UK charities are among the most targeted organisations for cyber attack. The NCSC's Cyber Security Breaches Survey consistently shows that charities experience breaches and attacks at rates comparable to medium-sized commercial businesses, but with substantially fewer resources to respond. A 2023 survey found that 24% of charities reported a cyber breach or attack in the previous 12 months — and that's only the ones that knew about it.
The reasons are structural. Charities often rely on volunteer IT support, legacy systems that haven't been updated, free or low-cost software tools with varying security postures, and a culture where security spending feels like a diversion from mission. Meanwhile, they hold exactly the kind of data attackers want: donor payment details, beneficiary personal data, grant records with financial information, and sometimes sensitive data about vulnerable individuals that has specific value for exploitation.
What Attackers Are After in the Charity Sector
Donor Payment Data
Regular giving schemes — monthly direct debits, standing orders, recurring card payments — mean charities hold or have access to significant volumes of payment data. The data itself may sit with the payment processor (Stripe, GoCardless, JustGiving), but the charity's CRM typically holds donor names, contact details, giving history, and sometimes card last-four or Direct Debit reference numbers. That combination is useful for social engineering and fraud.
Large donors, who may be identifiable from public recognition on your website, are targets for spear phishing. An attacker who knows someone donated £10,000 to your charity can craft a convincing email appearing to be from you, requesting an additional gift via a fraudulent link or bank transfer.
Beneficiary Data
If your charity works with individuals — homeless people, domestic abuse survivors, people with mental health conditions, asylum seekers, children in care — your database contains sensitive personal data about vulnerable people. This data has specific exploitation value: it can be used for targeting, blackmail, or sale to parties with harmful intent. Its exposure also causes direct harm to people who trusted your organisation with information shared in a context of need.
Under UK GDPR, much beneficiary data is Article 9 special category data (health conditions, racial or ethnic origin, data about criminal convictions). Processing this requires explicit consent or another Article 9 condition, a legitimate interest assessment or DPA, and heightened technical security. A breach affecting this data must be reported to the ICO within 72 hours.
Grant and Financial Records
Many charities hold detailed financial information: grant applications with budget breakdowns, funder reports, salary information for staff, contracts with suppliers. This information is valuable for fraud — particularly invoice fraud, where attackers intercept payment processes and redirect funds. Charity finance teams are known targets for business email compromise.
The Charity Commission requires charities with income over £25,000 to submit annual returns, and those over £500,000 to have their accounts independently examined or audited. Financial records are therefore both an internal resource and a regulatory obligation. Their compromise creates both fraud risk and compliance exposure.
How Charity Websites Are Typically Compromised
Donation Form Skimming
Online donation forms that process card payments directly (rather than redirecting to a fully hosted payment page) are targets for Magecart-style skimming attacks. An attacker injects malicious JavaScript — often via a compromised third-party script loaded by your page — that silently copies card details as donors enter them and sends them to an attacker-controlled server. The donor sees a normal transaction. The charity has no idea anything happened. The card details are sold or used within hours.
If your donation form loads any third-party JavaScript (analytics, tag managers, social share buttons, CRM widgets), that code executes with the same permissions as your own code. A single compromised CDN or third-party provider can expose your donors.
Volunteer and Staff Portal Attacks
Many charities offer a web portal for volunteers to log hours, access training materials, or manage their roles. These portals often have weaker authentication requirements than commercial systems — no MFA, no password complexity requirements, no session expiry. Compromising a volunteer account may seem low-value, but it provides authenticated access to systems that may also contain beneficiary data, financial information, or internal communications.
Outdated CMS and Plugin Vulnerabilities
Charity websites are disproportionately likely to run on WordPress with multiple plugins, some of which may not have been updated in years. Volunteer or part-time IT support may not have a robust patching process. Known CVEs in popular plugins — sometimes with working exploit code publicly available — go unpatched for months. Automated scanners find these within hours of disclosure.
The Charity Commission and ICO Angle
The Charity Commission expects charities to protect their assets, which includes data. Its serious incident reporting guidance lists data breaches as reportable serious incidents. A breach that results in ICO enforcement action may also trigger a Charity Commission inquiry — a double regulatory burden.
The ICO has issued fines to charities for data protection failures. The RNLI received an enforcement notice (later resolved) relating to fundraising communications. While the sector receives some regulatory latitude given resource constraints, that latitude does not extend to preventable technical failures. A charity that processes donor and beneficiary data and has never security-tested its website is in a weak position if a breach investigation asks what due diligence was in place.
The NCSC offers free resources specifically for charities: the Cyber Essentials scheme costs £300 for self-assessment at the basic level, and the NCSC's free Exercise in a Box tool helps charity teams practice their response to cyber incidents. These are complementary to, not a substitute for, technical security testing of your website.
What a Web Security Assessment Covers for a Charity
A security scan of a charity website assesses:
Authentication on any member, volunteer, or staff portals — password policy, MFA availability, session management, lockout after failed attempts.
Donation form security — whether the page loads third-party JavaScript that could be compromised, whether card data is handled by a fully hosted payment provider or processed locally, whether the form is protected against CSRF.
CMS and plugin vulnerabilities — whether WordPress core, plugins, and themes are current, and whether any known CVEs are present in installed components.
Email security — DMARC, SPF, and DKIM configuration, to prevent your domain being spoofed in fundraising fraud campaigns.
API and integration security — whether any CRM, email marketing, or payment integrations expose credentials in client-side code.
Security headers — Content-Security-Policy, X-Frame-Options, HSTS, and others that add defensive layers against common attack types.
For a charity, the case for security testing is both ethical — protecting the vulnerable people whose data you hold — and practical. Yrzo AI delivers a 44-point automated assessment with a plain-English report the same business day. From £399 at yrzoai.dev.
Find out if your website has these vulnerabilities
Yrzo AI runs 44 automated security checks and delivers a full report in under 20 minutes. Starting from £399.
Scan your website →