The victim did check. They found a licence number on the site, searched it, and the regulator's register returned an authorised firm with a matching name. Everything lined up except one detail nobody thought to compare: the website address on the register was not the website they were on. The firm they were talking to had copied the identity of a genuine authorised business, down to the address and the company registration, and built a site around it.
That is a clone. It is the most effective form of investment fraud aimed at people who have been told to check credentials, because it survives the check.
How the operation is assembled
The parts are consistent. A real authorised firm is selected, usually one with a modest retail profile so that clients are less likely to have direct experience of it. Its entity name, registration number, licence number and registered address are lifted from the public register, which is public precisely so that people can verify. A domain is registered that reads as the real one at a glance: a different top level domain, an inserted word, a hyphen, a doubled letter. The site copies the real firm's design, or a generic broker template with the borrowed details dropped in.
Then the contact channels are replaced. New phone numbers, new email addresses on the new domain, and a messaging account for the actual conversation. This is the pivot point of the whole scheme: from the moment contact moves to the new channels, the victim is talking to people who have no connection to the licensed firm, while every credential they might check still points at the real one.
The last part is the payment instruction, and it is the part that cannot be cloned. Money must reach an account the operators control, so the beneficiary is a company nobody has heard of, or an individual, or a crypto address, and the country rarely matches the licensed entity. Some operations dress this up as a payment processor or a settlement partner. A licensed firm collecting client funds does not settle to a personal account, and the deposit page of a real broker names the licensed entity, which is why deposit verification pages exist at all.
The tells, in the order they appear
Approach first. Clones rarely wait to be found. Contact starts with an unsolicited call, a message on a social platform, an advertisement using a public figure's image without permission, or a recruitment style pitch. Nothing about the approach is verifiable, which is the intent.
Then the domain. Compare it character by character with the domain recorded on the regulator's register, and where the register does not record a domain, compare with the one the firm publishes in its filed documents. A near miss is not a coincidence.
Then the channels. Correspondence from a free email service, a phone number in a country unconnected to the licence, or a hard push to move the conversation to a messaging app immediately. Regulated firms record communications and are usually reluctant to move off channel for that reason.
Then the money. Beneficiary name that differs from the licensed entity, a bank in an unrelated country, an instruction to pay an individual, or a request to buy crypto and transfer it. Any one of these ends the conversation.
Then the behaviour after payment. A platform showing rapid gains, pressure to deposit more, and a withdrawal that requires an unexpected fee, tax or verification payment. That last pattern is a recovery demand, and paying it never releases anything.
If you believe you have paid a clone, contact your bank or payment provider immediately and report it to the regulator whose firm was impersonated and to local police. Do not pay any further fee presented as a condition of withdrawal, and be wary of anyone who contacts you afterwards offering to recover the funds for an advance payment.
Verification that actually defeats a clone
Checking the licence number is necessary and not sufficient, because the number is genuine. Three additional steps do the work.
Compare the contact details on the register with the ones you have been given, and then use the register's details rather than the site's. Call the number on the register and ask whether the account, the adviser and the domain are theirs. Real firms answer this question all day.
Search the regulator's warning list by firm name and by domain. Regulators publish clone alerts naming the impersonated firm and the fraudulent site, and a listed domain settles the matter. The full reading method is in verifying a licence on a regulator website, and the broader process in how to check a broker licence.
Compare the payment instruction with the licensed entity name. This is the check with the highest yield and the one most often skipped, because by the time it arrives the victim has already decided to proceed.
If your firm is the one being cloned
Impersonation is a brand and compliance problem, and the response is largely operational. Monitor for registered domains close to yours and for advertisements using your name and imagery. Report confirmed clones to your regulator so an alert can be published, since a published alert is the artefact your clients can find. Keep the notified website, phone number and address on your register entry current, because that entry is the reference point every careful client will use. Publish your entity name, licence details and official domains on one page and refer inbound queries to it.
Also fix the internal side. Train support to expect calls from people who are not your clients, log every report with the domain and the payment details given, and make sure your own deposit instructions always name the licensed entity, never a group company with a different name. Client facing consistency between the entity, the site and the payment descriptor is what makes an inconsistency visible, and it is the same discipline described in regulated versus unregulated brokers. Being difficult to imitate is mostly a matter of being unambiguous about who you are.
"The clone always gets the licence number right. What it cannot get right is the bank account, because the money has to end up somewhere the real firm does not control."
— Alex Onta, Executive Director, SINGUARD
Key Takeaways
- A clone uses a genuine licence number belonging to a real authorised firm, so checking the number alone does not detect it.
- The domain, the contact channels and the payment beneficiary are where the imitation breaks down.
- Use the phone number and address recorded on the regulator's register, and search its warning list by name and by domain.
- Firms being cloned should keep register contact details current and report confirmed clones so an alert is published.
Frequently Asked Questions
How can a scam site show a real licence number?
Registers are public, so entity names, registration numbers and addresses can be copied by anyone. The register exists to let people verify, and clones exploit the fact that most verification stops at the number rather than comparing domains and contact details.
What is the fastest single check against a clone?
Compare the payment instruction with the licensed entity name. Funds destined for an individual, an unrelated company or an unconnected country are not going to a licensed firm's client account, whatever the website says.
What should I do if I have already sent money?
Contact your bank or payment provider at once, since some transfers can still be recalled, and report it to the regulator of the impersonated firm and to the police. Do not pay any further amount described as a release fee or tax, and treat unsolicited recovery offers as a second fraud.
About the Author
Alex Onta is an Executive Director at SINGUARD. He built eTrader, the terminal, the mobile apps, eTrader Broker, Copytrading, Business and Community, along with the worldwide clustered-server infrastructure it all runs on, with his brother Roman Onta helping on the design, and he leads that division today. Together with Roman he builds the Prop Firm CRM, the Broker CRM, Scalegram and CopySignals, and the two of them carry worldwide compliance, payment processing and international business structuring side by side. He lives and works in Dubai for most of the year. Meet the executive duo leading Singuard's five divisions.