I worked for a web development firm as my first job out of college, and one of our clients was MannaRelief. We were tasked with building the part of their online presence than handled donations via check, credit card, etc.
I didn't look into their business model for a long time, but when I eventually got curious, I realized that they (well, their parent company, MannaTech) basically peddled sugar pills to the parents of children with severe disabilities, making all sorts of promises (some vague enough to pass FDA muster, and some not.)
I'm not sure what I should have done differently, but the ethical compromise I came to was donating all the money I made working for them to St. Jude's hospital - since we billed clients hourly, it was pretty easy to figure out exactly how much tainted money was in my paycheck every week.
Fuck MannaTech, and fuck MannaRelief. Feel free to read up on them and their various run-ins with the law: https://en.wikipedia.org/wiki/Mannatech
Bonus fun fact: we inherited this project from someone else, and at the time, they were storing all billing data completely unencrypted, in clear text. Their production server was some windows box somewhere, running some older version of some SQL database. I kept pushing them to upgrade this, since a) not only was it a flagrant security risk, but also b) violated their agreement with their card processor and put them at risk of not being able to accept donations at all. Naturally, "it wasn't in the budget" until they discovered that the machine had been compromised for weeks, and the entire database had been exfiltrated repeatedly. Suddenly, we had the budget to start doing things the correct way.