🤝CharityInsurance.co.nz
← Back to Blog
Cyber & PrivacySarah Connell8 min read1 September 2026

QR Code Scams and Your Charity's Cyber Cover

The National Cyber Security Centre published its Cyber Security Insights report for the second quarter of 2026 on 20 August, covering the period from 1 April to 30 June. For charities, sports clubs, churches and community trusts, two numbers in it are worth sitting with.

What the Latest Quarter Actually Showed

The NCSC responded to 1,129 incident reports in the quarter, broadly level with the 1,164 reports received in the first three months of the year. Reporting volumes, in other words, are steady. What changed is severity. Of those reports, 92 were triaged for specialist technical support because of their potential national significance, up from 77 in the previous quarter. The remaining 1,037 did not require that level of response.

Reported direct financial losses came to $2.7 million for the quarter, a 52 percent fall from the $5.6 million reported between January and March. That headline drop is genuinely good news, but it hides an uncomfortable distribution. Scams and fraud returned as the most commonly reported category with 348 incidents, yet accounted for only around $860,000 of the total. Unauthorised access incidents were far less common and accounted for roughly $1.3 million — about half the quarter's entire reported loss. A small number of intrusions did most of the damage.

Phishing and credential harvesting sat second on volume. It remains the entry point for a large share of the unauthorised access that follows.

Why the Report Singled Out QR Codes

The NCSC devoted one of the report's two feature articles to QR code phishing, under the title "QR codes: Think before you scan". The technique attracted wider public attention this year after incidents involving Christchurch parking meters, where fraudulent codes were used to direct people to pages designed to capture payment details.

The mechanics are simple. A printed sticker or a code embedded in an email carries no visible destination. A person who would never click a suspicious hyperlink will scan a code on a poster without hesitation, because the code looks like part of the physical furniture of the venue. The phone opens the page in a mobile browser, where the address bar is truncated and the visual cues that help people spot a fake are largely absent.

Community organisations are unusually exposed here for reasons that have nothing to do with technical sophistication. Charities have moved donation collection onto QR codes at speed, precisely because contactless giving works: a code on a collection bucket, a table card at a fundraising dinner, a poster in a shop window, a slide at the end of a presentation. Those codes are printed in bulk, distributed to volunteers, displayed in public spaces for weeks, and almost never audited. Overlaying a fraudulent sticker on a legitimate donation code is trivially easy, and the charity may only discover it when the takings do not match the foot traffic — or when a donor calls to ask why their card was charged twice.

The second feature article, "Malware: Silent predators of cyberspace", covers a related trend the NCSC observed this quarter: an increase in reports where victims were persuaded to install malicious software themselves. That pattern travels well into volunteer environments, where the person managing the database is often the person who is most willing to help and least likely to have had security training.

The Gap Between an Incident and a Claim

A fraudulent donation code is an unpleasant discovery, but the loss to the organisation is often modest — the money never reached the charity's account in the first place. The exposures that carry real financial consequence sit elsewhere, and they are the ones most community organisations have not priced.

The first is the Privacy Act 2020 obligation. If credentials harvested through a phishing email give someone access to a supporter database, a client management system, or a shared drive holding case notes, the organisation has a notifiable privacy breach if the breach has caused or is likely to cause serious harm. That triggers notification to the Office of the Privacy Commissioner and to affected individuals. Working out who was affected, what was accessed, and what must be disclosed requires forensic investigation, and that investigation is not something a volunteer treasurer can run.

The second is business interruption in the non-commercial sense. A ransomware event or a locked-out finance system does not stop a charity earning revenue in the way it stops a retailer, but it does stop grant reporting, payroll, rostering, and service delivery. Organisations working with vulnerable people cannot simply pause for three weeks while systems are rebuilt.

The third is funds transfer fraud. Where a compromised email account is used to redirect a supplier payment or a grant disbursement, the money leaves the account legitimately, on the organisation's own authority. Whether that loss is recoverable depends on whether the policy in question is a cyber policy, a crime or fidelity policy, or neither.

What Cyber Cover Does and Does Not Reach

A cyber liability policy for a not-for-profit typically funds the response rather than reimbursing the theft. Expect incident response and forensic investigation costs, legal advice on notification obligations, the cost of notifying affected individuals, system restoration and data recovery, defence costs for regulatory investigation, and in most wordings, cover for extortion demands and the specialists who negotiate them.

What it usually does not do is replace money taken from a bank account. That sits with crime or fidelity cover, and the two policies are frequently held by different organisations or not held at all. Trustee liability cover is a third distinct thing again: it responds to claims against individual board members arising from governance decisions, which may include a claim that the board failed to manage a foreseeable risk, but it does not restore the funds or fund the breach response.

Most claims of this kind touch two or three of those policies at once. The question worth putting to a broker in plain terms is: if our email is compromised, a supplier payment is redirected, and our donor list is copied, which of our policies responds to which part of that, and where are the gaps between them?

Controls That Cost Nothing

Insurers price cyber cover partly on process, so several of the steps that reduce risk also reduce premium. Multi-factor authentication on email and cloud storage is the single highest-value control and is free on every mainstream platform. Donation QR codes should be checked physically at the start and end of every event and should be generated by one named person rather than by whoever is closest to a laptop. Bank account changes for any supplier should be verified by calling a number already held on file. Access to systems should be reviewed whenever a staff member or volunteer leaves a role, which in a high-turnover volunteer environment means quarterly rather than annually.

None of this requires an IT department. It requires a board that treats digital process the way it treats cash handling.

Where to Start

If your organisation holds supporter data, takes donations electronically, or runs any part of its operations through cloud services, cyber cover belongs in the same conversation as public liability rather than as an afterthought at the end of it. Premiums for small and mid-sized community organisations are typically modest, and the response costs the policy funds are the part boards consistently underestimate.

To review your organisation's cyber and privacy exposure alongside the rest of your programme, get a quote from one of our specialist charity insurance brokers.

About the Author

Sarah Connell — the CharityInsurance crew are your friendly insurance geeks on a mission to make specialist cover simple and accessible for every NZ charity, sports club, and community organisation.

Ready to Get Protected?

Get tailored insurance options from licensed NZ brokers who specialise in charities and not-for-profits.

No obligation. Brokers we personally know and trust.