Street solicitors posing as charities are exploiting tap-to-pay card readers to alter the donation amount a giver believes they are authorizing, according to Kurt Knutsson, the tech expert behind CyberGuy Report. A donor who intends to give $20 may instead find $2,000 charged to their card, often without noticing the screen changed.
The technology itself is not broken. Mary Ann Miller, fraud and cybercrime executive advisor and VP of client experience at identity verification company Prove, told Fortune that "the technology may work exactly as designed, but the problem is the manipulation happening around the transaction." Fraudsters, she said, increasingly exploit "trusted interactions and familiar behaviors rather than trying to break through security controls."
That distinction matters once the money is gone. Eva Velasquez, CEO of the nonprofit Identity Theft Resource Center, told Fortune that recovering funds is far harder when a donor technically authorized the payment but simply failed to check the final amount. Credit cards offer a cushion because cardholders can dispute a charge with the issuer, she noted, but instant payment methods carry no such protection — and "there is no guarantee that you will be made financially whole."
The scam lands at a moment when younger donors are trying to rebuild trust in philanthropy. Bloomerang's 2026 Giving Signals Report, produced with The Harris Poll among more than 1,000 U.S. donors and 400 fundraising leaders in March, found that millennials and Gen Z give in large part because it makes them feel like "part of something." The same report found 85% of active donors already trust organizations to use funds effectively.
"Donors are ready to trust nonprofits, but they want to see the receipts more," Steve Isom, chief operating and financial officer of nonprofit software company Bloomerang, told Fortune. "A bit more trust, but verified."
Velasquez's advice cuts against the impulse-giving model entirely: pick the cause yourself, rather than letting a card reader on a sidewalk pick it for you, and vet organizations through third-party charity accreditation sites before handing over a card.
The episode is a reminder that no regulator can authenticate intent — only a screen and a signature. The fraud here does not exploit a loophole in the law; it exploits inattention at the point of sale, the same vulnerability that exists in any transaction where a buyer trusts a seller's word over the number in front of them.
The market's own tools, not new mandates, are already the best defense. Credit card issuers, unlike instant-payment platforms, build in dispute rights precisely because private companies compete on trust and reliability. Consumers who want protection should choose the payment rail that carries it, verify charities independently, and treat every tap of a card as a signed contract — because it is one.



