
Texts and calls
The flood relief text that isn’t relief
Updated 6 October 2026
You read the headline, you feel the pull, and within sixty seconds your card is in a checkout page run by people who have never met a flood victim. That is the whole game, and the pull is the point.
How the post-flood donation text is built
Within hours of a real flood, real wildfire, real tornado, real hurricane, or a real earthquake, two things happen. Aid groups publish appeals asking for money. Scammers publish almost identical appeals asking for the same money, only routed to a wallet they control. The reason the scam version works is that it rides the news cycle at the moment your guard is lowest. You are not browsing. You are reacting. That reaction is the product.
The pitch itself is short on purpose. A typical text reads something like TX FLOOD RELIEF: text RELIEF21 to 20222 to donate $10 to victims in Kerr County, or HELP WILDFIRE FAMILIES text YES to 70007, $5 added to your bill, or a one-liner with a link that promises 100% goes to displaced families in [town]. The donor thinks the keyword billing trick is the official route because they have seen it on real charity drives. It is a real route. It is also a route that has been spoofed in every major US disaster since at least 2010, and a quick search of the FCC’s informal consumer complaint database will show fresh keyword-billing complaints filed within days of every named storm of the last two hurricane seasons.
The mechanics vary. The most common variant is a keyword billing number: you text a short word or code to a five or six digit short code, you agree to a recurring charge of $5, $10, or $20 added to your mobile bill, and the operator takes a cut that can be more than half. Legitimate campaigns exist, but the scam version simply registers a lookalike charity, sometimes a real one, and pockets the margin. A second variant is a link to a donation page that looks like GoFundMe, a familiar relief brand, or a press-release style microsite. The page collects card details and a billing zip, then either charges a one-off, opens a recurring subscription, or harvests the card for resale. A third variant is a QR code on a flyer taped to a lamppost near a flood zone, a wildfire evacuation centre, or a collection point. The QR leads to the same fake checkout. A fourth is an AI voice call that spoofs the caller ID of a known charity and asks you to confirm a card number you already used for a real donation months ago.
What ties them together is urgency. The text does not give you time to think. It does not give you a phone number you can call back. It does not give you a charity name you can verify. It gives you a feeling, then a path, and the path is the trap.

The law, the fees, and who actually moves the money
Charity solicitation in the United States is regulated state by state, not federally. The Federal Trade Commission and the IRS set the rules for what a charity can call itself and what it must disclose on its 990 filings. The individual state, usually through the attorney general’s office or a dedicated charities bureau, registers fundraisers and enforces the prohibition on fraudulent solicitations. In 2024 and 2025, the attorneys general of Texas, Florida, North Carolina, and California each opened public actions against disaster-relief keyword billing operators, and at least one FTC settlement in 2025 specifically barred a defendant from running any future short-code donation campaigns after the FTC alleged more than $110 million in consumer charges routed to entities unrelated to the named cause.
For the consumer, two things matter. First, under the Telephone Consumer Protection Act and the FCC’s 2024 rules on robocalls and robotexts, you have the right to revoke consent for any text charge at any time, and any reply containing the word STOP must be honoured. Second, keyword billing charges that you did not knowingly authorise are disputable as unauthorised charges with your mobile carrier, and a growing number of carriers will refund a first-time keyword billing charge as a goodwill credit if you ask within 30 days. The dispute pathway is stronger if you keep the original text, the short code, and a screenshot of the confirmation page you never visited. The same is true of any card charge that lands in your statement under a merchant name you do not recognise.
For keyword billing specifically, the CTIA, the wireless industry trade group, maintains a Common Short Code Administration registry, and any legitimate short code used for charity must be tied to a registered campaign with a clearly identified cause. If a text asks you to send a keyword to a short code and the reply confirmation does not name the cause, the registered nonprofit, the per-message charge, the per-month charge cap, and a customer support number, that is not a compliant campaign. It is a campaign that has not been through the registry process, which is the legal pathway. Reporting the short code to the CTIA and to your state attorney general creates a paper trail that helps the next consumer.
The Federal Communications Commission also operates a 7726 spam reporting short code that is the same on every major US carrier. Forwarding the offending text to 7726, with the sender number intact, sends the message to the carrier’s internal fraud team and to a shared database. It is one of the few consumer actions that genuinely moves at carrier speed.
How to verify a disaster appeal without feeding the scam
Verification is not a single step. It is a small ritual that costs you two minutes and saves you a charge you cannot easily undo. The ritual works in any order.
1. Ignore the link and the keyword entirely. Do not tap. Do not text. Do not scan. Open a fresh browser tab and type the name of the charity you think you are donating to, plus the word donate. If the cause is real, the real charity will appear in the first three results and the URL will be the charity’s own domain, not a lookalike. Charity Navigator and the IRS Tax Exempt Organization Search are the two fastest ways to confirm that a charity exists, that it is registered in your state, and that it actually deploys money to the disaster you are seeing in the news.
2. Search the exact short code. If the pitch is a keyword billing text, copy the five or six digit number and paste it into a search engine with the word scam. Short codes are reused over time, and complaints about a code tend to cluster quickly. A clean result is reassuring. A long list of complaints filed in the last 30 days is a stop sign.
3. Look up the cause on a recognised aggregator. After a named storm, the National Voluntary Organizations Active in Disaster publishes a list of vetted member organisations accepting donations for the specific event. Independent journalism outfits, including the local newspaper covering the affected county, will publish a list within 48 hours. Use those lists as your source of truth, not the text.
4. Check the state charity registry. Every US state that regulates charitable solicitation maintains a public search. A 30 second search by charity name will show the registration status, the principal officer, the registered address, and whether the charity has ever been the subject of an enforcement action. If the cause named in the text does not appear in your state’s registry, you have your answer.
5. Be wary of new domains. Disaster relief scam sites are typically registered in the days after the event and live for weeks. A whois lookup is not a normal consumer task, but a glance at the URL itself is. If the domain is brand new, hyphenated, contains the disaster name plus a generic word like aid, relief, help, or fund, treat it as suspect. Real charities use their existing brand domain. They do not stand up a new site for a single event.
6. Pay in a way that gives you a dispute path. A credit card gives you chargeback rights. A debit card does, but with weaker protections. A wire transfer, a gift card, a cryptocurrency transfer, or a payment app Friends and Family payment gives you almost none. Any disaster appeal that pushes you toward gift cards or crypto is not a charity, it is a fraud.
If you already texted the keyword, scanned the QR, or paid
The window for a clean reversal is short, so move on the same day. The exact steps depend on the rail you used, and the rail matters more than the amount.
If you texted a keyword to a short code and got back a confirmation that $10 or $20 will be added to your phone bill, reply STOP to that short code immediately. The carrier is required to honour it. Then call your carrier’s customer service line, ask for the keyword billing charge to be removed as unauthorised, and request a goodwill credit for the first charge. Document the call. If the charge has already posted to your bill, dispute it as an unauthorised third party charge. Carriers treat keyword billing disputes seriously when the consumer is the second or third person to complain about the same short code in a given month.
If you tapped the link and entered a card, call the number on the back of your card right now and ask the issuer to open a fraud claim, freeze the card, and issue a replacement. Do this before you email the merchant, before you try to log in to the donation site, and before you fill in any form on the scam site that promises a refund. The card issuer’s fraud team is the only party with the authority and the incentive to actually reverse the money. A chargeback filed within 60 days of the statement on which the charge appears is well within federal Regulation Z protections for credit cards and within the network rules for debit cards.
If you paid by gift card, the recovery path is narrow but real. Every major US gift card brand, including Amazon, Target, Walmart, and Visa or Mastercard branded open loop gift cards, maintains a fraud hotline. The receipt or the email confirmation contains the card number and the transaction ID. If the card has not yet been drained, the issuer can freeze the remaining balance. If the card has been drained, the issuer can sometimes tag the receiving account so that a future reload on the same stolen number triggers a hold. Do not assume the balance is gone forever just because the scammer said it was.
If you paid by crypto, the same principle applies but the rails are different. Most major exchanges and most US-based wallet providers will flag a wallet address that has been the subject of a law enforcement request. Filing a report with the FBI’s Internet Crime Complaint Center creates that paper trail. Reporting the wallet address to the exchange the scammer used to cash out gives the exchange a reason to hold the funds at withdrawal. Recovery is not guaranteed, but the gap between reporting and not reporting is the difference between zero chance and a small chance.
After you have stopped the immediate bleed, file three reports. One to the FTC at reportfraud.ftc.gov. One to your state attorney general’s consumer protection office, which is also where charity fraud is enforced. One to the FCC at consumercomplaints.fcc.gov for the unwanted text itself. The reports are short. The cumulative effect across thousands of identical complaints is what triggers the enforcement actions that eventually shut the operation down.
What a legitimate disaster appeal actually looks like
Knowing the real version of the pitch makes the fake one easier to spot. After a named event, the major US disaster relief organisations publish an appeal on their existing branded domain. The American Red Cross, Direct Relief, World Central Kitchen, the Salvation Army, Samaritan’s Purse, Convoy of Hope, and local community foundations all run on infrastructure that existed before the storm. They will not text you out of nowhere asking you to text a number. They will, at most, link to a donation page on their own site from a post you can verify on their own site.
Legitimate appeals will:
- Name a charity you can look up in an independent database, not just a generic phrase like flood victims.
- Provide a donation page on the charity’s primary domain, not a hyphenated lookalike.
- Accept credit cards, bank transfers, and sometimes checks. They will not ask for gift cards, crypto, or wire transfers to an individual.
- Disclose the charity’s EIN, the state of registration, and the name of the principal officer on the donation page or in the footer of the site.
- Show a history of disaster response in their public 990s that you can verify in minutes on Charity Navigator or ProPublica’s Nonprofit Explorer.
Anything that misses more than one of those checks deserves a 24 hour pause. The pause costs the disaster nothing. A disaster that has lasted 48 hours will still be a disaster in 48 more hours, and the charity that genuinely deploys money to it will still be accepting donations from the people who took the time to verify.
The bottom line on disaster relief texts
The text is not a donation opportunity. It is a conversion funnel tuned to the exact emotional state you are in after you read a headline about a flooded town. Every element of the design is built to bypass the part of your brain that would normally check a domain, look up a charity, or call your bank. The cure for that bypass is a small, repeatable ritual: do not tap, type the charity yourself, confirm on a regulator’s site, pay on a rail that lets you reverse the charge, and report the message to 7726 the FTC and the FCC. Five minutes of friction is the difference between helping a real family and funding the next round of texts.
Quick answers
- How do I report a flood relief scam text?
- Forward the text to 7726, then file a complaint at reportfraud.ftc.gov and consumercomplaints.fcc.gov. Also send a copy to your state attorney general’s consumer protection office, which is the agency that enforces charity fraud.
- Can I get a refund on a keyword billing charge?
- Often yes if you act within 30 days. Reply STOP to the short code, call your carrier, and ask for the charge to be removed as an unauthorised third party charge. Document the call and keep the original text.
- Is it ever safe to text a donation keyword?
- Only after you have independently confirmed the short code, the charity, and the campaign through the CTIA registry and a regulator’s database. If the text arrived unsolicited and the link or keyword is the only place you have seen the appeal, treat it as a scam.
- What is the safest way to donate after a disaster?
- Type the charity’s website yourself, confirm the charity through Charity Navigator or the IRS exempt organisation search, and pay by credit card so you have chargeback rights if anything goes wrong.
This is general safety information, not legal advice. Scams change. If you need an official desk: FTC ReportFraud or IC3.