After wildfires, hurricanes, wars, or year-end giving season, scammers invent charities that never existed—or clone the names of the Red Cross, United Way, UNICEF, local food banks, and GoFundMe-style campaigns. They want card numbers, bank logins, gift-card PINs, or wire details. Real charities solicit; fake ones pressure, spoof, and vanish.
Broader map: Credit and debt scams. Phishing patterns: Phishing and account takeover. Gift-card payment demands: Gift card payment scams.
Red flags vs normal fundraising
| Signal | Fake / high risk | Legitimate pattern |
|---|---|---|
| Urgency | “Donate in the next 15 minutes or matching ends forever” via cold call/text | Deadlines exist; high-pressure cold outreach is a warning |
| Payment method | Gift cards, crypto, wire, cash-reload PINs | Card/ACH through the charity’s official site or established processors |
| Name | “Red Cross Disaster Relief Fund LLC” with a slightly wrong URL | Exact legal name; HTTPS site you typed or bookmarked |
| Contact | Caller ID spoof; email from a free webmail account | Published phone/email on the charity’s own domain |
| Emotion | Graphic images + demand for immediate card CVV on the phone | Storytelling without demanding secrets on an inbound call |
IRS and benefits impersonators use similar scripts—see Fake IRS and benefits scams. Prepaid rails: Gift cards and prepaid debit risks.
Worked example: storm text + look-alike site
A text hits Maya’s phone: “FEMA partner—confirm $50 aid match for Hurricane survivors: bit.ly/…”. The landing page looks like a donation form, asks for card number and a one-time bank password “for verification,” and offers a discount if she pays with Apple Gift Card codes.
Maya stops. FEMA does not text random people to collect card data for “matches.” She closes the page, does not tap the link again, and instead opens a browser and types redcross.org or another known organization she already trusts. She can also check Charity Navigator, GuideStar/Candid, or her state attorney general’s charity search for registration—not a link inside the text.
If she had already entered a card number, she would call the number on the back of the card, monitor statements, and consider a credit freeze.
How to verify before you give
- Type the URL yourself or use a bookmark—do not trust shortened links in texts.
- Search the exact legal name plus “scam” and check state charity registration where available.
- Prefer established platforms you navigate to yourself (major charity sites, well-known processors)—still confirm the org is real.
- Never pay with gift cards or crypto because a stranger said it helps victims faster.
- Do not read MFA codes to anyone who contacted you first.
- For crowdfunding, verify the organizer through a separate channel (mutual friend, known nonprofit partner). Deep dive on cloned GoFundMe/crisis pages: Fake charity crowdfunding scams.
Report phishing texts to your carrier (many accept forward-to-7726) and file with ReportFraud.ftc.gov when appropriate.
Checklist
- Pause any donation ask that arrives as an unexpected call, DM, or text.
- Verify the organization on an independent registry or its official domain.
- Use a credit card you monitor (dispute rights) rather than wires or gift cards.
- Set a giving budget so urgency cannot override judgment.
- Keep confirmation emails; watch statements for duplicate or upsold charges.
- If data was exposed, change passwords, enable MFA, and freeze credit at Equifax, Experian, and TransUnion.
Educational only. Not legal advice. Charity registration rules vary by state; always verify before sending money.