19th August 2026
A recent UK Government press release carried a stark warning. The Charity Commission for England and Wales says charities are facing increasingly complex threats, ranging from cyber attacks and fraud to more sophisticated attempts to abuse charitable status for private gain.
For many people in Scotland, it would be easy to assume this is an English problem. After all, Scotland has its own charity regulator, its own legal system and its own charity sector.
But is that assumption safe?
The evidence suggests that while Scotland may not yet have the same headline-grabbing statistics, many of the same warning signs are already visible.
A Different Regulator, The Same Digital World as Scottish charities are regulated by the Office of the Scottish Charity Regulator (OSCR), not the Charity Commission.
That means the figures published south of the border cannot simply be copied across.
Yet charities in Caithness, Sutherland, Ross-shire or Glasgow all operate in the same online world as charities in Manchester or Birmingham. The emails arriving in trustees' inboxes do not stop at the border. Fraudsters do not check postcodes before launching phishing campaigns. Criminal gangs do not distinguish between Scottish and English bank accounts.
The risks are increasingly shared as Cyber Crime Is Growing Across Scotland
One of the clearest warning signals comes from Scotland's own cyber security data.
The Scottish Government's first Scottish Cyber Activity Report, published earlier this year, states that cyber threats to Scotland's public sector are growing and becoming more sophisticated. The report was significant because it represented the first attempt to provide a comprehensive assessment of cyber activity across Scotland's public sector.
Charities may not all be part of the public sector, but many handle sensitive information, hold financial data, process online payments and depend heavily on digital systems.
In rural areas especially, charities often rely on small teams, volunteers and trustees who are already stretched. Few have dedicated cyber security specialists. Many simply cannot afford them.
That creates vulnerabilities.
Fraud Is Becoming a Bigger Part of Crime in Scotland
The wider Scottish picture is also changing.
The latest Scottish Crime and Justice Survey found that 11.5% of adults experienced fraud or computer misuse during 2024-25, up from 9.5% the previous year. Fraud and computer misuse now account for almost half of all crime measured by the survey.
Think about that for a moment.
For decades, crime discussions focused on theft, burglary, vandalism and violence. Increasingly, the biggest threat is sitting on a smartphone, laptop or email account.
Most fraud victims never even meet the person targeting them.
The survey found that bank and credit card fraud accounted for a large share of incidents, while only a small proportion of fraud cases were reported to the police.
If ordinary households are facing these risks, charities are unlikely to be immune.
Governance Matters Too
The risks are not limited to cyber crime.
The warning from the Charity Commission in England was also about governance — making sure charities are properly managed and that trustees fulfil their responsibilities.
Scotland has seen its own examples.
OSCR continues to publish inquiry reports where concerns have been identified regarding governance and financial management. Earlier this year it reported on an inquiry into Fernhill School Ltd, stating that trustees appeared to have breached their duties and that there had been misconduct in the administration of the charity.
That does not mean Scottish charities have a widespread governance crisis.
Far from it with the vast majority of Scottish charities are run honestly and effectively by dedicated trustees and volunteers.
However, it does demonstrate that regulators are increasingly dealing with complex governance issues as charities navigate financial pressures, changing regulations and growing public scrutiny.
This issue may be especially relevant in the Highlands and Islands.
Many local charities are relatively small organisations. They often depend on volunteer trustees who already have jobs, businesses or family commitments.
A national charity may have professional finance staff, IT support and compliance teams.
A village hall committee, local community trust, sports club or heritage group often does not.
That does not mean they are poorly run. In many cases they achieve remarkable results with very limited resources.
But it does mean that one convincing email, one compromised password or one missed governance issue can potentially have a much larger impact.
The Hidden Problem is that We Don't Really Know. Perhaps the most interesting finding is not that Scottish charities are definitely facing the same level of attacks as England.
It is that we do not have a clear picture.
Scotland has information on cyber crime. It has information on fraud. It has information on charity regulation and investigations.
What it lacks is a comprehensive public dataset showing exactly how often Scottish charities are being targeted, how much money may be at risk, or whether attacks are increasing year by year.
In other words, there may be an information gap.
And information gaps can sometimes hide emerging problems.
The warning from England should not be dismissed as someone else's problem.
The rise of online fraud, cyber crime and increasingly complex governance challenges affects organisations across the UK.
Scottish charities remain one of the great strengths of civic life. They support communities, preserve local heritage, run sports clubs, provide social care and help some of the most vulnerable people in society.
But the environment around them is changing.
For trustees, volunteers and charity managers, the message is not one of panic. It is one of vigilance.
Because the next threat facing a charity in Scotland may not arrive through the front door.
It may arrive quietly, disguised as an email.