06/18/2026
Nonprofit Executive Directors and Operations Leaders โ your website doesn't need to be famous to be a target for automated attacks.
It just needs to exist and have one unprotected opening.
We recently updated three form endpoints on a client's web application. Two got locked down immediately. We forgot the third.
Within hours, bots were hammering it โ not because anyone shared the link, but because bots scan methodically until they find something that doesn't push back.
Here's what your team should be able to answer this week:
๐น Do we have rate limiting or traffic filtering in place โ and is it applied to every URL, including new ones?
๐น When a new page or form is launched, is there a checklist to confirm protections are applied before it goes live?
๐น Are our donation pages and member portals protected against high-volume automated requests?
๐น When was the last time someone reviewed our traffic logs for unusual patterns?
These are reasonable questions for any executive to ask. If the answers are vague, that's worth a follow-up conversation.
Full post โ including what to ask your tech team โ on the Coat Rack blog. Link in comments.
What does your team's process look like when new digital features are launched? I'd love to hear how others are handling this.
AI-driven bots are hitting nonprofit websites right now. Here's what happened on Coat Rack's watch, and what nonprofit leaders should ask their tech teams this week.