Payment / invoice fraud in the Charity / non-profit sector
How a payment / invoice fraud attack could realistically chain together in a Charity / non-profit organisation, from initial access to business impact — and exactly what you should test to break the chain.
Business email compromise to invoice fraud
A compromised finance or executive mailbox is used to study payment processes, establish stealthy persistence, and redirect a legitimate payment to an attacker-controlled account.
Web skimming to payment fraud
A weakness in an e-commerce site or one of its third-party scripts is used to capture customers' payment details at checkout, which are then used or sold for fraud.
Why chaining matters here
A scanner might flag each weakness in this environment in isolation. What determines whether payment / invoice fraud is actually achievable is whether those weaknesses — together with identities, trust relationships and gaps in monitoring — can be linked into a working path. That is what a red-team engagement validates, and what these chains are designed to help you scope.