THE WAPI NEWS – “ROUNDUP”
ASSOCIATIONS UNDER ‘SCAM’ ATTACK….
Can You Help With a Task? The Email Every Association Officer Will Eventually Get……
July 31, 2026
By John Withers
Managing Director, Priority International | International Support for Private Investigators | Board Member, CII & IPPIA
I recently received an email from someone claiming to be a fellow officer of an association I belong to. Short and simple. “Can you help with a task?” Within a couple of hours an identical message arrived, this time from a different free email account, again using the same officer’s real name. I didn’t pay it much attention. I’d seen it before, plenty of times, across different associations.
Almost immediately our secure association communications group filled with the same thing. Did you get this email. Someone’s trying to scam us, again. Then a few members made contact through the official address, and they too had been targeted.
It was clear the association was under attack. Again.
None of it was clever. That is the point.
I have seen versions of this across more than one of the professional bodies and member listservs I am part of. Different organisations, different names, the same method. If you hold any kind of office in a membership body, this email is coming for you eventually, if it has not already arrived.
It’s crude, and 99.99% of you will consign the email to the trash if your own filters didn’t already do it for you. But the scammer is only interested in 0.01%, those who reply, those who engage.
Why associations make such easy targets
Membership bodies are built to be found. We publish officer lists. We put committee names and email addresses on websites. We circulate AGM programmes and conference agendas months in advance. Our members connect to each other on LinkedIn and announce their roles. All of that is normal, and most of it is necessary.
It also hands an attacker a ready-made map. Who holds authority, who they might plausibly email, and what shared event or committee gives the message context. The trust that makes an association work is the same trust the attack relies on.
How the approach actually works
It rarely opens with a demand. It opens with a question.
The first message asks whether you are available or whether you have a moment. There are no links and no attachments, which is exactly why it can slip past the filters and past your own instincts. Nothing to click means nothing obvious to distrust.
If you reply, rapport is built. A short, plausible reason follows. A favour, quietly, because the sender is travelling or stuck in a meeting and cannot deal with it themselves.
Then comes the actual ask. Gift cards bought on their behalf. An urgent transfer. Login details, or confidential information about members or the organisation. And at some point the conversation is moved off email onto WhatsApp or SMS, where there is no header to inspect and no employer security sitting behind the account.
Every stage leans on something human rather than something technical. The authority of a senior name. The urgency of a request that cannot wait. The pull of reciprocity once a friendly exchange has started. The cover of confidentiality, which conveniently discourages you from checking with anyone else. And underneath all of it, the simple wish to be helpful to a colleague. None of those are flaws in you. They are the reasons the profession functions. The attack just turns them around.
This is not an association problem
It is tempting to treat this as a quirk of our world. It is not. The same pattern lands on charities, churches, schools, trade bodies, residents’ associations and any organisation run largely by volunteers who trust each other and publish their contact details.
What actually helps
The controls are not complicated, and none of them are new.
Treat any unsolicited request involving money, credentials or confidential information as suspect by default, however senior the name attached to it. Verify through a channel you already trust, a known telephone number or a direct approach through another route, never by replying to the message itself. Publish only the officer email addresses you genuinely need to. And brief new committee members about this the day they join, before they have had the chance to receive their first one cold.
The part no checklist fixes
Here is the honest bit. Every control above helps, and none of them removes the exposure, because the weak point is not the technology. It is that we cannot switch off.
In the world we now work in, there is no moment when you are safely offline. The approach can arrive anytime, when you are between tasks and half paying attention, and all it needs is one tired reply. No one is immune to this. That is precisely why it keeps coming. It does not need to work often. It needs to work once.
I value the times I switch off, the short window before bed when the devices are away, and the rare couple of days properly offline. I used to think of that as time away from the job. I have come to see it as part of it. The person who never puts the phone down does not get sharper. They become the tired officer who replies without thinking.
So, this is not really a warning about a scam. It is a reminder that the trust our associations run on is exactly what is being aimed at, that none of us are the exception, and that staying alert to it is a permanent, slightly tiring cost of the work. Worth paying. But worth naming out loud, because the people it catches are rarely careless. They are usually just busy, trusting, and briefly not looking.
If you hold office in any membership body, forward this to your committee before the email does the rounds. And if a colleague ever emails asking whether you are available, out of nowhere, take a moment and think.
Reposted by kind consent of the Author
Full Article on LinkedIn.com
Posted by: Ian (D. Withers)
www.WAPI.org
Copyright Notice: All article titles, trademarks and copyrights remain the property of their respective owners.
WAPI provides links and editorial summaries for informational purposes only.
Readers should access the original articles through the publishers’ websites or authorised services.
Disclaimer: WAPI is not the originator of this content and does not endorse or verify the accuracy of the material.
Complaints or requests for correction should be directed to the original publisher.
WAPI will review any substantiated notice of defamation and, if appropriate, remove or update the content.
