In 2024, a finance employee at Arup was persuaded to transfer approximately £20 million (US$25.6 million) to fraudulent accounts after a deepfake video call. A deepfake is synthetic video or audio created by AI to impersonate a specific person. That attack targeted a multinational. The same methods now target charities.
Prevent Charity Fraud has warned that deepfake impersonation of senior charity leaders for mandate fraud is already happening in the charity sector. Mandate fraud is when a criminal impersonates a trusted person to redirect payments or transfers. Charity CEOs, chairs, and high-profile campaigners are impersonation targets because their faces and voices are publicly available.
The National Cyber Security Centre (NCSC) found that AI gives criminals a significant uplift in social engineering and will make attacks more frequent and harder to detect (NCSC, 'Impact of AI on Cyber Threat from Now to 2027', 7 May 2025). Nationally significant cyber incidents rose from 89 to 204 year on year, with highly significant incidents up 50% (NCSC Annual Review 2025).
The NCSC says charities are attractive targets for financial gain and access to sensitive information. Your charity holds donor data, safeguarding records, and grant payment systems. The Association of Charitable Foundations reports rising grant application volumes linked to AI tools and falling success rates, as criminals use AI to generate convincing but fraudulent applications. AI also enables fabricated beneficiary stories in fundraising content and social engineering at scale exploiting the trustworthiness of charitable brands.
Standard annual cyber awareness training was written before these attack types existed. It teaches staff to spot spelling and grammar errors. AI-enhanced phishing (AI-written emails that are grammatically perfect and personalised at scale) removes those errors entirely. Phishing was the attack vector in 84% of UK businesses that detected a breach (DSIT Cyber Security Breaches Survey 2024).