Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› What should employees do when a holiday message…
Threats, Abuse & Incident Response

What should employees do when a holiday message asks them to buy gift cards or donate through an urgent executive request?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 25, 2026 Domain: Threats, Abuse & Incident Response

Employees should treat that request as suspicious until verified through a separate channel. Gift card and charity scams often rely on emotional pressure, urgency, and a sense of goodwill to bypass normal judgment. The right response is to stop, verify the request with the purported sender using known contact information, and avoid sharing gift card numbers, PINs, or donation details from unsolicited messages.

How this scam works when the message feels urgent or personal

These requests usually work because they borrow the tone of a legitimate executive message and add a time pressure that discourages verification. The holiday setting makes the message feel routine and friendly, which lowers suspicion. In practice, the scam is less about technical compromise than about manipulating trust, politeness, and speed.

The attacker’s goal is to get the employee to act before checking whether the sender is real, whether the request matches normal business practice, or whether the supposed executive would ever ask for payment help in that format. The message may also try to create embarrassment or secrecy so the employee does not ask a colleague or supervisor.

Holiday-themed gift card requests and donation appeals are effective because they look plausible at a glance and often arrive when people expect irregular communication. The safer assumption is that any urgent request for gift cards, donation details, or payment codes must be verified before any action is taken.

What employees should do before responding

The immediate response is to stop and verify using a separate channel that is already known to be legitimate. That means contacting the purported sender through a trusted phone number, internal directory entry, or established messaging path, not by replying to the suspicious email or text.

If the request asks for gift card numbers, PINs, screenshots, or donation credentials, do not provide them. Those details are effectively value-bearing payment instructions, and once they are shared they can be used immediately. If anything in the message feels unusual, treat it as an exception that needs confirmation rather than as a normal holiday favor.

Employees should also watch for telltale signs such as unusual wording, slight changes in sender address, pressure to keep the request quiet, or a request that bypasses normal approval and purchasing processes. A legitimate executive can tolerate delay for verification; a scam usually cannot.

Why reporting matters even if nobody lost money

Even when an employee spots the scam in time, the message still matters because it can reveal a broader phishing or impersonation campaign. Early reporting helps security teams check whether the same lure was sent to others, whether the sender account or domain is being abused, and whether similar requests are reaching finance, HR, or executive assistants.

Fast reporting also reduces the chance that a second recipient will comply out of habit or urgency. In many organizations, these scams succeed only once a believable executive name is used. Stopping the first attempt quickly can prevent a wider wave of account or payment fraud.

If the message came through email, chat, or SMS, preserve the original message and report it through the organization’s normal security or phishing-reporting process. Do not forward it in a way that spreads the lure to more people unless your process specifically requires that.

Risk and Threat Considerations

These scams are designed to exploit authority, goodwill, and holiday distraction. The main risk is not just the immediate loss of money or gift cards, but the possibility that the same impersonation method will be reused against other employees or turned into a broader business email compromise attempt.

Failure mechanism: The attacker uses urgency and executive impersonation to bypass normal verification, then captures gift card codes, donation payments, or other value-bearing details before the target has time to confirm legitimacy.

Impact: Organizations can lose funds, expose employees to further fraud attempts, and create confidence gaps in executive communications, especially when the message appears to come from a trusted leader during a high-volume holiday period.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP API Security Top 10 and MITRE ATT&CK address the attack and risk surface, while CIS Controls v8, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-17 — Incident Response ManagementPhishing and impersonation emails need a defined reporting path and response process.
Recommendation — Route suspicious gift-card requests into your phishing reporting and incident handling workflow.
NIST CSF 2.0RS.CO-01 — Personnel know their roles and order of operations when a response is neededEmployees need a clear reporting path when a request looks fraudulent.
Recommendation — Define how staff should report suspected impersonation and payment-fraud messages.
NIST SP 800-53 Rev 5AT-2 — Awareness TrainingHoliday gift-card scams are social-engineering events that training should cover.
Recommendation — Train employees to verify urgent payment-style requests through a separate channel.
OWASP API Security Top 10API2 Broken Authentication — Broken AuthenticationImpersonation scams succeed by abusing weak sender verification and trust assumptions.
Recommendation — Require independent verification before accepting an urgent executive request as authentic.
MITRE ATT&CKT1566 — PhishingThese messages are a phishing-style social-engineering lure aimed at action and credentialless fraud.
Recommendation — Detect and block holiday-themed phishing lures that request gift cards or donations.

Practitioner Guidance

What to verify: Verify the request through an out-of-band channel that you already trust, and compare the message against ordinary company practice. If the request is unusual, secretive, or bypasses approval steps, treat that as a stop condition rather than a reason to move faster.

Decision rule: If the message asks for gift cards, PINs, donation links, or payment details, do not act on the request until the sender is independently confirmed. If the request also pressures you to keep it quiet or act immediately, escalate it as a likely impersonation attempt.

Practitioner takeaway: The safest default is to slow the interaction down, verify the identity of the requester separately, and refuse any request that turns holiday goodwill into an urgent payment action.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 25, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org