Method note · back to the study
How this study was carried out
Every figure describes a single external scan completed on 21 August 2026. Nothing is carried over from an earlier run, and no trend or improvement is claimed against one.
What we looked at
Two lists: 220 of the best-known UK charitable organisations and 236 of the largest by income. All 220 and all 236 were scanned.
⚠️ The two groups are never added together. 76 organisations appear in both, so the study covers 380 distinct organisations. A combined “456 organisations” would double-count them — 456 is the number of scans, not organisations.
The income list also contains higher education bodies that are charities or exempt charities — around 35 universities, independent schools and research institutes, roughly 15% of that group. That matters when comparing the two: excluding education entirely, employee exposure runs at 40% against 30%, so the gap narrows but survives.
What we did not do
The assessment is external and non-intrusive. It uses information already observable from the public internet and public records. Nothing was logged into, no password was tried, and no system was probed beyond what an ordinary web visitor and an external non-intrusive scan can see.
What the assessment does not prove
Nothing in this study says any organisation has been breached. Credential findings describe sign-ins circulating in criminal collections, often harvested from infected staff, supplier or public devices. A reachable port is not proof that a database can be accessed. A hosting IP on a threat feed may reflect another tenant on shared infrastructure.
External posture is evidence of exposure, not evidence of intrusion. We can see that a window looks open. We cannot see whether anyone has climbed through it, and in many cases nobody has.
How to read the scores
On the 21 August 2026 run the homepage did not serve to our scanner for 67 organisations in the best-known group and 70 in the income group — around three in ten of each. In many cases this appears to be bot defence refusing an automated request, which is itself a security control. No finding is raised for the area that could not be read, but the organisation earns no points there either.
So the published scores are floors, not verdicts. Both group averages of 65 would rise to as much as 69 had every homepage answered, and the effect on the weakest scores is larger than on the averages: of the 25 lowest-scoring organisations in each group, nine in each would leave that band. ⛔ No organisation should be publicly described as ‘at risk’ on a score alone without first checking whether its homepage was readable. Bot defence must not be mistaken for poor security.
About the credential figures
Credentials fall into three separate groups: the organisation's own staff addresses on its own domain, the organisation's own addresses signed in to outside services, and supporter or service-user accounts. The three do not overlap — they sum exactly to the provider's total on every one of the 440 charity scans checked. Supporter accounts are excluded from the headline figure entirely, because they largely describe malware infections on members of the public's own devices rather than charity security, and nobody at the charity can reset them.
The second group is often called ‘supplier’ exposure. That is misleading, and we no longer use the word: these are the charity's own email addresses signed in to somebody else's platform. Where the provider names the services, they are identity and collaboration tools — Microsoft sign-in, Salesforce, Zoom, Dropbox, Mimecast. The accounts sit on other companies' systems; the identities are the charity's.
⚠️ How current this exposure is cannot be established for most of it. The study counts exposure as current for 12 months, and treats a record with no date as current rather than assuming it is old. But the provider supplies a date only for the staff-on-own-domain group, and most records carry no date at all — 13 of 61 exposed organisations in the best-known group and 23 of 98 by income. The outside-services group has no date field whatsoever.
So the headline should be read as ‘these addresses appear in credential collections’, not ‘these passwords were stolen this year’. The exposure is real and worth acting on either way — an undated credential is not a safe one — but the date is not evidence we hold.
Raw credential volumes are deliberately not used as a headline: most account-holder credentials relate to members of the public, and larger organisations naturally create more opportunities for employee exposure.
Where the study reports known software vulnerabilities, those are inferred from published version numbers rather than confirmed by testing. A version number can be wrong, and a patch can be applied without the number changing. It is a prompt to check, not a finding of vulnerability.
Where these figures differ from the PDF
The credential figures on the study page were re-derived on 1 September 2026 directly from the provider's own counts, for all 440 charity scans. The two estates are reported separately, as in the report; they are never added together.
| Measure | Best-known (220) | Largest by income (236) |
|---|---|---|
| Staff addresses on own domain | 65 (30%) | 99 (42%) |
| Own addresses on outside services | 94 (43%) | 140 (59%) |
| Either — the headline | 102 (46%) | 148 (63%) |
| …carrying a provider date inside 12 months | 9 (4%) | 14 (6%) |
| Supporter accounts only (excluded) | 69 (31%) | 41 (17%) |
The PDF gives 44% and 56% for the headline row. The difference is the recency rule: its pipeline used the staff date to age out the whole record, including the outside-services part that carries no date of its own. Reading the buckets directly, without inferring a date the provider never gave, produces the higher figures above. Every other row agrees with the report to within one organisation.
One row in the report is worth reading carefully. ‘Internal login pages already recorded’ is not an independent measure — it is exactly the same organisations as the staff-exposure row, 65 of 65 and 99 of 99. The provider returns the captured pages precisely when it holds staff credentials, so the two rows carry identical counts. That makes the pairing universal rather than partial, which is a stronger statement than the report's presentation suggests.
Comparing this with the government survey
The study sets its findings alongside the Cyber Security Breaches Survey 2025/26. The two answer different questions and should not be equated: the government figures are self-reported incidents that organisations identified and recalled, while these figures are externally observed posture. Neither is a substitute for the other.
Scope and status
No charity registration status has been independently verified. No organisation named in the underlying scan has been contacted for right of reply. This study is not legal advice, and it is not a verdict on any organisation's security — it is an account of what was showing from outside on one day.
The full report
Sources, the government comparison table in full, and every figure with its caveat.
Read the full report (PDF, 15 pages)