EMAIL SECURITY FOR CHARITIESCharity money,
spent on the cause.

Charities run on trust, volunteers and tight budgets, and the Charity Commission says phishing is the most common kind of cyber-enabled fraud they experience.

A fictional email12:09
FromJordan Ellisjordan.ellis@yourfirm.example
Reply-Tojordan.ellis.payroll@freemail.examplenote 1

Note 1: Replies go to a private address

ToAlex Morgan
SubjectChange of bank details for payroll
ChecksSPF fail, DKIM none, DMARC fail

Hi Alex,

I have recently switched banks and would like my salary paid into my new accountnote 2 from this month's payroll. Could you please update my details before the payroll is run?

Note 2: Staff pay redirected by email alone

Account name: Jordan Ellis Sort code: 11-22-33 Account number: 12345678

I am out at the community project all week with no signal, so email is the easiest way to reach menote 3. Thanks for sorting this.

Note 3: Steers you away from a phone call

Best wishes, Jordan

100out of 100

Very high riskJatzo's result for this fictional email

What moved the score

  • Payment change with a warning sign+28
  • DMARC failure reported+22
  • Supplier payment details changed+16

and 5 more

The numbered notes point out what to look for. The score and the reasons beside it are Jatzo's own result for this email, which was written for this page. Every name and address in it is invented.

Invoice and mandate fraud, as UK Finance recorded it.

  • £41.3 millionlost to invoice and mandate fraud in 2025
  • 2,305cases recorded in the year
  • 68%of the losses came from business accounts

Criminals intercept emails or take over an email account, then pose as a supplier, a solicitor or a builder with new bank details. UK Finance, Annual Fraud Report 2026, June 2026 (opens in a new tab)

The Charity Commission opened 603 cases relating to fraud between November 2023 and October 2024. That counts fraud of every kind, not only fraud that began with an email. Charity Commission, Regulator refreshes guidance as it reveals 600 cases related to fraud, November 2024 (opens in a new tab)

What charities worry about.

And what Jatzo does about each, in the inbox your team already uses.

  1. Staff pay redirected

    Fraudsters email HR or finance pretending to be a member of staff with a new bank account, from a spoofed or lookalike address.

    What Jatzo does

    The check flags a change of bank details with a warning sign beside it, and a High risk result emails your treasurer at once.

    Business and Business Pro
  2. Phishing, first and most often

    Phishing is the most common type of cyber-enabled fraud charities report to the Charity Commission.

    What Jatzo does

    The check gives anybody, staff, volunteer or trustee, a score out of 100 with the reasons in plain English, so nobody has to be an expert to make the right call.

    Every plan
  3. Donors' and beneficiaries' details

    A charity holds donors' details and often its beneficiaries' circumstances. A data breach can be a serious incident to report to the Charity Commission, as well as to the ICO.

    What Jatzo does

    The check flags fake sign-in requests before anybody types a password, and Jatzo keeps the findings, never the email or its attachments.

    Every plan

How it unfolds for charities.

  1. Payday approaches

    Staff pay, or a payment to a supplier or grantee, is about to go out.

  2. Check it here

    New details arrive

    An email to HR or finance, in a staff member's name, gives a new account for their pay.

  3. The address looks right

    It comes from a spoofed or lookalike address, so it seems to be from somebody you know.

  4. The pay goes

    Unless somebody checks with the employee on separately sourced contact details, the pay goes to the fraudster.

The gold mark is where Jatzo's check fits: somebody has the email open and nothing has been paid yet.

The check before you pay.

Six steps, every time. Print it, put it by whoever pays the invoices, and agree that nobody skips it because somebody senior is in a hurry.

Download the one-page checklist (PDF)
  1. Never change a supplier's, grantee's or employee's bank details because of an email alone.

  2. Ring them on the number already on your records, not one in the email.

  3. Ask for the request on the supplier's own amendment form and check it against past payments.

  4. Two people authorise every payment and every bank detail change, volunteers included.

  5. For a first payment to new details, send a small amount and have the payee confirm receipt by phone.

  6. If money has gone, ring your bank's fraud line at once, then report to Report Fraud on 0300 123 2040 or reportfraud.police.uk (Police Scotland on 101 in Scotland).

    Also on day one in England and Wales: tell the chair, keep a record of what happened and when, and consider a serious incident report to the Charity Commission.

What the charity gets.

It does not replace the call. It makes sure somebody makes it. Jatzo adds a check beside the message in Outlook and Gmail, at the moment somebody decides whether to pay, reply or click, and your existing email protection stays as it is.

  • Check before pay details change

    Every plan

    Anybody unsure about a request to change where pay goes presses Check in Outlook or Gmail and sees a score out of 100 with the reasons.

  • A separate check on supplier invoices

    Separate licence, from £129 a year

    Invoice Fraud Checker, a Windows program, compares the bank details on each supplier invoice with the ones you confirmed for that supplier. About the Invoice Fraud Checker

  • Your treasurer hears at once

    Business and Business Pro

    When anybody checks a message scoring High risk or above, an email goes to addresses you choose at your own domain, such as your treasurer's.

  • See what is aimed at the charity

    Business and Business Pro

    The organisation threat report counts the checks that reached Suspicious or above by kind of attack, the last 30 days against the 30 before, and names nobody.

  • Training for staff and volunteers

    Business Pro

    Business Pro adds every Training Centre course for everyone in the team, staff and volunteers alike, with a record of who completed it.

Which plan fits: an example

For charities with 4 people, we suggest Business: £32 a month, or £320 a year paid annually.

That is £8 a person a month.

Business gives the few people who handle payments and staff pay the Check button, High risk alerts and the threat report; Business Pro adds training when the budget allows.

Business includes the threat report, so you know what is being aimed at the charity and whether it is getting worse: every email your team checked that came back Suspicious or above, by kind of attack, the last 30 days against the 30 before, naming nobody. At the start of each month a report goes by email to the addresses you choose, saying what was checked and what is still waiting.

  • The Check button in Outlook, including on a phone, and in Gmail, for everybody in the team.
  • Staff do nothing. Whoever looks after your email adds it once, for everybody.
  • Nothing to replace. Your email, and the protection it already has, stay as they are.
  • Jatzo keeps the score and the findings for up to 90 days, never the email or its attachments.
  • Pay monthly, or a year in advance for ten months' price.

The Invoice Fraud Checker is a separate licence, from £129 a year. About the Invoice Fraud Checker

What your sector's own bodies say.

Each point is linked to where it was published, with its date.

Use dual authorisation for all financial transactions; if fraud happens, act quickly, preserve evidence, report to Report Fraud, and consider a serious incident report to the Commission.

Charity Commission, Protect your charity from fraud, November 2024 (opens in a new tab)

Review how employee bank details are changed and approved, and verify requests with the employee using separately sourced contact details.

Charity Commission, Alert for charities: fraudsters impersonating staff, December 2019 (opens in a new tab)

Report Fraud replaced Action Fraud in December 2025. The number, 0300 123 2040, did not change. GOV.UK, Report Fraud: new service from City of London Police, December 2025 (opens in a new tab)

Questions charities ask.

Does every volunteer need a seat?

Only those who check email in the team. Each person who presses Check has a seat, and every check goes to the team's history. A charity can start with the people who handle payments and staff pay, and add more later.

Does it replace dual authorisation?

No. Two people authorising every payment and every bank detail change is what the Charity Commission advises, and it still applies. Jatzo helps whoever reads the email notice that it needs checking, before anybody authorises a payment.

Does Jatzo read our beneficiaries' records or the rest of the mailbox?

No. Jatzo reads only the email somebody chooses to check, and the add-in cannot reply, forward, move, delete or change anything in the mailbox. It keeps the subject line, the score and the findings for up to 90 days, never the message or its attachments. Links in it are checked against Google Web Risk.

Will our IT company need to do anything?

A little, once. Whoever looks after your email proves your domain with one DNS record. For Microsoft 365 they then upload one file in the admin centre, which needs the Exchange Administrator or Global Administrator role, and Microsoft takes 24 to 72 hours to add the button. For Google Workspace they install Jatzo for the domain. Staff do nothing.