Employees should treat that request as suspicious until verified through a separate channel. Gift card and charity scams often rely on emotional pressure, urgency, and a sense of goodwill to bypass normal judgment. The right response is to stop, verify the request with the purported sender using known contact information, and avoid sharing gift card numbers, PINs, or donation details from unsolicited messages.
How this scam works when the message feels urgent or personal
These requests usually work because they borrow the tone of a legitimate executive message and add a time pressure that discourages verification. The holiday setting makes the message feel routine and friendly, which lowers suspicion. In practice, the scam is less about technical compromise than about manipulating trust, politeness, and speed.
The attacker’s goal is to get the employee to act before checking whether the sender is real, whether the request matches normal business practice, or whether the supposed executive would ever ask for payment help in that format. The message may also try to create embarrassment or secrecy so the employee does not ask a colleague or supervisor.
Holiday-themed gift card requests and donation appeals are effective because they look plausible at a glance and often arrive when people expect irregular communication. The safer assumption is that any urgent request for gift cards, donation details, or payment codes must be verified before any action is taken.
What employees should do before responding
The immediate response is to stop and verify using a separate channel that is already known to be legitimate. That means contacting the purported sender through a trusted phone number, internal directory entry, or established messaging path, not by replying to the suspicious email or text.
If the request asks for gift card numbers, PINs, screenshots, or donation credentials, do not provide them. Those details are effectively value-bearing payment instructions, and once they are shared they can be used immediately. If anything in the message feels unusual, treat it as an exception that needs confirmation rather than as a normal holiday favor.
Employees should also watch for telltale signs such as unusual wording, slight changes in sender address, pressure to keep the request quiet, or a request that bypasses normal approval and purchasing processes. A legitimate executive can tolerate delay for verification; a scam usually cannot.
Why reporting matters even if nobody lost money
Even when an employee spots the scam in time, the message still matters because it can reveal a broader phishing or impersonation campaign. Early reporting helps security teams check whether the same lure was sent to others, whether the sender account or domain is being abused, and whether similar requests are reaching finance, HR, or executive assistants.
Fast reporting also reduces the chance that a second recipient will comply out of habit or urgency. In many organizations, these scams succeed only once a believable executive name is used. Stopping the first attempt quickly can prevent a wider wave of account or payment fraud.
If the message came through email, chat, or SMS, preserve the original message and report it through the organization’s normal security or phishing-reporting process. Do not forward it in a way that spreads the lure to more people unless your process specifically requires that.
Risk and Threat Considerations
These scams are designed to exploit authority, goodwill, and holiday distraction. The main risk is not just the immediate loss of money or gift cards, but the possibility that the same impersonation method will be reused against other employees or turned into a broader business email compromise attempt.
Failure mechanism: The attacker uses urgency and executive impersonation to bypass normal verification, then captures gift card codes, donation payments, or other value-bearing details before the target has time to confirm legitimacy.
Impact: Organizations can lose funds, expose employees to further fraud attempts, and create confidence gaps in executive communications, especially when the message appears to come from a trusted leader during a high-volume holiday period.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP API Security Top 10 and MITRE ATT&CK address the attack and risk surface, while CIS Controls v8, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-17 — Incident Response Management | Phishing and impersonation emails need a defined reporting path and response process. |
| Recommendation — Route suspicious gift-card requests into your phishing reporting and incident handling workflow. | ||
| NIST CSF 2.0 | RS.CO-01 — Personnel know their roles and order of operations when a response is needed | Employees need a clear reporting path when a request looks fraudulent. |
| Recommendation — Define how staff should report suspected impersonation and payment-fraud messages. | ||
| NIST SP 800-53 Rev 5 | AT-2 — Awareness Training | Holiday gift-card scams are social-engineering events that training should cover. |
| Recommendation — Train employees to verify urgent payment-style requests through a separate channel. | ||
| OWASP API Security Top 10 | API2 Broken Authentication — Broken Authentication | Impersonation scams succeed by abusing weak sender verification and trust assumptions. |
| Recommendation — Require independent verification before accepting an urgent executive request as authentic. | ||
| MITRE ATT&CK | T1566 — Phishing | These messages are a phishing-style social-engineering lure aimed at action and credentialless fraud. |
| Recommendation — Detect and block holiday-themed phishing lures that request gift cards or donations. | ||
Practitioner Guidance
What to verify: Verify the request through an out-of-band channel that you already trust, and compare the message against ordinary company practice. If the request is unusual, secretive, or bypasses approval steps, treat that as a stop condition rather than a reason to move faster.
Decision rule: If the message asks for gift cards, PINs, donation links, or payment details, do not act on the request until the sender is independently confirmed. If the request also pressures you to keep it quiet or act immediately, escalate it as a likely impersonation attempt.
Practitioner takeaway: The safest default is to slow the interaction down, verify the identity of the requester separately, and refuse any request that turns holiday goodwill into an urgent payment action.
Related resources from NHI Mgmt Group
- How should online merchants balance holiday conversion goals with fraud controls when gift cards, BOPIS, and promotions all become more attractive to shoppers?
- What are the signs that a social media message is part of a scam?
- What breaks when employees share PHI through unsecured tools?
- How should organisations decide whether to buy AI security tools through procurement channels?