Important limitations

Escalate suspicious donation activity without disabling safeguards

Last materially reviewed 2026-09-30

Quick answerPreserve the observed pattern and contact the authorized provider route; do not improvise a refund or weaken controls.
Likely to work well when

✓ Small nonprofit handovers

✓ Recurring-gift administration

✓ Requirement-led platform comparison

Important limitations

— Payment execution

— Tax or legal advice

— Donor profiling

— A substitute for the nonprofit’s support team

What to know

Record observations without accusing a donor

Repeated failed small attempts, an unusual cluster of requests or a demand to return money elsewhere can justify review. They are not proof that a named person committed fraud. 4aGoodCause discusses card testing and refund scams in its fraud guidance. Capture only the relevant time range, pattern and private reference location for the organization’s authorized investigator. Avoid copying card details or publishing the suspected person’s information. This guide helps route a concern, not identify criminals or make a financial decision.

What to know

Use the established incident route

Identify the nonprofit account owner and the relevant processor support path from trusted account documentation. A message claiming to be support is not enough to establish that its link or return account is legitimate. Do not follow an unexpected instruction to transfer funds, disclose credentials or change authentication. If the concern is urgent, use the organization’s existing escalation process. Keep the original observations available to the responsible team rather than experimenting with live payments to see whether the suspicious pattern can be reproduced.

What to know

Do not treat a feature list as verified protection

The merchant’s fraud article discusses gateway controls and CAPTCHA, but that does not show which protections are active or effective in a particular account. Have the authorized administrator inspect the actual configuration and provider recommendations. This publication has not tested those protections. Do not switch off safeguards to reduce errors or use a successful test as proof that abuse is impossible. Any operational change should follow the organization’s security and payment procedures, with a clear owner and a way to verify its intended result.

What to know

Keep the case separate from routine support

A donor’s ordinary cancellation or missing acknowledgment belongs in its normal workflow unless evidence calls for escalation. For a suspicious refund destination, preserve the request and let the responsible team verify it before a financial action. Record what was referred, to whom, and what remains unknown; “sent to the processor” is not the same as “resolved.” Use the refund guide for the distinction between past and future payments, and the data-boundary guide for limiting unnecessary copies of sensitive material during the investigation.

Source boundary

Where the safety evidence stops

This guide draws on 4aGoodCause: Merchant fraud guidance, 4aGoodCause: Stripe dashboard responsibilities. Merchant-controlled records describe the provider’s own capabilities, terms or standards; they do not independently validate those claims. These records do not establish independent confirmation of the product claims.

Verify any current price, plan limit, label direction, compatibility rule, or commercial term that would materially change the decision. The dated source ledger shows the underlying records so this conclusion can be checked and updated.

Sources used for this page

These records support the facts and comparisons above. Merchant-controlled records are labelled so you can separate product claims from independent evidence.

  1. 4aGoodCause: Merchant fraud guidance — Merchant documentation · help.4agoodcause.com · Merchant-controlled · checked 2026-09-30
  2. 4aGoodCause: Stripe dashboard responsibilities — Merchant documentation · help.4agoodcause.com · Merchant-controlled · checked 2026-09-30