HumanVerified is in beta — free while we build it.Help us make it better →
EntrepreneursNonprofits & FundraisingSep 11, 20264 min read

Executive Impersonation Fraud Finds Nonprofits Right as They Start to Scale

Scammers copy a real executive director's name and public role to reach nonprofit staff. Growth doesn't shrink that risk — it adds more people who might act on the ask.

Listen to this article
Audio narration
Narrated in a natural voice

A nonprofit's executive director is, by design, one of the most public people in the organization. The Form 990 lists her name and compensation. The annual report puts her photo next to the mission statement. Local press quotes her when the shelter opens a new wing. None of that is a mistake — donors are supposed to know who's running the place. It's also a ready-made identity kit for a stranger, which is exactly why executive impersonation fraud keeps finding its way into nonprofit inboxes, and why it lands hardest on organizations that have just grown large enough to have someone besides the founder handling money.

Why executive impersonation fraud finds nonprofits early

For-profit executives can at least try to keep a low profile. Nonprofit leadership can't, because transparency is the job. A 990 is a public filing by law. Staff directories and board rosters sit on the website so grantors and donors can vet the organization before they give. A founder-led nonprofit that grows into a real staff — a bookkeeper, a development director, a program lead — hands a fraudster more names to copy and more people who might act quickly on a message that looks like it came from the boss.

The ask usually looks small, on purpose

The Nonprofits Insurance Alliance, which insures thousands of nonprofits, has documented the pattern directly from claims it has handled. In one case, someone impersonating an executive director asked a staff member to buy a few hundred dollars in gift cards and send photos of the redemption codes. In another, someone impersonating the nonprofit's own employee talked the organization into switching a payment method to wire transfer — money that couldn't be recalled once it left. A third case involved a fraudster posing as a payroll company and convincing a nonprofit to move payroll from paper checks to ACH, a switch that cost the organization close to $9,500 before anyone caught it. None of these required breaking into a system. They required one person believing a message came from someone it didn't.

The bigger number behind the small asks

These small asks add up to a large total. The FBI's Internet Crime Complaint Center put exposed losses from business email compromise at $55.5 billion globally between October 2013 and December 2023, with losses climbing another 9 percent in the final year alone. The bureau describes the scam plainly: it targets "legitimate transfer-of-funds requests," which is exactly what a wire change, an ACH switch, or a reimbursement request looks like from the inside. Nonprofits aren't a footnote to that number. They run the same email and the same invoices as any small organization, often with a thinner back office — one or two people who can approve a payment, instead of a finance department that can slow a request down.

Growth is when the risk widens, not shrinks

A one-person operation has a check built in by accident: the founder signs everything, so there's no one else to fool. The moment a nonprofit adds a bookkeeper, a grants manager, or a second signer on the bank account, that check disappears. Now there are several people who might plausibly receive an urgent, confidential-sounding message from the executive director, and several people who don't have the standing to tell their boss to slow down and call her directly before acting. Growth is the goal. It also means more inboxes carrying her name, with no one responsible for saying which messages actually came from her.

What a public record proves, and what it can't

A 990 confirms the organization exists and files honestly. A staff directory confirms the executive director's name and title are real. Neither one tells a bookkeeper, three years into the job, whether the email in front of her asking to change a vendor's bank details actually came from that person today. The fraud was never about whether the director is real — she obviously is, that's the whole reason the name works. The fraud is in the message, and the same public records that establish her identity are what a scammer copies to fake it.

What a verified identity changes

A Human ID gives each person at a nonprofit — starting with whoever can approve a payment — a permanent identifier attached to the communications they personally reviewed and authorized. A staff member who gets an unusual ask can check the ID or a specific verification code directly, the way how it works describes, instead of guessing whether calling the director is even the right move for something marked confidential. For an organization onboarding a new signer or offboarding one who's leaving, issuing or revoking an ID is a step that happens that day, not a note someone has to remember later. For Organizations covers how a nonprofit sets this up across a growing staff.

This doesn't replace a callback policy for anything involving money, and it shouldn't. Verification confirms that a message was personally reviewed and authorized by the person shown; it doesn't confirm a wire instruction, a vendor's bank account, or the accuracy of what's written. It also doesn't claim the message was written without help from AI or software, because that isn't a claim anyone can honestly make. AI can help draft the message. Verification tells the recipient who's willing to put a name behind it. The Trust page lays out those limits in full. For a nonprofit that's just added its first real back office, the practical starting point is narrow: issue IDs to the executive director and anyone with signing authority first, then expand from there.

Verify your team's communications

Give every person on your team a verifiable identity your clients can check in seconds. Free during beta.

Request organization access

More Commentary