Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesCybercrime can cost a charity money, interrupt services, expose sensitive information and undermine the trust on which fundraising depends. UK government data for 2025/2026 estimates that 14% of charities—about 28,000 organisations—experienced at least one cybercrime in the previous year. A broader 28% identified a cyber-security breach or attack. These are different measures: cybercrime is a subset of the wider category.
Charities are attractive targets not because every organisation is technically weak, but because they combine donor and beneficiary data, public payment channels, trusted communications, cloud services and distributed staff or volunteers. A proportionate baseline—multi-factor authentication, tested backups, patching, payment verification and a practiced response plan—reduces the most damaging risks.
What counts as cybercrime against a charity?
Cybercrime is an offence involving computers, networks, accounts or digital systems. A cyber-security breach or attack is broader and can include accidental disclosure, technical failure or attempted attacks that are not proven crimes. Technology-enabled fraud includes an impostor redirecting a supplier payment; a data breach is unauthorised access, disclosure, alteration or loss of personal data. Fake charity websites or appeals are cyber-enabled abuse aimed at donors or the public.
The UK survey warns that its cybercrime estimate and its breach-and-attack estimate must not be treated as interchangeable. Results are survey estimates, not a complete incident register, and undetected incidents cannot be counted reliably. See the Cyber Security Breaches Survey 2025/2026 for definitions and methodology.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What the latest UK data shows
| Measure | 2025/2026 result |
|---|---|
| Charities experiencing at least one cybercrime in the previous year | 14% (approximately 28,000 charities) |
| Charities identifying any breach or attack | 28% |
| Charities treating cyber security as a high priority | 60%, down from 68% in 2024/2025; among low-income charities, 53%, down from 64% |
| Seeking external cyber-security guidance | 31% |
| Weekly-or-more incidents, among charities identifying any | 26% |
| Most disruptive type, among those able to specify | Phishing, 69% |
| Policy not to pay ransomware demands | 38% |
| Unsure of ransomware-payment policy | 25% |
| Reporting externally beyond an IT or cyber provider, among those identifying an incident | 33% |
| No action after an incident with a material outcome | 11% |
The survey’s median perceived cost for a charity’s most disruptive incident was £0; the 95th-percentile cost was £1,000. These self-reported figures may miss long-term, indirect or unreported harm, and a loss that is small to a large organisation can threaten a small charity.
Why charities are attractive targets
Valuable personal and operational data
Records may include donor names and giving histories, Gift Aid and payment information, beneficiary health or safeguarding details, volunteer and employee files, passwords, access tokens, grant applications and restricted-fund information. Criminals can monetise data, use it for extortion or exploit access to trusted accounts.
Trust makes impersonation effective
Supporters are inclined to open messages about emergency appeals, disaster relief, Gift Aid, events, volunteering or grants. Criminals can imitate a charity, compromise a genuine mailbox or replace a donation link. The historical 2020 BetaNews Q&A identified this dual risk—attacking the organisation and deceiving its donors—but its prevalence and advice are now dated.
Limited capacity and distributed access
Small budgets, volunteers, remote work, shared devices and many cloud applications create practical constraints. Larger charities may have substantial security teams; income is not a perfect measure of technical maturity, so the right response is proportionate controls rather than assumptions about carelessness.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchRank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Attack routes that matter most
Phishing and account takeover
Fake Microsoft 365 or Google Workspace pages can steal credentials, while attachments or links may install malware. A compromised mailbox can expose donor files, create forwarding rules or send convincing internal requests.
Business-email compromise and payment diversion
Common scenarios include a fake chief executive requesting an urgent transfer, a supplier “changing” bank details, a grant recipient receiving new payment instructions or a fundraiser’s mailbox contacting donors. Verify new account details, unusual payments, payroll changes and refunds through a known telephone number or separate channel—not contact details supplied in the suspicious message.
Ransomware
Ransomware can encrypt shared drives, stop casework and fundraising, steal data before encryption and create legal and communications work even when no ransom is paid. Trustees should decide in advance who can make any payment decision, what specialist and legal advice is required and how essential services will continue.
Website and social-media compromise
Attackers may replace donation links, publish fraudulent appeals, deface a website or use a legitimate social account to distribute malicious links. Public channels are both operational systems and trust assets.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Supplier and cloud compromise
Donor-management, payment, email-marketing, website, storage, IT-support, volunteer and case-management providers can all become attack paths. Certification is not a guarantee: record what data each supplier holds, its access, incident-notification process, export arrangements and continuity plan.
Lost devices and accidental disclosure
An unencrypted laptop or phone with logged-in accounts can expose data. Other incidents include emailing a spreadsheet to the wrong person, making a cloud folder public, reusing passwords, retaining a former volunteer’s access or sending a bulk email incorrectly.
How the damage spreads
Financial losses and response costs
- Stolen donations, diverted supplier or payroll payments and fraudulent refunds.
- Forensic investigation, legal advice, emergency restoration, notifications and possible credit-monitoring support.
- Lost fundraising during downtime, website rebuilding and supplier remediation.
Service disruption
Staff may lose access to beneficiary records, referrals, helplines, emergency payments, payroll, volunteer contacts, donation reconciliation or safeguarding information. The practical harm can therefore fall on beneficiaries rather than only on the balance sheet.
Trust, privacy and safeguarding
Donors may stop giving if scam messages come from a compromised account. Exposure of information about children, domestic-abuse survivors, refugees, patients, trafficking victims or whistleblowers can create physical or social risk far beyond an ordinary mailing-list breach. Assess whose data was affected, what it reveals, how easily it can be misused and the vulnerability of the people involved.
Recommended Free Tools
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Governance and opportunity cost
Trustees may face regulator, contract, funder, bank, insurer and law-enforcement requirements. Staff can spend weeks resetting passwords, preserving evidence, rebuilding systems, answering donors and preparing notifications instead of delivering services.
A proportionate security baseline
- Enable MFA: cover email, administrator, banking, payment, donor, cloud, social-media and remote-access accounts. Use phishing-resistant methods where practical; an authenticator app is generally preferable to SMS alone.
- Use unique passwords and individual accounts: a password manager, role-based access and a documented leaver process prevent shared credentials from becoming permanent access.
- Patch and retire unsupported systems: prioritise internet-facing services, operating systems, browsers, routers and remote-access tools.
- Maintain independent backups: back up regularly, restrict ordinary-user access, separate copies from the main network where possible and test restoration. An untested backup is an assumption, not a recovery plan.
- Train with realistic examples: practise fake invoices, shared-document invitations, login pages, donation links, social-account recovery and safe reporting of mistakes. The NCSC’s free staff training is a starting point.
- Set payment rules: require two-person approval and independent call-back verification for new bank details, urgent transfers, payroll changes, refunds and unusual donations.
- Harden email and domains: use anti-phishing controls, domain authentication, separate administrator accounts, forwarding-rule alerts and restrictions on automatic external forwarding.
- Minimise retained data: delete information no longer needed and limit access by role.
- Manage suppliers: document data held, MFA support, incident contacts, export rights, service outages and access revocation.
- Write and rehearse an incident plan: name the incident lead, technical provider, trustee escalation, legal or data-protection contact, bank, insurer, regulator, communications lead and law-enforcement route, with an alternative communication channel if email is compromised.
The NCSC charity resources, Small Organisations Guide and charity guide PDF provide free implementation advice.
What trustees should ask
- What are our three most critical systems and who administers them?
- Is MFA enabled on every important account, including social media and banking?
- Can we restore a recent backup, and when was restoration last tested?
- Who can approve payments and verify changed bank details?
- Which suppliers hold sensitive data, and how would they notify us?
- Who coordinates the first hour if email or systems are compromised?
- When was the incident plan last rehearsed?
What to do after an incident
First hour
- Record the time, symptoms, affected accounts and suspicious messages; preserve emails, headers, screenshots, payment instructions and logs.
- Disconnect suspected ransomware or actively compromised devices from networks, but do not wipe or rebuild before evidence is preserved.
- Call the IT provider or incident-response specialist and the bank immediately if money or payment details are involved.
- Disable compromised accounts and revoke active sessions where appropriate, using a clean device.
- Escalate to senior management and trustees under the plan; avoid using the possibly compromised mailbox for coordination.
- Do not negotiate with an attacker or promise that no data was accessed until specialists have assessed the facts.
First day
- Map affected systems, accounts and data subjects; check for unauthorised mailbox rules, new accounts and changed payment details.
- Confirm whether backups are intact and whether an attacker still has administrative access.
- Reset credentials from a clean device and determine legal, regulatory, contractual, insurer and funder notifications.
- Issue one approved message to staff and volunteers, then prepare safe donor or beneficiary communications if public channels are affected.
- Report suspected fraud or crime through the relevant UK channels and obtain specialist advice. Reporting duties differ by jurisdiction, regulator and incident facts.
When free guidance is enough—and when to pay for help
Free or routine IT support may suffice when
- A single suspicious message was received and no one interacted with it.
- No account, device or data compromise is indicated.
- MFA, tested backups and a capable IT provider are already in place.
- The charity needs baseline policy, training or configuration help.
Specialist response is justified when
- An account is taken over, ransomware or data exfiltration is suspected, or banking details are involved.
- Beneficiary, safeguarding or other sensitive personal data may be exposed.
- Backups are unavailable or the attacker may retain administrator access.
- Several suppliers or cloud services are implicated, or public or regulatory notification is likely.
Managed security can provide administration, monitoring and escalation without a full-time employee, but accountability remains with trustees. Cyber Essentials can demonstrate a UK baseline for funders or contracts; it does not prevent every phishing, insider, cloud or ransomware incident. Insurance may fund response and restoration, but check MFA, backup, patching conditions, exclusions, sub-limits and notification requirements before relying on it.
Questions and answers
Are charities more vulnerable than businesses?
Not universally. Charities can be attractive because of their data, trusted brands and payment channels, while resources and expertise vary widely. The survey does not prove that charities are inherently less secure than commercial organisations.
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Should a charity ever pay ransomware?
There is no universal answer. Decide in advance who has authority, obtain legal and specialist advice, consider sanctions and law-enforcement issues, and maintain a continuity plan. The 2025/2026 survey found 38% had a policy not to pay and 25% did not know their policy.
Does MFA solve account takeover?
MFA substantially reduces credential-theft risk, but stolen sessions, social engineering and weak recovery processes can still be exploited. Secure recovery and monitoring are necessary as well.
What is the first control for a small charity?
Put every important identity behind MFA, eliminate shared administrator accounts and document who can approve payments. Then establish tested backups and a simple incident contact list.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




