Most fraud detection content focuses on consumer fraud — stolen credit cards, identity theft, account takeovers. Those are real problems, but there's a quieter category of financial crime that gets far less attention: nonprofit fraud in the corporate social responsibility space. I've spent years investigating it, and it's genuinely fascinating — partly because it's technically complex, and partly because the organizations perpetrating it are often hiding behind the language of doing good.

This article is a practical rundown of the tactics I see most often. If you work in fraud, compliance, or AML and your organization handles charitable giving — through a CSR platform, a donor-advised fund, or a corporate matching program — this is the landscape you're operating in.

The most effective nonprofit fraudsters don't look like fraudsters. They look like charities.

Why NPO fraud is different

Consumer fraud usually involves someone trying to take money that isn't theirs. NPO fraud in the CSR space involves someone who has already received money — legitimately, in many cases — and is either misrepresenting how it's used, inflating their activity to extract more, or running a shell organization designed to funnel funds back to the people who donated them in the first place.

The detection challenge is compounded by two things. First, nonprofits are trusted by default. When a 501(c)(3) appears on a platform, donors and corporate clients assume someone has already done the vetting. Often, that assumption is wrong. Second, the fraud frequently involves insiders — employees or their family members — which makes pattern detection harder. The signals are there, but they're subtle.

The tactics, one by one

01 — Match harvesting

Most common · High volume · Often coordinated
Gaming the employer match to extract double the value

Match harvesting is the most prevalent tactic I encounter. The mechanics are simple: a donor gives to a nonprofit they control, or in which they have a personal interest. Their employer matches the donation. The nonprofit then returns some or all of the funds to the donor, effectively turning a $50 donation into a $100 personal gain with the employer covering the difference.

In practice it's often more coordinated than that. I've seen cases where a small group of employees — sometimes colleagues, sometimes family members — rotate donations across a handful of complicit nonprofits, generating match payouts repeatedly over months before the pattern becomes visible in transaction data.

In more sophisticated schemes, diaspora groups sit on NPO boards and rotate leadership frequently — particularly when they suspect they've been identified. Rather than stopping, they'll simply create a new NPO or transfer control to an existing one and continue the same practices under a different name. The fraud doesn't end; it migrates. This is why the ability to review cluster entities for overlapping leadership and governance structures is so valuable — the individual NPO may look clean, but the network it belongs to tells a different story.

Signals to look for Donations clustering tightly at or just above the minimum match threshold. A high ratio of match value to base donations (4× or higher is a red flag). Multiple donors sharing an email domain donating to the same small NPO. Zero recurring donors — everyone gives once, near the match cap, and never again. When reviewing flagged NPOs, look for overlapping board members and governance structures across cluster entities — fraudulent networks often resurface under new names when they believe they've been caught, and shared leadership is the thread that connects them.

02 — Impossible volunteer hours

Underreported · Hard to disprove · Often combined with match harvesting
Claiming volunteer hours that simply couldn't have happened

Many corporate CSR programs offer a dollar-per-hour incentive for verified volunteer time. The verification is usually self-reporting — employees submit their hours, and the company makes a corresponding donation. The problem is that there is rarely any mechanism to verify whether those hours actually happened.

I've reviewed volunteer hour submissions where individuals are logging several hundred hours within a single month — while employed full-time. It's a simple test: you cannot volunteer more hours than you are employed. When the math doesn't work, the submission is fraudulent by definition, and yet these claims routinely pass through platforms without any automated check against that basic threshold.

A subtler but equally telling red flag: an NPO that receives a disproportionate volume of corporate-matched volunteer hours while showing zero donations. Genuine charitable engagement doesn't look like that. When people care enough about an organization to give hundreds of hours of their time, some of them donate too. An NPO with high matched-hour volume and no donation activity isn't organic — it's a signal that the hours are being manufactured specifically to extract the corporate match.

Signals to look for Individual hour submissions that exceed what's physically possible alongside full-time employment — particularly claims of several hundred hours within a single month. NPOs receiving high volumes of corporate-matched volunteer hours with zero corresponding donations. Hours claims that spike around match program deadlines and drop to zero outside them.

03 — Shell NPOs

Highest risk · Often linked to repeat offenders · Network effects
Legitimate-looking organizations with nothing behind them

A shell NPO has a valid EIN, a website, a mission statement, and sometimes even a brief operating history — enough to pass a surface-level review. What it doesn't have is any meaningful charitable activity. Funds flow in through a CSR platform, and flow back out through payments to "contractors," "consultants," or "program partners" that trace back to the same individuals who control the nonprofit.

What makes this particularly difficult to detect is that shell NPOs often mirror the language and presentation of legitimate charities operating in the same space. I've seen mission statements that were essentially paraphrased from a real local organization's website. The EIN checks out, the 501(c)(3) status is current, and there's a physical address — which, on investigation, turned out to be a UPS store.

Signals to look for Domain registered less than 18 months ago, with social accounts created around the same time. Mission statement language that mirrors a legitimate local NPO. No Form 990 on file, or 990s with minimal program expenditure relative to total revenue. Board members sharing a residential address. Cross-referencing EINs against flagged organizations on the same platform often reveals network connections.

04 — Form 990-EZ underreporting

IRS reporting gap · Platform data mismatch · Often overlooked
Filing a postcard return while processing far more than the threshold allows

US-based nonprofits with annual revenues under $50,000 are eligible to file a Form 990-N — commonly called the e-Postcard — instead of a full 990 or 990-EZ. It's a minimal disclosure: eight data points, no financial detail, no public accountability. Organizations with revenues between $50,000 and $200,000 file the 990-EZ, which requires more information but still far less than a full return.

The tactic I've seen is straightforward: an NPO files a 990-N or 990-EZ claiming revenues below the relevant threshold, while their actual donation volume on the CSR platform tells a completely different story. I've reviewed cases where an organization's platform data showed six figures in processed donations within a single calendar year — donations that never appeared in any public filing. The IRS record showed a postcard. The platform showed fraud.

This works because IRS filings and CSR platform data exist in entirely separate systems with no automatic reconciliation between them. Nobody is routinely cross-referencing the two — which is exactly what the fraudster is counting on.

Signals to look for 990-N or 990-EZ filings from organizations whose platform donation totals materially exceed the $50,000 or $200,000 filing thresholds. Multi-year 990-N filers whose donation velocity on the platform has been growing steadily. Organizations that cite "low revenues" in self-certification submissions while showing high transaction volume. Any NPO where the IRS-reported revenue and the platform-processed total don't reconcile within a reasonable margin.

05 — AI-generated websites & forged documentation

Rapidly evolving · Increasingly convincing · Affects KYB/KYC integrity
Using AI tools to manufacture legitimacy from scratch

This is the tactic that has changed the most in the last few years, and it's the one I'd most want other fraud professionals to be paying attention to in 2026. It is extraordinarily easy to use AI tools to spin up a convincing nonprofit presence — a polished website, a compelling mission statement, emotionally resonant imagery generated in seconds. What used to take months of organizational history to fabricate can now be assembled in an afternoon.

The documentation problem is just as serious. AI can be used to alter financial statements, business registration documents, tax filings, and anything else required to pass a KYB or KYC review. The alterations are often subtle — and that's exactly what makes them dangerous. I've seen documents where the business name changes partway through the same file, where the entity is described using language that suggests a for-profit structure (LLC designations appearing in what's supposed to be a 501(c)(3) filing), and where typos or formatting inconsistencies point to a document that was assembled rather than issued. None of these individually would fail a surface review. Together, they tell a different story.

Third-party document verification tooling can help catch forgeries at scale, and it's worth integrating where possible. But tooling alone isn't enough. The most important thing is to stay hyper-vigilant and trust your instincts — if something feels off about a document, it usually is. The details that don't quite add up are often the ones worth pulling on.

A related pattern worth flagging: trend-farming. Fraudsters will spin up an NPO around a current crisis — a natural disaster, a conflict, a public health emergency — accepting donations while the cause has maximum emotional salience, then disappear. These organizations often deliberately mimic the branding and naming of well-regarded legitimate charities, and they use aggressive tactics: manufactured urgency, heavy emotional appeals, and pressure to donate immediately. The speed is the tell. Legitimate organizations build presence over time. Crisis-opportunists arrive fully formed and vanish just as quickly.

Signals to look for Websites and documentation that look polished but lack any organizational history — no press coverage, no event records, no staff profiles with verifiable LinkedIn presence. Business names or entity designations inconsistent with nonprofit status anywhere in the documentation. Formatting anomalies, font inconsistencies, or metadata that doesn't match the issuing body. NPOs that appeared recently and are tied to a current high-profile crisis, especially those using emotional urgency and branding similar to established charities. When something in a document doesn't add up, don't rationalize it away — investigate it.

Fraudulent NPOs rarely operate alone. Shell organizations and repeat offenders often share board members, addresses, or platform history — and that network is where the clearest evidence lives.

How I approach an investigation

When a case lands on my desk, the first thing I do is resist the temptation to jump straight to the most visible red flag. A suspicious donation pattern is usually a symptom. The underlying cause — whether it's a shell NPO, a coordinated harvesting scheme, or an insider — takes more structured investigation to surface.

My approach runs in stages. Legal and regulatory status first, because a revoked 501(c)(3) is an automatic critical flag and changes the entire character of the case. Then governance and leadership — who actually controls this organization, and do those people check out? Adverse media next, because reputational signals often appear in local press long before they show up in any database. Then digital presence, financial transparency, program evidence, and finally network analysis, which cross-references board members and EINs against the platform's broader history.

That last stage — network analysis — is where coordinated fraud most often reveals itself. Fraudulent organizations rarely operate in isolation. The same names, addresses, and email domains appear across multiple entities. Catching one usually means catching several.

What good prevention looks like

Detection matters, but the most effective fraud programs invest equally in prevention. A few things that make a real difference: requiring Form 990s or equivalent financial disclosures at onboarding rather than on request; flagging donation velocity spikes in real time rather than catching them in monthly reviews; building transaction anomaly detectors that watch for threshold clustering and match ratio outliers; and making self-certification submissions reviewable against prior submissions so inconsistencies surface automatically rather than requiring manual comparison.

None of this is glamorous, but it's the operational infrastructure that separates reactive fraud programs from proactive ones. Building it before something goes wrong is significantly cheaper than recovering after — both financially and in terms of client trust.

Key takeaways
  • Match harvesting is the highest-volume tactic — watch for threshold clustering, high match ratios, and single-domain donor groups.
  • Volunteer hour claims are almost never audited. A simple check — individual hours versus hours physically possible alongside full-time employment — catches a surprising amount. Zero donations alongside high matched-hour volume is equally telling.
  • Shell NPOs invest in looking legitimate — check registration date, Form 990 history, board member addresses, and program evidence, not just 501(c)(3) status.
  • Cross-reference IRS filing status against platform donation totals. A 990-N postcard filer processing six figures on your platform is a serious red flag that no single system will surface on its own.
  • AI has made it trivial to manufacture a convincing nonprofit presence — polished websites, generated imagery, and altered documents can all pass a surface review. Look for organizational history, not just organizational appearance. When something in a document doesn't add up, trust that instinct and investigate it.
  • Trend-farming — spinning up crisis-linked NPOs to harvest donations then disappear — is an increasingly common pattern. Urgency, emotional appeals, and similarity to established charities are the hallmarks.
  • Network analysis catches coordinated fraud that individual NPO checks miss. Fraudulent organizations share people, addresses, and histories more often than you'd expect.
  • Prevention infrastructure — velocity monitoring, anomaly detection, financial disclosure requirements — is far cheaper to build than a post-incident recovery.