention rate. Learn more about Armour Cybersecurity.



