Guide · Nonprofits

Email security for
nonprofits on a budget.

Nonprofits handle money, hold sensitive data, and run on lean teams and trusting volunteers — a combination attackers know well. The good news is that the highest-impact protections are free or nearly so. Here is what matters most, in plain language, for organizations that don't have an IT department.

In brief

Nonprofits are targeted because they move money, hold donor and beneficiary data, and run lean — but the most protective steps cost little. Turn on multi-factor authentication for every account, adopt a written rule that any payment or bank-detail change is verified by phone, keep donor data out of ordinary email, and train staff and volunteers on donation and grant-fraud scams. Google Workspace and Microsoft 365 both offer nonprofit programs, so strong tools are within reach even on a tight budget.

Published 8 August 2026 · updated 11 August 2026 by Family Sentinel.

An 8-minute read for executive directors, operations staff, and boards.

+35%Year-over-year rise in email threats against nonprofits (Abnormal Security, 2025).
+50%Rise in credential-phishing against the sector over the same period.
Free / low-costThe steps that matter most are included in nonprofit tech programs.

Why nonprofits are targeted

Attackers follow value, and nonprofits hold more of it than they realize: donation and grant flows to redirect, donor and beneficiary records to steal, and payroll to divert. What they typically lack is a dedicated security team, so defenses rest on a few busy people and a rotating set of volunteers. That gap between what's at stake and what's protecting it is precisely the opening. None of this requires a big budget to close — it requires the right few habits.

The free and low-cost essentials

  • Multi-factor authentication on every account. Free with Google Workspace and Microsoft 365, and the single biggest barrier to account takeover. Make it mandatory, including for volunteers and board members with access.
  • A written payment-verification rule. Any new or changed bank detail — for a vendor, a grant, or payroll — is confirmed by phone using a number you already had. This one rule stops most donation- and invoice-fraud losses, and it costs nothing.
  • Use your provider's nonprofit program. Google for Nonprofits and Microsoft's nonprofit offers include security features at no or low cost. Take the upgrade and turn the protections on.
  • Least-privilege access. Give each person — especially volunteers — only the access their role needs, and remove access promptly when someone leaves or a term ends.
  • Publish SPF, DKIM, and DMARC on your domain so criminals can't easily impersonate your organization to your own donors.

Protecting donor and beneficiary data

  • Keep sensitive data out of ordinary email. Don't send full payment details, Social Security numbers, or large donor lists as attachments; use your CRM or a secure portal.
  • Limit who can see donor records, and log or review access where you can.
  • Separate the donor CRM and finance systems from general staff email. A phished email account should not automatically open your donor database or accounting — keep those behind their own logins and MFA, granted only to the people who need them.
  • Have a plan for a data incident. A breach of donor information can carry legal obligations and real reputational damage; knowing in advance who to call shortens the harm.

The scams that hit nonprofits hardest

  • Donation-page and invoice fraud — redirected payment details, or fake invoices for services the organization uses.
  • Grant scams — fake grant “awards” that ask for a fee or bank details up front, or impersonation of a real funder to redirect a legitimate payment. Confirm any award or payment change directly with the funder.
  • Grant-application phishing — a fake “grant provider” requesting your EIN, banking details, or documents to “unlock” funding. A real funder does not need your bank login to send money.
  • Board-member and executive impersonation — a “director” or board chair emailing a request for gift cards or an urgent transfer, often timed around a board meeting or travel. See our impersonation and invoice-fraud guide.
  • The fake-donor overpayment — a “major donor” overpays by check and asks for the difference refunded, or promises a big gift contingent on a processing fee. The check bounces after you've sent real money. Never refund against an uncleared deposit.
  • Volunteer-account phishing — a compromised volunteer login used as a way into the organization. Volunteers need MFA and a moment of training too.

Train the people, simply

You don't need a formal program. A short, plain briefing — here are the scams aimed at us, here is our one payment rule, here is who to ask if something feels off, and no one will ever be blamed for double-checking — does most of the work. Repeat it when volunteers turn over.

Sources & further reading: CISA resources for under-resourced organizations · TechSoup and Microsoft/Google nonprofit programs · NTEN cybersecurity resources · U.S. FTC business guidance (ftc.gov). Sector threat figures per Abnormal Security research (2025). Educational only; not a substitute for advice tailored to your organization.

Common questions

Why are nonprofits targeted by email scams?

Nonprofits combine three things attackers love: they move money (donations and grants), they hold sensitive donor and beneficiary data, and they usually have small teams, tight budgets, and many volunteers with account access. That mix means real value behind often-thin defenses, which is exactly what makes them a target.

What is the most affordable way for a nonprofit to improve email security?

Turn on multi-factor authentication for every account — it is free with Google Workspace and Microsoft 365 and stops the large majority of account takeovers. Then adopt a simple written rule that any change to bank or payment details is verified by phone. Those two steps cost nothing and remove most of the risk. Many providers also offer nonprofit discounts or free tiers.

How do we protect donor data in email?

Avoid sending full payment details, Social Security numbers, or large donor lists over email at all; use a secure portal or your CRM instead. Where you must, limit who has access, turn on MFA, and be alert to phishing that tries to harvest that data. A breach of donor information can carry both legal obligations and lasting reputational cost, so treat it as sensitive by default.

What is grant fraud and how does it target nonprofits?

Grant fraud includes fake grant offers that ask for a processing fee or bank details up front, and impersonation of a real funder to redirect a legitimate grant payment. Treat any unsolicited grant award, or any change to how an expected grant will be paid, as suspect until you confirm it directly with the funder through a contact you already had.

What is the fake-donor overpayment scam?

A scammer poses as a generous donor and either promises a large gift that requires an upfront “processing fee”, or sends a check for more than intended and asks the nonprofit to refund the difference. The original check later bounces, leaving the organization out the refunded amount. Never refund or forward money against a deposit that has not fully cleared, and verify any large or unusual gift offer before acting.

Should we get Microsoft 365 or Google Workspace through a nonprofit program?

Yes — it is one of the best security values available to a nonprofit. Qualifying 501(c)(3)s can get Google for Nonprofits, or Microsoft 365 Business Basic free for up to 300 users and Business Premium at a steep discount through TechSoup. Business Premium in particular includes advanced phishing protection (Defender for Office 365) and Conditional Access, so budget is rarely a real reason to run without strong email security.

Coverage that fits a nonprofit budget

Family Sentinel's Org Guard watches your organization's email for the scams that target nonprofits — donation and grant fraud, impersonation, account takeover — and alerts a person you choose before the money moves. Read-only, and never able to send or delete.

Book a free posture review More guides