Join our Newsletter — 33% off our NHI Course

What should people do differently when they suspect a charity, shipping, or shopping offer may be fraudulent?

They should verify the organisation independently before engaging. Check the web address, look up the company or charity through a trusted source, and avoid clicking links in the message itself. If the request pressures immediate action or asks for payment in gift cards, crypto, or wire transfers, treat it as high risk and stop there.

What Makes These Offers Dangerous Before You Click

Fraudulent charity, shipping, and shopping messages work because they borrow the appearance of normal commerce and public goodwill. The real risk is not just a fake payment page; it is the combination of urgency, emotional pressure, and a believable brand wrapper that pushes people past verification. For charities, the abuse often targets empathy. For shipping and shopping, it often targets convenience and fear of losing a parcel, order, or discount.

The most important change in behaviour is to slow the decision down and separate the offer from the message that delivered it. A legitimate organisation can be checked through a trusted search, a known app, or a bookmarked site. A message that insists you must act now, or that channels payment into gift cards, crypto, or wire transfer, is signalling that the safest response is to stop rather than continue negotiating.

People often recognise the fraud only after they have already followed the link, because the message is designed to feel like a routine transaction rather than a security event.

What To Do Instead Of Responding In The Message

The practical response is to treat the message as untrusted until you confirm the organisation through an independent path. That means typing the address yourself, using a saved contact method, or checking the charity or retailer through an established directory rather than the link or phone number supplied in the message. The message should be treated as a claim, not as evidence.

For shopping and shipping offers, confirm the transaction history in the retailer’s own app or website, and compare the sender details with the organisation’s normal domain and customer contact pattern. For charities, confirm registration, published contact details, and the donation route before giving money. Fraudsters frequently rely on a small amount of friction being enough to make people give up on checking, which is why the safer habit is to verify first and respond later.

  • Open the organisation through a trusted bookmark or search result, not through the message.
  • Compare the sender domain, payment method, and wording against the organisation’s normal practice.
  • Use a second channel, such as a known phone number or official app, if the offer involves money or account access.
  • Report the message if the content asks for urgent payment, gift cards, or secrecy.

For broader control thinking, the NIST SP 800-53 Rev 5 Security and Privacy Controls catalogue is useful because it shows how organisations reduce fraudulent communication exposure through access, awareness, monitoring, and response controls.

The guidance breaks down when the organisation cannot be independently found, when the sender spoofs a trusted domain closely enough to pass a quick glance, or when the person is asked to continue inside a lookalike login or payment flow that is already operating outside normal channels.

Where The Rule Changes For Charities, Shipping, And Shopping Scams

Tighter verification slows the transaction down, so people have to balance convenience against the possibility that the offer is engineered to create urgency. In practice, the details that matter differ slightly by scenario, and that is where many victims make the wrong assumption.

With charity appeals, the key question is whether the organisation is real and whether the donation route is legitimate, because emotional language can make a fake appeal feel morally compelling. With shipping messages, the issue is often whether a parcel notice is forcing a fee or login through a spoofed delivery page. With shopping offers, the weak point is usually the lure of a discount or refund that leads to credential theft or card misuse. In all three cases, the safest rule is to trust the channel you started from, not the channel the message wants you to use.

People sometimes assume that a branded logo, an order number, or a familiar charity name is enough to make the request safe, but those signals are exactly what fraudsters are good at copying.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
CIS Controls v8 14 — Security Awareness and Skills Training Fraudulent offers exploit user trust and urgency.
Recommendation — Train users to verify offers through trusted channels before they click or pay.
NIST CSF 2.0 PR.AT — Awareness and Training The question is about safer user behaviour against fraudulent messages.
DE.CM — Security Continuous Monitoring Users benefit when suspicious messages and lookalike domains are monitored.
RS.CO — Communications Reporting and escalation matter when a message appears fraudulent.
Recommendation — Teach people to recognise impersonation cues and verify requests independently. Monitor for spoofed domains and suspicious payment lures that mimic trusted organisations. Route suspicious offers to the right reporting channel so others are warned quickly.
MITRE ATT&CK T1566 — Phishing Fraudulent charity, shipping, and shopping offers commonly use phishing delivery.
Recommendation — Map suspicious offers to phishing patterns and escalate matching messages for investigation.

Practitioner Guidance

What to prioritise: Verify the organisation and the payment path before you assess the story in the message. If the request cannot survive an independent check, treat it as unsafe regardless of how polished it looks.

Decision rule: If the message pushes urgency, secrecy, gift cards, crypto, or wire transfer, do not “partially engage” to see what happens. Stop, verify through a separate channel, and only continue if the claim matches the known organisation record.

What practitioners underestimate: The failure is often not technical; it is a trust shortcut. The offer succeeds when people confuse a believable request with a verified one, especially on mobile where the sender, link, and landing page are seen too quickly to challenge.

Practitioner takeaway: The safest behaviour is not to judge the offer inside the message at all, but to re-anchor the decision in a trusted source that the attacker cannot control.