Home Articles Get your free assessmentComing soon

After the Storm: Disaster-Relief Giving Fraud Runs Both Ways

A folding table with a cardboard donation box, bottled water, and a clipboard in a church fellowship hall

The storm came through on a Thursday night. By Friday morning the church has already decided to help — that’s not a decision that takes a meeting, and it shouldn’t be.

By Friday afternoon two things are in motion.

A message is circulating among your members with your church’s name on it, asking for donations to the relief effort, with a link. Nobody at the church wrote it.

And in the office, an email has arrived from a coalition of regional relief organizations mobilizing in the affected county. They need commitments today; trucks leave in the morning. The letterhead is good, the tone is right, and there’s a wire transfer instruction at the bottom. The benevolence fund has $8,000 in it, and the pastor is inclined to send $5,000.

Disaster fraud runs in both directions at once, and most guidance only covers one of them.

Direction one: someone raises money in your name

Disasters generate two things attackers want: an obvious reason to ask for money, and a population that has already decided to give.

Your church supplies the third ingredient — a name people trust. So a page appears, or a Facebook post, or a text message chain among your members, with your church’s name and often your logo on it. The money goes somewhere else.

The specific mechanics of cloned pages and lookalike names deserve their own treatment, and we’ve covered them separately. What matters here is the timing. A disaster compresses the window in which your members will believe an unusual appeal. In an ordinary week, a message asking for an immediate wire to a new account would strike your congregation as odd. In the week after a hurricane, it strikes them as exactly what a church would be doing.

The defense is to occupy the space first. Within twenty-four hours of any disaster your church responds to, publish — bulletin, email, website, social — a short statement that says exactly how you are collecting, and exactly how you are not:

We are receiving relief donations through [your normal giving page and address] only. We will not ask you for gift cards, wire transfers, or cryptocurrency, and we will not send anyone to your door. If you see an appeal using our name anywhere else, please tell the office before you give.

Send it before you need it. The point is not to warn about a specific fake; it’s to establish what normal looks like while your members are still calm enough to read carefully.

Direction two: your money goes out the door

This is the direction churches don’t see coming, because it doesn’t feel like fraud. It feels like generosity under time pressure.

The pattern is consistent. A relief organization contacts you — by email, sometimes by phone, sometimes through a name-drop from someone in your network. It has a real-sounding name, often one syllable away from an organization you’ve actually heard of. There is a deadline: trucks, a matching gift that expires, a shelter opening Monday. The ask is a wire transfer, a cashier’s check by overnight mail, or increasingly a payment through an app to a person who “coordinates” for them.

Sometimes there’s no organization at all. Sometimes there’s a real disaster and a real need and a fake middleman. Occasionally the request arrives from a compromised mailbox belonging to someone you genuinely know, which is why it survives the sniff test.

The variant aimed squarely at churches: an individual applies to the benevolence fund and needs help urgently because of the disaster — a relative stranded, a deposit on temporary housing, a vehicle repair to get to the affected area. The money needs to go to a third party, right now, by a method that can’t be reversed.

Urgency is not a detail of these attacks. It is the entire mechanism. Every element of the pitch exists to remove the interval in which somebody would have checked. Take that interval back and almost nothing else matters.

Why churches are especially exposed here

Not negligence. Structure.

Speed is a virtue in your world. A church that takes eleven days to approve disaster relief has failed at something real. Your instincts are correctly tuned for compassion, and fraud is designed to ride those instincts, not defeat them.

Benevolence funds are built to move fast. They often have looser approval than the operating budget by design — that’s the point of having one. That same design means a single person can frequently authorize a payment without a second signature.

The approver is often one person. A pastor or an administrator who will not want to say “let me check” to someone describing a family sleeping in a car.

Ministry networks are informal. Partnerships form through relationships, conferences, and word of mouth, so an unfamiliar organization introducing itself is not unusual. In the corporate world, an unknown vendor asking for a wire is a red flag on its own. In yours, it’s Tuesday.

Vetting an organization, and choosing how the money leaves

You don’t need a due-diligence department. You need four checks, and together they take about as long as a coffee break.

Confirm it exists as a tax-exempt organization. The IRS Tax Exempt Organization Search tool lets you check “an organization’s eligibility to receive tax-deductible charitable contributions.” Search the exact legal name. If nothing comes up, that alone isn’t proof of fraud — small groups and churches are treated differently — but it means you need a different reason to believe in them.

Check state charity registration. Most states require organizations soliciting donations to register. Your state’s charity office, usually within the Attorney General’s or Secretary of State’s office, can confirm it. The National Association of State Charity Officials maintains a directory of all of them.

Look them up at a standards-based evaluator. BBB Wise Giving Alliance publishes free reports at give.org against twenty accountability standards covering governance, finances, and truthful representation. The FTC points people to it and to Charity Watch for exactly this purpose.

Search the name plus a hostile word. The FTC’s own advice: search the organization’s name along with “complaint,” “review,” “rating,” “fraud,” or “scam.” And the FTC’s blunt rule of thumb — “if you can’t find detailed information about a charity’s mission and programs, be suspicious.”

If an organization is real and the need is real, none of this offends anyone. Legitimate relief organizations are asked to prove themselves constantly and have the answers ready.

Then decide how you’ll send it, because that matters as much as who receives it. Some payment methods can be stopped or reversed. Some cannot. Fraudsters know exactly which is which, and they will steer you toward the second group while telling you it’s about speed.

Never send by gift card, wire transfer, cryptocurrency, or cash on a first contact. The FTC states it plainly: “Don’t donate to anyone who insists you must pay by cash, gift card, wiring money, or cryptocurrency.” A relief organization does not need gift cards. Nobody’s supply truck runs on iTunes credit.

Use a method with a paper trail and some recourse — a check to the organization’s legal name, or a credit card. Both give you something to point at later.

And apply the money rule you already use for vendors. Any change to payment details — and any new payment instruction from a partner you already have — is verified by voice, on a phone number you already had, before the money goes out. Not the number in the email. The disaster version of that rule is one sentence longer: a new organization you’ve never paid before does not get a wire on its first contact, no matter what the deadline is.

Route disaster giving through relationships you already have

This is the single highest-leverage decision, and you can make it before any disaster happens.

Most churches and nonprofits already have partners: a denominational relief arm, a regional association, a food bank, a long-standing mission partner, a local ministerial alliance. These organizations are typically on the ground faster than any stranger who emails you, and you can verify them once and reuse that verification for the next twenty years.

Write it down as policy, in one sentence:

Disaster giving goes to organizations we already have a relationship with. Anything else requires two people to approve and a twenty-four-hour wait.

That policy costs you almost nothing in real responsiveness — a day, at most, on a giving decision, and your existing partners are unaffected. It costs a fraudster everything, because the pitch depends entirely on being answered inside the hour.

The same shape works for benevolence: any benevolence payment to a third party rather than to the applicant, or by any irreversible method, waits until tomorrow and is approved by two people. Applicants with genuine need are not harmed by a day. The scripts fall apart.

If it already happened

Move within hours, not days.

Call your bank immediately and ask about a recall. Wires and ACH transfers have narrow windows, but they exist, and the window closes fast.

Report it to the FBI at ic3.gov the same day. Include the account details, the amount, and the timeline. The Bureau’s Recovery Asset Team froze $507,042,623 across 3,574 domestic incidents in 2025, and that process depends almost entirely on speed — it works dramatically better inside the first 24 to 72 hours.

Report it to your state charity regulator and the FTC, which is how patterns get built into cases.

Then tell your congregation what happened, if their gifts were involved. Plainly, without drama. Organizations that get quiet after being defrauded do more damage to their own credibility than the fraud did.

What to do this week

Write the two policy sentences down — disaster giving goes to existing partners; anything else waits twenty-four hours and needs two approvals — and email them to everyone who can authorize a payment. Ten minutes.

Then draft the congregation notice now, while nothing is happening. Save it where you can find it. Fill in your real giving address, state that you’ll never ask for gift cards or wires, and leave it ready to send the same day something happens near you. Twenty minutes today, and it goes out inside an hour when it matters.

MissionDefend’s free assessment walks through how your organization handles email, donations, member data, and accounts in plain English — including who can move money and how fast — and gives you a baseline score and a ranked list of what to fix first.

No spam and no sales calls — just one email when it’s live.


MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

Sources: Federal Trade Commission, Before Giving to a Charity; Federal Trade Commission, After a disaster, make your donations count; Internal Revenue Service, Tax Exempt Organization Search; BBB Wise Giving Alliance, give.org; National Association of State Charity Officials, State Government directory; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.

Found this useful? Pass it on.

Facebook X LinkedIn Email