Tips to keep your cat safe at home
Read more
PetRescue was contacted about a potential philanthropic grant that appeared genuine, personalised and too good to ignore. It wasn't. Here's what happened, the red flags we eventually spotted, and how your organisation can protect itself from similar impersonation scams.
A sophisticated scam may not ask you for money straight away. It may first ask for your trust.
Watch out for:
-
An unexpected funding opportunity that seems unusually personalised
-
Someone representing a professional organisation from a personal email address
-
Pressure to communicate only by email
-
Requests for confidentiality before you've independently verified the person
-
A LinkedIn profile or identity you can't independently confirm
-
Responses that feel unusually polished, generic or AI-generated
-
Any reluctance to let you verify their identity directly
-
Urgency, secrecy or pressure to keep the opportunity moving
If something doesn't feel right, stop and verify it through a channel you find yourself.

A few weeks ago, someone very nearly convinced us that PetRescue was about to receive a large philanthropic grant. The email exchange was warm, personalised, specific, and well-researched.
It referenced PetRescue’s impact and actual programs by name and with accuracy.
Their follow-up responses asked thoughtful questions about what we'd do with the funding if we were successful, and took the time to learn more about what this would mean for pets.
It came with all the hallmarks of a serious, discreet introduction from a professional working on behalf of a private philanthropist - and to see PetRescue’s work recognised by someone who could potentially believe in our vision and unlock what’s to come financially? Well, that was energising, to say the least.
To those who are reading this from a charity or non-profit organisation, the feeling we’re referring to might be familiar at this moment; this type of outreach was the kind of opportunity that an organisation can only dream of accessing, especially when you aren’t large enough to have dedicated philanthropic personnel on the team. While we have game-changing initiatives that we’re ready to hit go on that we know will drive long-term impact, the grants and funding process is frankly time-consuming, opaque, and stressful.
Well, we all know what they say when things are too good to be true.
I'm writing this because I think a lot of charities are going to get this exact email, or one that’s similar, if they haven't already. Just this week, another similar one from a different sender appeared in my inbox.
This isn't the clumsy scam most of us have learned to spot on sight - bad grammar, a stranger's bank details, "click here to claim your prize", or even an ask for any fees or money - it was the opposite offer.
This is a new generation of fraud: patient, personalised, calculated, and very likely assisted by AI. It's built specifically to exploit how nonprofits actually work - our hope that a genuine philanthropist might be quietly watching, our habit of taking cold outreach seriously because sometimes that's exactly how real funding starts. Sometimes.
Here's how it unfolded for us, and what to watch for.

How the scam worked
The approach had three key stages, but several email exchanges, each designed to lower your guard a little further.
Stage one: personalised outreach that doesn't feel cold.
The first email isn't generic. It names you, your organisation, references specific programs, and shows evidence of genuine interest and desk research - not just your public "About" page, but details that suggest someone actually read your annual report or recent media coverage. This is what makes it feel different from the obvious phishing you're used to deleting.
Stage two: the "confidential intermediary" framing.
The sender presents as a professional consultant or representative of a global organisation working with private philanthropists. They explain, credibly, that direct philanthropic outreach is unusual and that their client values discretion - hence the need for confidentiality before anything is discussed further. This explains away almost every question you'd normally ask (why no public process, why not go through official channels) before you've even thought to ask it.
Stage three: engagement, not extraction.
Unlike a classic scam, there's no early request for money or bank details. Instead, the exchange focuses on your organisation - what your specific initiatives are, what you'd do with the funding, what impact it would have. Your answers get reflected back to you, expanded on, taken seriously. It feels like being listened to by someone who's genuinely invested in your mission. That feeling is the product being sold to you.

The five red flags that gave it away 🚩
None of these, on its own, is damning. Together though? Follow your nose, and you’ll see where it smells off…
1. They're using a personal email address for a professional role
The sender's photo and title matched a real person at a real organisation when we looked them up, but their name was spelled inconsistently, sometimes, across messages. When we asked why they weren't using an official company email, they had a ready answer: as a contractor, they said, everyone on their team uses Gmail. A personal Gmail address doesn't prove something is a scam, but it is a reason to pause and independently verify who you're dealing with, particularly when someone is representing an organisation or philanthropic client. And a real person doesn't misspell their own name.
We recently published an article about PetRescue’s recent email verification upgrades - we believe every organisation should go through these steps so that their caring audiences and beneficiaries can check the legitimacy of the communications they are receiving.
Tip: always check the sender’s email address, not just their name.
2. They insist on email-only communication
No call, no meeting, and the NDA was nothing more than typing "I acknowledge and agree" back in an email. A real NDA is a document, often with a signature through e-sign software or, at minimum, a formal process behind it. There was a note that this was the first step to keep things moving forward while they were assessing your eligibility and that the formal paperwork would follow. An email acknowledgement isn't confidentiality; it's a psychological commitment device: once you've "agreed," you feel obliged to keep engaging.
3. Their identity can't be independently verified.
They offered to share their LinkedIn profile, but refused to connect, and wouldn't reply to a direct message asking them to simply confirm it was them - insisting that wasn't "how things were done." If someone is representing a real organisation, you should be able to independently verify their identity and connection to that organisation. If they discourage or prevent you from doing so, treat that as a significant warning sign.
4. Their messages feel unusually polished or AI-generated.
Structurally smooth, comprehensively on-topic, but with a certain uncanny uniformity - the same rhythm and thoroughness in every reply, regardless of what was asked. This is increasingly hard to prove, but if it's setting off a "this doesn't sound like a person typing quickly" instinct, trust that.
5. The organisation they represent says the approach isn't legitimate.
This is the one that matters most, because it's the only one that's conclusive. When things don’t feel right, it’s encouraged to follow your intuition. We contacted the ‘real’ organisation directly through their official, published channels and asked whether this person and this outreach were legitimate. They confirmed it was an impersonation and confirmed that we should not engage further.
The golden rule: verify independently
Don't verify the sender using the contact details they've provided. Find the organisation's official website, phone number or email address yourself and contact them directly.
Is this philanthropic grant a scam?
You don't need to become paranoid to protect your organisation. You need a short, consistent verification habit that helps to weed out scams before they take up too much of your precious and finite time. If you ever have a question about the legitimacy of an email and are asking yourself, “is this philanthropic grant a scam?”, then these are your first steps to follow:
Verify through a channel the sender didn't give you. Don't reply to the email to ask "is this real?" Go to the organisation's official website or a known public phone number, and ask them directly. If the sender's own claim is your only route to verifying the sender's claim, it isn't verification.
Ask for a video call before anything substantive. A genuine philanthropic intermediary managing a serious grant relationship will get on a call. If the answer is "our client prefers written communication only" for the entire process, that preference is doing a lot of work to keep things unverifiable.
Treat any NDA request as a real legal step, not an email formality. A confidentiality agreement should come as an actual document, ideally reviewed by whoever handles your contracts, before you share anything you wouldn't say publicly. "Reply and agree" is not a binding or protective process.
Test identity claims where the other person can't control the outcome. If someone gives you a name and organisation, look them up independently and try to make contact through a channel they don't control - a company switchboard, a colleague, a LinkedIn message to the actual profile. Their willingness (or refusal) to let that verification happen tells you almost everything.
Loop in a second person before you invest real time. Scams like this work partly through momentum: each email makes withdrawing feel more awkward - what if your inaction or slow responses were the reason your organisation missed out on a life-changing donation? If the governance steps are missing or haven’t captured new approaches for scams, naming it out loud to a colleague or board member, "Does this feel like a legitimate grant conversation to you?", breaks that momentum early.
Remember: real funders are patient with scrutiny. Nothing about verifying a grant opportunity should offend a genuine philanthropist or their representative. If checking credentials produces defensiveness or urgency ("this is a rare window," "my client may lose interest"), that pressure is itself information.

What could have happened if the scam played out?
It's worth sitting with this for a second, because "they never asked for money, so no harm done" is exactly the trap this scam is built around.
The next step is very rarely nothing.
Advance-fee scams like this typically don't ask for money upfront; they ask for it later, dressed up as something reasonable: a "processing fee," a "compliance or escrow charge" to release international funds, a "verification payment" that gets refunded along with the grant. By the time that ask arrives, you've had weeks of warm, trust-building exchanges behind you, and organisations under funding pressure make decisions under that kind of momentum that they'd never make cold.
Banking details go two ways.
Even if no fee is ever requested, at some point a legitimate-sounding grant needs somewhere to land - and handing over your organisation's banking details "to prepare for the transfer" gives a scammer real financial information and can open the door to business email compromise: invoices that suddenly look like they're from you, redirected the moment a real donor or partner tries to pay you.
"Due diligence" can run both ways.
A next-stage ask might be a link to an online "verification" or "grantee" portal - a login page built to harvest credentials, or a document with something malicious attached. It doesn't have to be the CEO who clicks it; it could be anyone on the team looped in to help move things along.
Everything you shared becomes ammunition.
We talked openly about our specific programs, our plans, what success would look like for us. In a genuine funding conversation, that's exactly the right thing to do. In this one, it's reconnaissance - details that could be recycled into a more convincing follow-up scam aimed at our board, our finance team, or our actual donors, or even used to impersonate us to others.
It's a rehearsal for the next one.
Whoever is running a pattern like this is refining it conversation by conversation. Every reply we sent, every detail we gave, would have made this actor better at running the next version of this exact scam on the next charity - we were highly likely not the first target; it’s why their pre-emptive responses were crafted to be reassuring - they’ve played out this training drill before.
None of this happened to us, because the pattern broke at red flag five. But every one of those paths remained while there was interaction, and that's really the point: the danger in this scam was never the first email. It's in how far a normal, well-intentioned back-and-forth can carry an organisation before someone stops to check.

What to do if you receive a suspicious grant approach
1. Stop and slow down
Don't let excitement or urgency push you into continuing the conversation.
2. Don't click links or open unexpected attachments
Particularly if you've been asked to complete a "verification" or "grantee" process.
3. Never provide sensitive information
Pause before sharing banking details, login information, internal documents or information that isn't publicly available.
4. Verify independently
Find the organisation's official contact details yourself and contact them directly.
5. Get a second set of eyes
Ask a colleague, CEO, board member or finance person to review the approach.
6. Report it if appropriate
For Australian organisations, you can report scams to Scamwatch, and cyber incidents can be reported through Australian Cyber Security Centre. Cyber.gov.au also provides guidance on business email compromise.

Why this matters for charities
Charities are, by heart and by design, trusting. We assume good faith because most of what we do depends on it, and because sometimes genuine, quiet philanthropy really does arrive exactly this way, through a personal introduction, asking careful questions, wanting privacy. That's precisely what makes this scam effective against us in the sector specifically, and precisely why sharing what it looks like matters more here than almost anywhere else.
Fortunately, we’re not writing this cautionary tale because we got fooled. We caught it, verified it, and confirmed it. We're writing it because the version of this scam aimed at your organisation will be personalised to you, built from your public information, and delivered with genuine polish. Knowing the pattern in advance is the whole defence.
If your organisation gets an email like this, you don't need to be an expert in fraud detection. Make one phone call or email to the organisation the sender claims to represent, using a number or official email you found yourself.
Then take a moment to share your cautionary tale with your colleagues to protect them from falling prey to this frustrating piece of the digital world we must navigate.
If you remember one thing…
A genuine funding opportunity should survive scrutiny. When something looks too good to be true, this is the exact moment to pause and verify.
By Patima Tantiprasut, CEO & Managing Director, PetRescue
Authorship transparency.
A note on how this article was written: the information, framing, core ideas, story, and recommendations are the author’s own. AI tools were used to help edit and refine the text for the purposes of efficiency and identifying any questionable gaps, and fresh-eyed human editors cast a review over it with refinements prior to publishing (probably while their pets were eyeing them off for treats simultaneously).
*We can't prove that AI was used, but the consistency, structure and tone of the responses made us suspect the correspondence may have been AI-assisted.
Images via Canva, except PetRescue office doggo (image 4)
