One Organization, Five Scams: What a Real Impersonation Case Reveals About Fundraising Fraud

A trusted organization recently watched its own name become the bait for a sophisticated fraud campaign. Scammers cloned its brand, created fake profiles of its executives, and launched counterfeit donation pages, all designed to target the people who trust the organization most. This is what fundraising scams look like today: coordinated impersonation campaigns that exploit a legitimate organization’s credibility and turn it against its own audience.
The target in this case happened to be a nonprofit, but the playbook works in any sector. Swap the fake donation page for a counterfeit checkout, a spoofed banking portal, or a fraudulent alumni campaign, and the tactics barely change. Every fake fundraiser and impersonated leader chips away at the one asset organizations can least afford to lose: the trust of the people they serve. In the worst cases, they convince people to hand over money, credentials, or even become part of the fraud themselves. Read on to learn how scammers abuse trusted brands, and how defenders are working to stop them.
Why Any Trusted Brand Is a Target for Fundraising Scams
Scammers want three things in a target: a recognizable name people already have confidence in, a public way to move money, and a reason to act fast. Fundraising brings all three together. People visit fundraising webpages expecting to donate, supporters are already inclined to trust the organization asking for help, and there's often a deadline, crisis, or another reason people feel pressure to act quickly. That combination makes fundraising an ideal cover for impersonation, and the same tactics work anywhere trust and urgency intersect.
The most convincing scams borrow real credibility. Recently, the ZeroFox Signals Research Team uncovered an investment scam that impersonated a licensed financial adviser and linked to her legitimate credentials to make a fraudulent cryptocurrency scheme appear authentic. The same playbook powers fake donation pages, spoofed bank alerts, and counterfeit retail promotions.
The reach is bigger than most teams expect. According to the FTC, consumers lost $3.5 billion to imposter scams in 2025, the fifth consecutive year they ranked among the most-reported fraud categories. Many of those scams begin on social media, but impersonators also operate through search, email and text messages, allowing fake versions of trusted brands to reach people through the same channels those organizations use every day.
$3.5 billion: reported losses to imposter scams in 2025, the fifth year running they topped the FTC's fraud list.
Federal Trade Commission, June 2026
How Fundraising Scams Show Up
For this organization, impersonators used five different tactics to exploit its brand and the trust surrounding it. Each tactic is effective on its own, and none of them are unique to nonprofits.
Lookalike and Spoofed Domains
The attackers registered web addresses that looked almost identical to the real one, then used them to create fraudulent fundraising and payment pages under the organization's name. It’s the same trick behind counterfeit checkout and login pages for a retailer or a bank. The FBI warns specifically about copycat and lookalike names in charity and disaster fraud, and the tactic works because donors rarely check a web URL character by character.
Fake Fundraising and Crowdfunding Campaigns
Fraudulent crowdfunding campaigns traded on the organization’s reputation, often reusing stolen photos and AI-generated content to appear legitimate. Platforms like GoFundMe offer ways to report suspicious fundraisers and back eligible donations through the Giving Guarantee. However, someone has to recognize the scam and report it before the platform can step in. Unfortunately, by the time a fake campaign is reported, it may have already collected donations. That's why external cybersecurity like Attack Surface Intelligence is so important to help protect both brands and their customers.
Executive Impersonation
Fake LinkedIn profiles and social accounts posed as named executives, built partly from personal details pulled off data-broker sites. This is one of the most common forms of brand impersonation, and any public-facing leader is a potential target, as their names already carry authority and trust.
Social Media Account Impersonation
Spoofed social accounts posed as the brand itself and messaged its followers directly, mixing donation asks with the ordinary-looking updates that make an account feel legitimate. It’s a widely-used tactic, because people tend to trust accounts with recognizable branding, and rarely think to verify them.
The Money-Mule Recruitment Twist
The abuse didn't stop at fake fundraising pages. Impersonators began using a finance leader's name to recruit college students into fake research jobs posted to a university job board. The recruits, believing they’d found legitimate work, were unknowingly acting as money mules by transferring stolen money on behalf of criminals. What began as brand impersonation had expanded into a money-laundering operation under the cover of a trusted organization’s reputation. It's a growing problem: according to the FTC, reported losses from job and employment scams rose from $90 million in 2020 to $501 million in 2024.
Red Flags Your Audience Misses
- Vague details about who actually benefits from the money
- A brand-new organizer account with little or no history
- Pressure to give right now
- Photos that appear elsewhere online or look AI-generated
- A web address, social account, or payment destination that doesn't match the organization's official channels
Why Fundraising Scams Are So Hard to Stop on Your Own
Most organizations aren't dealing with just one fake account or website. They're dealing with potentially dozens spread across social platforms, crowdfunding sites, domain registrars, search results, messaging apps, and anywhere else scammers can reach their audience.
Each platform has its own reporting process, response times, and rules for what qualifies as impersonation. Even if an internal team finds every fake, removing them quickly becomes a full-time job.
Defensive domain registration helps, but it isn't enough. An organization can buy the obvious misspellings of its domain, but scammers are known to be creative, and can register new variations in minutes. It's an important layer of defense, not a complete solution.
The bigger challenge is that these threats don't stay neatly separated. A fake domain can support a fraudulent fundraising page. An impersonated executive can lend credibility to a fake job posting. A spoofed social account can send followers directly to a fraudulent site.
The more pieces an organization has to connect, the harder it becomes to understand what is actually happening and what threats need to be addressed first.
How These Scams Get Shut Down
Detecting fake accounts is only the first step. Security teams need evidence and context to separate real threats from false positives, prioritize the ones capable of causing harm, and disrupt them before they spread and reach more people. That's where ZeroFox comes in.
It starts with visibility. You can’t disrupt an impersonation you haven’t discovered, so ZeroFox continuously monitors social platforms, crowdfunding sites, the deep and dark web, and newly registered domains to uncover threats, including exposed executive data and PII scammers use to make fake profiles look convincing.
Validation determines which threats deserve your attention. Discovery uncovers suspicious domains and profiles, but only some pose a real risk to your brand. ZeroFox correlates signals across the surface, deep, and dark web, combining AI detection with analyst review to confirm intent, ownership, and relevance before an alert reaches your queue. Every confirmed impersonation includes supporting evidence, giving your team the context to understand who is being targeted, threat severity, and how to respond.
Once a threat is confirmed, the focus shifts to disruption. ZeroFox combines automated action, analyst review, and a global partner network to remove impersonation threats across fragmented platforms. For the organization in this case, that meant fake fundraising pages and impersonator accounts taken down, along with exposed executive data reduced, without limiting the leader’s legitimate public presence.
Behind the scenes, that process runs at enterprise scale. ZeroFox monitors more than 180 platforms and over 6 billion domains, works through a Global Disruption Network of more than 80 partners, maintains a 95% takedown acceptance rate, and completes more than one million takedowns each year.
What Your Organization Can Do Now
You don’t need a fifty-person security team to become a harder target. A few concrete moves help right away:
- Monitor for lookalike domains and register the highest-risk variants of your web address. Registration alone will never cover every variation, so treat it as one layer among several.
- Claim and verify your official accounts on every platform. Then publish a single "official channels" page your audience can use to verify an account in seconds before they click or donate.
- Give the public a fast, obvious way to report suspected fakes. Make it easy for supporters, customers, employees, and partners to tell you when they encounter a suspicious account, domain, or fundraising campaign.
- Reduce your executives' personal-data exposure at data brokers. The less information available to impersonators, the harder it is to build convincing fake profiles and fraudulent outreach.
- Line up a takedown path before your peak-fraud moments arrive. Disasters and holidays can create urgency for donation-driven organizations. Product launches, earnings announcements, major campaigns, and other high-visibility moments can create the same opportunity for everyone else.
Stop Fundraising Scams Before They Reach Your Audience
Impersonation campaigns thrive on time. The longer a fake profile, fundraising page, or scam stays live, the more people it can reach and the more damage it can do. Early discovery and fast disruption can stop a single impersonation from becoming a much larger problem.
Protect the trust your organization has earned. Schedule a tailored demo to see how ZeroFox HNTR helps security teams discover impersonation activity earlier, validate real threats faster, and disrupt them before they can do damage.