TD is educating nonprofit executives to protect their organizations, donors and clients from significant losses to fraudsters.
Key Points
- Learn about common fraud types and evolving scams to understand how they work.
- Confirm information is coming from a reputable source before acting. Urgent or threatening language is a red flag.
- Always be cautious about clicking on unsolicited links, scanning QR codes in public places, and sharing personal or financial information.
- Be skeptical of offers that promise easy money or require you to send funds to “make more.”
The nonprofit sector has faced mounting financial challenges in recent years, and another costly threat quickly rising: the loss of funds to fraudsters.
The average amount lost by nonprofits to fraud is $69,000, according to the 2026 Association of Certified Fraud Examiners' Occupational Fraud Report to the Nations. While business fraud averages $1.5 million per incident, the theft of dollars earmarked to help communities in need can be especially egregious.
That's just the direct financial cost. Nonprofits build credibility on trust, and the reputational damage following a fraud event could be even more devastating. In response, the TD Security Awareness for Everyone (TD SAFE) and TD financial education teams recently introduced a fraud prevention seminar for nonprofit leaders at events in Westchester County, New York, and Charleston, South Carolina.
"We all need to watch out for the dreaded "-ings," said Christopher Blackmore, Senior Manager of Fraud Operations, TD Bank U.S. "Spoofing, phishing, vishing, smishing and now quishing — the fraud type is always evolving."
Watch this video to see how TD SAFE is helping protect nonprofits.
How to prevent criminals from profiting off nonprofits
"It's a business now to scam," Christopher said to the dozens of nonprofit leaders gathered in Charleston. He asked how many in the room had been a victim of fraud or know someone who has — nearly everyone raised their hand.
How to prevent fraud incidents was less clear to TD SAFE attendees, as nonprofit organizations typically have small staff sizes and supporting cybersecurity can be out of reach with limited resources.
Adrienne Terpak, Senior Commercial Segment Manager in Transaction Banking Product, TD Bank U.S., said some low- or no-cost resources are available. For instance, nonprofits may be able to use AI-driven cyber defense tools, and a few companies offer free cybersecurity audits or services to nonprofit organizations.
But true security begins within the organization, she noted. Like all other companies, insiders at nonprofits — the staff, leaders, board members or others who have access to confidential information — are a fraud risk.
"Regardless of your title, we're all risk managers," Adrienne said. "It can seem daunting, but it's about taking a measured approach to tackling gaps."
With a small employee base, sharing resources, software or login credentials can seem efficient or practical. However, doing so creates significant security vulnerabilities and increases the risk of fraud and unauthorized access. One easy step: Ensure only those who need access to banking and payment system have it, limited to the functions they require, and create separate logins and unique passwords for each person.
Sometimes fraudulent activity is more direct.
"We've had fraudsters impersonate our CEO and send emails to staff," said Cheryl Reid, Chief Financial Officer, Center for Heirs Property in North Charleston, SC. "In the nonprofit space, we have to be more diligent and think of ourselves as a business. We can be so open-armed [where we welcome everyone] that we have our guard down [and create risks]."
Protecting clients and donors: the other potential fraud victims
Along with direct fraud attempts on organizations, their donors and clients can be vulnerable.
Criminals may create spoofed websites that may look legitimate, including logos and a picture of the director. Nonprofit leaders should periodically conduct web and social media searches on their organization to make sure an impersonation site doesn't exist. If it does, reporting the site or fake social media profile to the platform (such as Google) can help get it taken down.
Nonprofits should proactively share secure, direct donation links with their regular donors, so they always have a trusted way to make contributions and are less vulnerable to fraudulent requests, TD presenters noted. As with any business, donors and clients should also contact the organization directly to verify if they receive any communication that says donation and payment instructions have changed.
Tom Gabriel, President and CEO of United Way Westchester and Putnam, which recently held a Nonprofit Leadership Summit presented by TD, agreed that tackling these challenges don't always have to be difficult to overcome.
"The TD SAFE curriculum provided real-world solutions for nonprofit staff to implement to ensure that their organizations remain efficient and safe,” he said.
A stronger defense for stronger communities
"Discussing fraud and scams is the right thing to do, and it’s imperative that all organizations build greater awareness, increase vigilance and collaborate to foster a mindset centered on action, resilience and capability," Chris said. "Our nonprofits are just as vulnerable as any business to fraud and understanding these vulnerabilities is key."
For nonprofits, fraud prevention is more than a financial safeguard — it's protection for the trust, resources and relationships that make their missions possible. By taking practical steps and layering defenses of people, procedures and technology to strengthen awareness, limit access and verify suspicious activity, organizations can reduce risk and keep focus where it belongs: serving their communities.