October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Why Criminals Use Charity Websites to Test Stolen Credit Cards

Criminals have used low-friction charity donation pages to test stolen cards with small payments. Learn the warning signs and how charities and donors can respond.
From TheFinanceBase Team5 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Criminals have used charity donation pages to check whether stolen credit-card details still work. They submit small payments through low-friction donation forms, then use the results to identify cards that may be usable elsewhere. This is card testing—not evidence that the charity knowingly took part—and even tiny fraudulent donations can leave a nonprofit handling refunds, processor reviews and chargebacks.

How charity donation pages get used for card testing

In the service PhishLabs described, criminals sent stolen card numbers, names and expiration dates to an IRC bot. The bot tried transactions through charity or nonprofit websites and returned transaction details that helped criminals assess whether cards were valid. SecurityWeek reported that the same service also checked package-tracking numbers and cardholder addresses.

The PCI Security Standards Council calls this broader pattern automated account testing or card validation. Its 2020 bulletin says test payments typically range from $1 to $5. A payment that looks like a small donation may therefore be part of an attempt to verify stolen data, rather than a genuine gift.

LexisNexis reported bot attacks using $1 or $5 charity payments, followed by larger purchases on other services or websites when card data was validated. The report’s date is not stated here, so those amounts describe the reported incidents, not a current universal pattern.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why criminals target donation forms

Charities often make giving quick by removing account-creation and other checkout barriers. The Chronicle of Philanthropy described this donor-friendly design as one reason donation pages can be attractive targets: fewer steps can also make it easier for automated attempts to move through a payment flow. Retail checkout may ask for more identity or purchase information.

This creates a real tension for nonprofits. Adding friction to every donation can make giving harder for legitimate donors, while leaving a payment form without adequate safeguards can expose the charity and its donors to abuse. Kevin Conroy, then GlobalGiving’s chief product officer, described the sector’s exposure to card thieves as a “giant target painted on the industry’s back,” as quoted by the Chronicle.

Rank #2
Sale
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
  • Ideal for Gifting
  • Ideal for a bookworm
  • Compact for travelling

What the documented incidents show

Historical cases illustrate the possible operational and financial consequences. They are examples from particular organizations and years, not estimates of what a charity should expect today.

Organization and reporting Reported activity and impact
Jack & Jill Children’s Foundation, 2013 The foundation reported that more than €130,000 was refunded; most fraudulent donations were under €5. It said criminals used its website to test whether stolen cards remained active.
New Zealand charity, reported by NetSafe, 2015 NetSafe reported almost 50,000 automated attempts and more than 2,000 successful donations. The charity needed its bank and merchant-account provider to refund fraudulent payments.
DonorsChoose, as reported by the Chronicle of Philanthropy, 2015 About 3% of transactions were flagged for extra screening. This is a historical case figure, not a current benchmark for donation fraud or screening rates.

These cases show why the face value of a suspicious payment is not the whole cost. A series of small transactions can create substantial review and refund work, and can require coordination with a bank or payment provider.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Signs a donation may be a stolen-card test

No single clue proves fraud. Look for patterns across transactions and assess them alongside your processor’s alerts and the charity’s usual donation activity.

  • Small token payments: unusually small donations, especially when they arrive in a cluster. The UK government’s charity-compliance toolkit identifies small token donations as a warning sign; PCI SSC also lists clusters of small payments as an account-testing indicator.
  • Repeated attempts involving one card: the UK toolkit identifies repeated use of a single card as a concern.
  • Inconsistent or nonsensical donor details: names that do not match cardholders, or random characters in required name or address fields, are among the UK toolkit’s warning signs.
  • Rapid, automated activity: PCI SSC identifies rapid automated attempts as an indicator of account testing. A burst of transactions that departs from the organization’s normal pattern warrants prompt review.

What a charity should do about repeated $1 donations

  1. Review the cluster promptly. Check the payment-provider records for related suspicious activity, including repeated attempts and small-payment clusters. Use the provider’s fraud and transaction-monitoring tools rather than treating each donation in isolation.
  2. Apply the charity’s fraud controls. Use appropriate velocity limits, bot detection, device and network anomaly checks, and card-verification controls. The exact settings depend on the payment flow and provider; the available evidence does not establish a universal threshold that every charity should use.
  3. Contact the acquiring bank and payment processor. Coordinate on suspected card testing, suspicious transactions and the appropriate handling of refunds or reversals. The New Zealand case reported by NetSafe involved the charity’s bank and merchant-account provider in refunding fraudulent payments.
  4. Investigate and document unusual transactions. The UK government toolkit recommends investigating unusual transactions. Keep the review focused on the patterns and records needed to assess the activity and coordinate with relevant payment or information-sharing channels.
  5. Reverse fraudulent donations where appropriate. The Chronicle described GlobalGiving using automated monitoring and proactive reversals. Prompt reversals can help reduce chargebacks, but the charity should coordinate the handling with its payment provider.
  6. Escalate through relevant channels. Where warranted, coordinate with relevant law-enforcement or information-sharing channels as well as the payment institutions involved.

Controls small charities can put in place

There is no single control that addresses every part of card testing. A layered approach can combine payment limits, automated-abuse detection and human review without assuming that every small donation is fraudulent.

Control What it addresses Practical consideration
Transaction velocity limits Rapid or repeated payment attempts Set limits with the processor in a way that considers normal donation patterns; no universal threshold is established by the cited guidance.
Bot detection and device or network anomaly checks Automated activity and unusual clusters Ask the payment provider what monitoring is available for the charity’s actual payment flow.
Card-verification controls Attempts to use card details in transactions Confirm which verification controls the processor supports and how they apply to the charity’s checkout.
Processor monitoring and review procedures Suspicious payment patterns, investigation and response Agree who reviews alerts, how suspicious activity is escalated, and how refunds or reversals are handled.

Implementation effort, processor integrations, false-positive rates and total cost vary by provider and setup; the cited material does not give current comparable product data or prices. Matt Holford, then DoSomething.org’s chief technology officer, told the Chronicle that a unified solution was difficult because organizations had different technology stacks, payment flows and processors. For a small charity, the practical first step is to understand which safeguards and monitoring its existing provider offers, then establish a clear review and escalation process.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What donors should know

A suspiciously small charge on a card statement can be a sign of card testing, but it does not by itself identify who initiated the transaction or establish that a charity acted improperly. If you see an unfamiliar transaction, contact your card issuer promptly using the contact details on your card or statement and follow its instructions. The nonprofit may be dealing with fraudulent activity against its own donation page as well.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

SaleBestseller No. 1
SaleBestseller No. 2
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
Ideal for Gifting; Ideal for a bookworm; Compact for travelling
$10.99
SaleBestseller No. 5
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
It can be a gift option; Comes with secure packaging; Helpful in various ways
$9.15
Best Value
Sale
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
  • It can be a gift option
  • Comes with secure packaging
  • Helpful in various ways

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.