Sector study · scan of 21 August 2026

Nearly half of UK charities have staff passwords in criminal credential collections — six in ten of the largest

We looked at 380 UK charitable organisations the way anyone on the internet could: from the outside, without logging into anything or trying a single password. None of them showed any sign of having been compromised. What turned up instead was ordinary, preventable exposure — and most of it takes an afternoon to put right.

46% / 63%

have staff email addresses in infostealer credential collections (best-known / largest by income)

30% / 42%

have staff credentials tied to their own domain — and in every case, the login page is recorded too

~1 in 3

do not tell mail providers to reject forged email sent in their name

0

ransomware leak-site mentions, breach-collection records or browser-safety flags

Somebody walking down your street

They never go inside any house. They never try a door. They simply walk past and notice what is visible from the pavement: a window left open, a side gate unlatched, a spare key under the mat where everyone knows to look.

None of that means the house has been burgled. It means somebody passing by can see opportunities, and most of them take a minute to put right.

That is exactly what this assessment does. Staff passwords circulating in criminal collections are the spare key under the mat — it does not mean anyone has used it, but somebody else knows where it is. A login page recorded alongside those passwords is knowing which door the key opens. A service reachable from the internet that need not be is the side gate nobody remembers leaving unlatched.

A stolen password is half an intrusion

A credential becomes far more useful to an attacker when the same criminal collection also records the page where it is used. That pairing is the single most actionable finding in this study — and it is not a subset. Every organisation with staff credentials exposed also has its internal login pages recorded alongside them: 65 of 65 in the best-known group, 99 of 99 by income. Where the key exists, so does the address.

In one case those pages included a jobs portal and a remote-desktop gateway — the kind of door that opens onto an internal network rather than a website.

A key on its own is of limited use to a stranger. A key with the address attached to it is a different matter.

The fix is unglamorous and it works: reset the credential, enforce multi-factor authentication, revoke the sessions that are already open.

Larger budgets did not remove the exposure

Both groups averaged the same external score of 65. Higher income did not translate into a visibly better external position — the differences are in the detail, and they run in both directions. The income group carries more credential exposure; the best-known group has more services answering from the internet. These are differences in exposure, not in competence.

The impersonation risk is the one charities feel

Charities depend unusually heavily on trust, and a convincing fraudulent email can exploit a charity's name even when the charity itself has not been breached. Around a third of each group does not tell receiving mail systems to reject forged messages.

Moving to an enforcing policy is low-cost, but it is not a switch to flip: identify the legitimate senders, monitor first, and only then move to rejection, so that genuine fundraising, CRM and supplier mail is not caught by it.

What we could not see

Standing in the street tells you nothing about the alarm system, the safe, or the locks on the internal doors. Many of these organisations will have good protections we simply cannot observe.

Around three homepages in ten did not serve to our scanner at all — in many cases bot defence refusing an automated request, which is itself a security control. Where that happened the organisation earned no points for the area we could not read, so its score is a floor, not a verdict. Both averages would rise to as much as 69 had every homepage answered.

So no organisation should be described as ‘at risk’ on a score alone. Of the 25 lowest-scoring organisations in each group, nine in each would leave that band had their homepage answered.

The full method, population and interpretation notes are on the method note.

Where to start

The full report sets out seven steps. The first three carry most of the benefit:

  1. Check for exposed staff credentials and act on what you find — reset, enforce MFA, revoke live sessions, starting with identity providers, email, finance, CRM and remote access.
  2. Enforce multi-factor authentication everywhere it matters — it removes most of the value of a stolen password.
  3. Protect your name from forged email — move SPF, DKIM and DMARC towards an enforcing policy, after monitoring.

Steps four and five are about suppliers, and they are the ones a board can act on without any technical work at all: know what each material supplier holds for you, and make prompt, charity-specific incident information a contractual requirement. Supplier assurance cannot prevent a failure inside someone else's systems. What it can do is shorten your response.

The useful conclusion

It is not that charities are failing. It is that a large part of cyber resilience is made of small, manageable decisions — and that this sector starts from high public trust, committed people, and no visible sign of compromise across 380 organisations. It is a short list of things worth doing, and there is time in which to do them.

Read the full report

15 pages, written for trustees, journalists and regulators: the full method, the population, every figure with its caveat, the seven steps in full, and the sources.

Read the full report (PDF, 15 pages)Or check a domain against the same external checks