UK charities are a genuinely attractive target for cybercriminals, and the data makes that uncomfortable reading. Around 30% of charities experienced a cyber breach or attack in the 2025/26 reporting period — approximately 61,000 organisations. Phishing accounts for 95% of attacks. And only around 19% of charities have a formal incident response plan in place.

The sector is disproportionately exposed because charities sit at an awkward intersection: they hold sensitive personal data about donors, beneficiaries, and volunteers; they often rely on legacy systems; they operate with stretched staff and tight budgets; and they have a rotating door of volunteers and trustees whose access to systems frequently isn’t managed as carefully as it would be in a commercial organisation.

If you’re responsible for a charity’s operations, here’s what you’re actually up against and what you can do about it.

What Attackers Are After

Donor data is the obvious target. Full names, postal addresses, email addresses, phone numbers, and in many cases payment card details or bank account information for direct debits — all held in fundraising databases or CRMs that may not have seen a security review since they were set up. Donor databases have genuine value to fraudsters for phishing, identity fraud, and credential stuffing.

Grant application data is less obvious but significant. Applications often contain sensitive information about beneficiaries, financial statements, and sometimes safeguarding information about vulnerable people the charity works with. This data is sensitive under UK GDPR and attracts serious ICO attention if it’s breached carelessly.

Email account compromise is the entry point for most successful attacks. A phished trustee or finance officer with access to the charity’s bank account is the pattern behind mandate fraud and CEO fraud incidents that hit charities regularly. The NCSC’s charity threat report notes that the relative informality of many charity communications makes pretexting easier — attackers can impersonate a trustee or executive director convincingly.

The Volunteer Access Problem

This is the charity-specific vulnerability that business-focused security advice tends to underestimate. Charities routinely have dozens or hundreds of volunteers with varying levels of system access, often joined and leaving on an informal basis, with no formal offboarding process.

The result: former volunteers retain access to shared mailboxes, Google Drives, CRM systems, and social media accounts long after they’ve moved on. In the worst cases, a disgruntled former volunteer has access to donor lists or the charity’s social media accounts with no easy way to revoke it quickly.

Fixing this isn’t complicated, but it requires making access management a routine process rather than something that happens ad hoc. When a volunteer finishes their stint, go through a simple offboarding checklist: remove their access to shared inboxes, remove them from distribution lists, revoke CRM access, remove social media account access. Run an access audit quarterly to catch anyone who slipped through.

NCSC Free Tools Worth Using

The NCSC provides free cyber security services specifically for charities and small organisations, and they’re genuinely useful.

Mail Check analyses your email domain configuration — SPF, DKIM, and DMARC settings — and tells you whether criminals can send convincing phishing emails pretending to be your organisation. Most charities should have DMARC in place and many don’t.

Web Check scans your website for common vulnerabilities and misconfigurations. If your charity website is running an outdated WordPress installation with unpatched plugins, Web Check will surface this.

Protective DNS provides a free DNS filtering service that blocks malicious domains at the network level, reducing the risk of staff or volunteers clicking malicious links.

Suspicious Email Reporting Service (SERS) at report@phishing.gov.uk — worth briefing all staff and volunteers on so they know what to do when they’re unsure about an email.

The NCSC also publishes a Small Charity Guide, updated regularly, which covers the basics in plain language and is worth sharing with trustees who aren’t technically confident.

GDPR and the ICO

Donor data falls fully within UK GDPR scope. Charities are data controllers, the same as any other organisation, and the ICO doesn’t give charities a pass on data protection obligations. If you experience a breach that affects personal data — donors’ names and emails leaked, a laptop with beneficiary information lost — you have 72 hours to notify the ICO if the breach is likely to result in risk to individuals.

The ICO does take a more lenient enforcement view when an organisation had demonstrable security controls in place and responded promptly. Document what you do: multi-factor authentication on email, DMARC, access reviews, staff training. That documentation matters.

Practical Steps for Charity Teams

Multi-factor authentication on your email accounts is the single most impactful control. If you’re on Microsoft 365 or Google Workspace, MFA is free to enable and dramatically reduces the risk of account compromise. Enable it for every user with access to anything sensitive, including trustees who may only log in occasionally.

DMARC on your charity’s email domain prevents criminals from sending phishing emails that appear to come from your organisation to your donors. If you’re not sure whether you have DMARC, ask your IT support or use the NCSC Mail Check tool.

Cyber Essentials certification is increasingly asked for by funders. Some grant-making bodies now require or strongly prefer charities with Cyber Essentials certification as evidence of basic security hygiene. It’s not expensive for smaller organisations and the process of getting it forces a useful baseline review.

If a cyber attack does succeed, report to Action Fraud (0300 123 2040 or actionfraud.police.uk) and check your trustee liability insurance and any cyber cover you hold. Many charities discover they have less cover than they assumed — check before you need it.

The threat is real and the sector is under-prepared. The good news is that the most effective controls — MFA, DMARC, access reviews — cost very little to implement. Start there.