When the Bhotekoshi river burst its banks in Nepal's Rasuwa district on August 26, 2026, the floods killed hundreds of people and left many more missing. Within hours, the world was watching and people everywhere wanted to help. Within those same hours, scammers were already at work.
Nepal Police issued a public warning the very next day, alerting citizens that fraudsters were circulating fake QR codes, creating bogus Facebook and WhatsApp groups in the name of the "Prime Minister's Disaster Relief Fund," and calling people to harvest banking details under the cover of registering them for relief. The Kathmandu Post reported that police urged everyone to verify donation account details exclusively through the Prime Minister's Office's official website before sending a single rupee.
Nepal is not an isolated case. It is the latest chapter in a story that repeats itself after every earthquake, hurricane, wildfire, and flood on the planet.
Key fact: In 2024, the FBI's Internet Crime Complaint Center (IC3) received more than 4,500 complaints reporting approximately $96 million in losses to fraudulent charities, crowdfunding accounts, and disaster relief campaigns. (FBI IC3, January 2025)
Scammers do not wait for the dust to settle. They move faster than legitimate relief organizations, faster than journalists, and often faster than authorities. Understanding how they operate is the first step to making sure your generosity reaches the people who actually need it.
The timing of disaster fraud is not accidental. Scammers deliberately exploit the window immediately after a catastrophe, when public emotion is highest, news coverage is saturated with images of suffering, and people feel compelled to act fast. That urgency is the weapon.
This pattern has been documented across decades of disasters:
Hurricane Katrina (2005)
When Katrina devastated the Gulf Coast, fraudsters flooded inboxes with emails soliciting donations for fake charities with names deliberately similar to legitimate organizations like the American Red Cross. The U.S. Department of Justice's National Center for Disaster Fraud was established partly in response to the explosion of Katrina-related charity fraud, which included bogus telephone solicitations, fake websites, and impersonation of official relief funds.
The COVID-19 Pandemic (2020-2021)
The pandemic demonstrated that "disaster" does not have to mean a flood or earthquake. As billions of people sought information and relief, scammers launched fake vaccine registration sites, fraudulent WHO donation pages, and phishing campaigns impersonating national health agencies. The same playbook, applied globally.
Hurricanes Helene and Milton (2025)
Following two major Atlantic hurricanes in 2025, fake charities stole an estimated $34 million from donors. The Florida Attorney General took action against 23 fraudulent relief organizations, leading to 8 arrests and the shutdown of 15 fake websites. Charity scams surged by an estimated 400% in the weeks after the storms struck.
Nepal Bhotekoshi Floods (August 2026)
Within 24 hours of the flooding that killed at least 359 people, Nepal Police were already warning the public about fake QR codes, impersonation of the Prime Minister's Relief Fund on social media, and phone calls designed to steal one-time passwords and banking credentials.
The common thread across all of these events: scammers register new domain names, spin up convincing social media pages, and begin soliciting donations before legitimate relief operations have even fully mobilized.
The mechanics are consistent enough that the FTC and FBI have both issued guidance on exactly what to expect. Knowing the specific tactics makes them far easier to spot.
Fake Charity Websites and Copycat Names
Fraudsters register domain names that include the disaster's name or location within hours of a major event. They build websites using stock images and stolen news photos, mimic the branding of legitimate organizations, and set up payment processors that route funds directly to their own accounts. The site typically disappears within a few weeks, long after the money is gone.
Copycat naming is a deliberate strategy. A donor searching for "Red Cross flood relief" might encounter "Red Cross Flood Relief Fund" or "American Red Relief," close enough to look legitimate at a glance.
Fake QR Codes and Social Media Fundraisers
As Nepal Police specifically warned, scammers copy the logos and formatting of official government agencies to create convincing QR codes that redirect to fraudulent payment pages. These spread rapidly on Facebook, WhatsApp, TikTok, Instagram, and Viber, shared by well-meaning people who have no idea the code is fake.
Social media fundraisers are particularly dangerous because platforms like GoFundMe allow anyone to create a campaign with minimal verification. Scammers create campaigns with emotional photos and compelling stories, sometimes fabricating personal accounts of being a disaster survivor.
Impersonation Calls and Phishing Messages
Phone-based scams involve callers claiming to represent official relief funds, asking victims to "register" for assistance or verify their identity by providing banking details, PINs, or one-time passwords. The FBI has specifically warned that scammers may also impersonate celebrities, influencers, or high-profile disaster victims to solicit donations.
Phishing links sent via SMS or email direct recipients to fake donation portals designed to harvest payment credentials.
The "Urgent Family Member" Scam
Nepal Police flagged a particularly manipulative variant: messages from unknown numbers claiming that a family member is safe after the disaster but urgently needs money. The emotional relief of hearing a loved one survived, combined with the manufactured urgency, makes this one of the most effective psychological traps in the scammer's toolkit.
Fake charity website: Spreads through search engines, social media, ads, and phishing links. Scammers want donations, payment details, or personal information.
Copycat QR code: Shared through WhatsApp, Facebook, TikTok, Instagram, and Viber. Scammers use them to collect donations or steal payment and banking information.
Phishing email/SMS: Sent through mass emails, text messages, or social media. The goal is to steal banking details, passwords, or OTPs.
Fake social fundraiser: Promoted through shared posts, fake pages, groups, and impersonation accounts. Scammers seek direct donations or payment information.
Impersonation call: Made through phone calls, WhatsApp, or other voice services. Scammers may ask for banking details, PINs, or OTPs.
Fake family emergency message: Sent through SMS, WhatsApp, or messaging apps. Scammers claim a family member needs urgent help and request money or a financial transfer.
Most donation scams share recognizable warning signs. The challenge is that in the immediate aftermath of a disaster, people are emotionally primed to act quickly rather than pause and verify. That is exactly what scammers rely on.
Watch for these warning signs before you donate:
The organization appeared after the disaster. Legitimate relief charities exist before disasters happen. If a charity or fundraising page was created in the days immediately following a specific event, treat it with significant skepticism.
Pressure to donate immediately. Urgency is a manipulation tactic. Genuine charities do not set countdown timers or insist you must give "right now." As the FTC advises, legitimate charities do not pressure you to act fast.
Requests for payment via gift cards, wire transfer, or cryptocurrency. These payment methods are untraceable and irreversible. No legitimate charity requires them. This is one of the clearest signals of a scam.
The charity name is suspiciously similar to a well-known organization. Slight variations in spelling or the addition of words like "Fund," "Relief," or "International" are classic copycat tactics.
The website was recently registered. A domain registered within days of a disaster, even if it looks professional, is a major red flag. You can check a website's registration date and trustworthiness using ScamAdviser's free website checker.
No verifiable contact information or registered address. Legitimate charities have physical addresses, registered charity numbers, and verifiable contact details.
QR codes or links shared by unknown accounts. Never scan a QR code or click a donation link shared by someone you do not know, especially on social media during a disaster.
Requests for your banking PIN, OTP, or password. No charity needs this information to accept a donation. Anyone asking for it is attempting fraud.
"Don't assume charity messages posted on social media are legitimate. And when texting to donate, confirm the number on the charity's official website." — Federal Trade Commission
This problem extends well beyond natural disasters. ScamAdviser has previously documented how donation scams exploited the war in Ukraine, where fraudsters created fake fundraising pages mimicking legitimate aid organizations within days of the conflict beginning. The same pattern appeared during the Thailand earthquake and numerous other crises, as covered in ScamAdviser's A-Z guide to scams.
The answer is not to stop donating. Disaster relief depends on public generosity, and the vast majority of established organizations do extraordinary work with the funds they receive. The goal is to make sure your money actually gets there.
Verify Before You Give
Disaster scams succeed because they exploit one of the best impulses people have: the desire to help. Scammers understand this, and they count on the combination of emotional urgency and limited information to bypass critical thinking.
The core defense is simple: slow down by 60 seconds. Check the website. Verify the organization exists. Donate through an official channel you found yourself, not one that found you.
Every dollar that reaches a legitimate relief organization makes a real difference to real people. Every dollar that goes to a scammer is stolen twice: once from the donor, and once from the disaster victims who needed it.
Before you donate to any charity or relief fund, check the website at ScamAdviser.com. If something looks wrong, report it so others can be warned too.
Adam Collins is a cybersecurity researcher at ScamAdviser who operates under a pseudonym for privacy and security. With over four years on the digital frontlines, he specialises in translating complex threats into actionable advice. His mission: exposing red flags so you can navigate the web with confidence.