Fake charities have expanded rapidly in recent years, increasingly blending humanitarian branding with coordinated digital infrastructure designed to simulate legitimacy and attract donations.
A recent investigation by Haaretz and Libération found that “ Sadaqah Palestine ,” a now- scrubbed Gaza charity, was a fabricated donation platform used for illicit fundraising and data harvesting, as well as identifying pro-Palestinian figures. The report also linked its digital infrastructure to the Israeli influence firm BlackCore , which is currently under investigation in Europe for alleged election interference.
The operation presented itself as a humanitarian fund for Palestinian families in Gaza affected by the war, complete with a website, a credit-card donation system, active X, Instagram, and accounts, and paid Meta advertising designed to simulate legitimacy and reach donors.
But there is no real organization behind it; Sadaqah Palestine is not in any United Kingdom, United States, European Union, or Israeli charity registries and has no verifiable legal status, no leadership, and no institutional footprint — only a shiny digital shell.
According to the investigation, the audience appears largely inauthentic: Of 221 followers, one-third are bots, and at least 59 percent are fake, with none verified. The follower base includes clusters of Russian-language accounts, generic Western personas, and empty bios consistent with mass-generated profiles, with engagement similarly engineered.
On X, coordinated bursts of replies came from recently created accounts, split between American-style “fitness coach” personas with motivational slogans and misspelled US locations, and Vietnamese-named accounts posting repetitive phrases like “Done helping” and “Just did my part.” Activity spiked rapidly after the launch of Saddaquah Palestine in early 2025, then collapsed, consistent with short-term bot amplification rather than organic support.
Behind the humanitarian framing, the site functioned as a digital “ honeypot ” operation, soliciting donations and capturing user data through credit card forms, without transparency, governance, or audit structure typical of legitimate nongovernmental organizations (NGOs).
The key finding is that Sadaqah Palestine and electric-marinade.com were repeatedly listed together in dozens of Let’s Encrypt certificates issued between March 2025 and March 2026.
Let’s Encrypt issues these certificates only when domains are jointly verified for encryption. The paired listing with electric-marinade.com suggests the two domains were likely managed within the same underlying infrastructure, including shared website and email systems. This is evidence of shared infrastructure, but it does not by itself prove common ownership or control.
Electric-marinade.com is part of a suspected infrastructure cluster involving tools used to generate fake identities and coordinate social media activity.
The infrastructure evidence points toward the Israeli firm BlackCore , which is under investigation by French authorities for alleged interference, targeting left-wing candidates in France’s 2026 municipal elections .
Before scrubbing its online presence, BlackCore described itself as an “elite influence, cyber and technology” firm. It now has no active public-facing website and has not publicly responded to the allegations against it.
This pattern is stark: a nonexistent humanitarian organization, artificially manufactured audiences, coordinated bot engagement, and technical links to a firm under legal scrutiny in Europe, pointing to exploitation of humanitarian trust for fundraising, data harvesting, and coordinated influence operations.
Fraudulent charity campaigns often imitate legitimate NGOs by copying names, branding, and messaging, making them hard to distinguish from real aid organizations.
Red flags include poor site quality, spelling errors, lack of financial transparency, and requests for nonstandard payments such as crypto, gift cards, or direct transfers.
Scam operators also tend to avoid clear answers how donations are used, unlike legitimate charities that provide accountability and reporting. Even formal registration can be misleading, as some deceptive operations still function under valid legal status.
Taken together, these patterns suggest such sites may not be isolated scams but part of a broader, coordinated infrastructure used for influence, deception, and data collection.
From Fortune : “There is no clear data how common nonprofit fraud is or how prevalent it is compared to corporate fraud or acts of fraud by people employed by government agencies. The Association of Certified Fraud Examiners estimates that companies and nonprofits lose approximately 5% of their annual revenue to fraud, according to a 2024 report.”
The author writes , “France’s cybersecurity agency has accused the Israeli tech company BlackCore of interfering in the Scottish elections earlier this year by targeting the first minister, John Swinney. The disinformation detection agency Viginum said BlackCore had this year used proxy social media accounts to target Swinney, the Scottish National party, and the Scottish government on four occasions. Viginum said BlackCore had focused its operations on municipal elections in France but had also targeted the mayoral elections in New York, won by Zohran Mamdani, and other countries such as Togo and Angola.”
From Le Monde : “French authorities point to the involvement of the Israeli firm BlackCore. Other companies may also have been involved, according to Le Monde ’s sources. A web of subcontractors is complicating efforts to identify the sponsor.”
From Nonprofit Pro : “When people think cyberattacks, they often picture banks, large enterprises, or government agencies as the primary targets. Yet, one of the most attacked sectors today is one many people least expect: nonprofits — particularly humanitarian organizations.”
The author writes , “This report focuses on 17 organizations that collect international zakat, reporting a total revenue of $924 million. Of that amount, $493 million does not exist; it is phantom revenue resulting from a discredited accounting tool.”
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
