Fake brokers and clone firms: checking a licence
A clone firm copies a real broker's licence number, address and staff names — which is why checking that the number exists is exactly the wrong test.
How this page was made: AI-drafted and published after automated format, contract and source-link checks by Beez Automated Validation, Automated checks only — no human review on . Human editorial and specialist review has not yet been completed.
The specific trick a clone firm plays
There is a category of investment fraud that defeats careful people, and it defeats them precisely because they were careful. It is called the clone firm.
Here is what happens. A genuine, properly authorised investment firm exists. It has a real licence, a real registration number, a real registered address and real named directors. All of this information is public, because regulators publish it deliberately so that consumers can check.
A fraudster copies all of it.
They register a domain that differs from the real one by a hyphen, a letter, or a top-level suffix. They build a site using the real firm's branding, the real firm's licence number, the real firm's address and often the real names of its employees. Then they contact you, and when you do the sensible thing — search the licence number — you find it is genuine. The register confirms an authorised firm. The number matches. The address matches.
You have just verified the wrong entity. The licence you found belongs to a real firm that has no idea this is happening and will never see your money.
Confirming that a licence number exists proves that some firm is authorised. It proves nothing whatsoever about the firm that is talking to you.
This article explains the difference and gives you a method that closes the gap. It is educational only and is not advice about any particular firm.
Why the intuitive check fails
The instinct most people follow is: take the details the firm gave me, and check whether they are real. Call this the forward lookup. It runs from the firm outward.
The forward lookup fails against clone firms for a structural reason. Every piece of information you are checking came from the party you are trying to verify. If that party is dishonest, they supplied you with details chosen specifically because those details check out. You are not testing them. You are testing a real firm they nominated on your behalf.
The fix is to reverse the direction of travel. Start at the regulator. Find the authorised entity in the official register. Then take the contact details **from the register** and use those to reach the firm. Call this the reverse lookup.
The reverse lookup works because it never trusts anything the counterparty gave you. The website address, the phone number, the email domain and the bank account details all come from the official source instead. If the entity contacting you is a clone, this immediately produces a mismatch: the register's phone number reaches a firm that has never heard of your account, and the register's website is not the one you were sent to.
Everything below is an elaboration of that single reversal.
The seven-step verification method
Run these in order. The order matters, because each step assumes the previous one passed.
Step 1: Establish which regulator should apply
Financial activity is licensed by activity and by jurisdiction, not by ambition. Before checking a register you need to know which register.
Ask what the firm is actually doing:
- Taking deposits, running payment services or currency exchange generally falls under central banking supervision.Sourcesource
- Dealing in securities, brokerage, investment management or promoting investment funds generally falls under securities regulation.Sourcesource
- Some jurisdictions have distinct financial free-zone regimes with their own separate authorities and their own separate registers.
A firm that describes itself vaguely — "a global fintech and wealth platform" — has often chosen that vagueness so you cannot tell which register to search. Treat definitional fog as a finding, not a formatting problem.
Step 2: Reach the register yourself, from scratch
Type the regulator's address directly, or reach it via a search engine and confirm you are on an official domain. Do not click a link supplied by the firm, do not use a QR code from a document, and do not use a link from a chat message.
This step exists because the most efficient clone attack is not a fake licence — it is a fake register. A convincing lookalike of a regulator's search page, reached through a link the fraudster controls, will confirm anything they want it to confirm.
Step 3: Search by name, not by number
Search the legal entity name. Then search the number separately and see whether the two point at the same record.
Clone firms routinely supply a genuine number attached to a slightly different name. Searching only the number hides the mismatch, because the register will happily return the genuine record. Searching the name exposes it, because the name they use will either be absent or will return an entity whose registration number is not the one you were given.
Step 4: Match four fields, not one
This is the core check. Compare four things between what the firm told you and what the register says:
- **Exact legal name.** Not the brand, the trading style or the app name. Look for extra or missing words, a different suffix, or a plural. "Meridian Capital Partners Limited" and "Meridian Capital Partners LLC" are different companies.
- **Licence or registration number.** Digit for digit.
- **Permitted activities.** Registers state what the firm may do. A firm licensed to advise may not be permitted to hold client money. A firm licensed for corporate services is not licensed to run an investment platform.
- **Registered contact details.** Website domain, registered address, and any published telephone number or email domain.
A clone will typically match on two or three and fail on the fourth. The domain is the usual failure point, because they cannot use the real firm's actual website — that is where the real firm lives.
If any field mismatches, stop. Do not accept an explanation for the mismatch from the firm. Explanations are cheap and this is the exact moment the fraud must be persuasive.
Step 5: Contact the firm using the register's details
Call the number the regulator publishes. Email the domain the regulator publishes. Then ask a simple question: does an account exist in my name, and is the person who contacted me an employee?
This step is what converts a paperwork exercise into a real verification, and it is the step most people skip. It also does something valuable beyond your own protection — genuine firms generally want to know they are being cloned.
Be alert to a countermeasure. Some operations pre-empt this step by telling you the published number is "an old head office line", or by giving you a "direct line for private clients". Any instruction that steers you away from officially published contact details is itself the finding.
Step 6: Check warning lists, in more than one place
Regulators publish alerts naming firms operating without authorisation and firms known to be cloning authorised entities. Securities regulators additionally contribute to cross-border alert portals, so a firm targeting you from another country may already be named somewhere you would not have thought to look.Sourcesource
Two cautions:
- **Absence is weak evidence.** New clone sites appear faster than any list updates, and a clone that has existed for three weeks will be on no list at all.
- **Presence is strong evidence.** A named entity, or a named lookalike domain, is a hard stop.
Search the domain as well as the company name. Alerts frequently list the URL, because the URL is the part the fraudster cannot borrow.
Step 7: Check where the money is going
The final and often most decisive check happens at the payment stage, and it does not require any register at all.
Compare the payee on the payment instruction to the legal entity you verified. Ask:
- Is the account in the exact legal name of the authorised firm?
- Is it in the jurisdiction you would expect for that firm?
- Is it a business account, or a personal name?
- Are you being asked to pay a third-party "payment processor", "settlement agent" or intermediary?
- Are you being asked to send crypto to a wallet address rather than to a bank account?
A genuine authorised firm collecting client money in its own name is the normal case. A payment routed to a personal account, an unrelated company, or a wallet, is a structural break between the entity you checked and the entity receiving your funds. That break is where almost all recoverable money is lost.
Note that this check catches even a firm that is genuinely licensed. Real licences have been used as cover while payments were routed elsewhere.
A worked example
Suppose you are contacted about a fixed-return note. The material names "Aldbridge Wealth Management" and gives a licence number. The website is aldbridge-wealth.com. The address is a real tower in a real financial district. The brochure is excellent.
Run the method.
**Step 3:** You search the licence number on the regulator's site. It returns an authorised firm. Encouraging. You then search the name and find the authorised entity is "Aldbridge Wealth Management Ltd", registered at that address — good so far.
**Step 4:** You compare the four fields. Name matches. Number matches. Address matches. Then you check the website field on the register and it reads aldbridgewealth.ae. The site you were sent to is aldbridge-wealth.com. One hyphen and one suffix apart.
That single mismatch is the entire case. Everything else was copied.
**Step 5:** You call the number on the register. The real firm confirms no account exists in your name, no employee by that name works there, and they are aware of the cloned domain.
**Step 7 (had you continued):** The payment instruction would have named a payment processor in a third country, not Aldbridge Wealth Management Ltd — a second, independent break that would have caught the same fraud on its own.
Total time: perhaps twenty minutes. Note that the fraud passed every check except the two that used information the fraudster did not control.
Signals that appear before you check anything
Verification is the reliable method, but some patterns are strong enough to trigger it early. None is proof on its own.
- **Inbound contact about a specific product.** Cold approaches offering a defined return are the dominant delivery mechanism for this category.
- **Returns described as fixed, guaranteed, capital-protected or risk-free** in the same breath as an attractive percentage. Return and risk do not decouple because a brochure says so.
- **Time pressure.** A closing allocation, a limited tranche, a price that expires. Urgency exists to prevent step 2.
- **Payment instructions that change.** A second set of bank details "because the first account is undergoing an audit" is a classic escalation.
- **Discouragement of independent checks**, including advice not to tell your bank the real purpose of a transfer. A firm that coaches you on what to tell your bank has stated its own status.
- **Documents that reference a regulator without being from one.** A logo is not supervision.
- **Difficulty establishing a single legal entity.** Marketing in one country, contracting entity in a second, bank account in a third, support staff in a fourth.
The recovery-room follow-up
There is a second fraud that specifically targets people who have already lost money to the first, and it deserves naming here because it uses the same clone technique.
Weeks or months after a loss, you are contacted by someone presenting as a regulator, a law-enforcement unit, a law firm or a "fund recovery" specialist. They know real details of your loss — often because the contact list was sold, or because it is the same operation running a second pass. They offer to recover your money, for an advance fee, a legal retainer, a court filing cost or a tax payment.
Apply the same reversal. A real public authority is findable on an official domain and can be reached through officially published contact details. Verify by contacting that body independently, never through the details the caller supplied. And apply the same payment logic: a demand that money travel from you before money travels to you is the shape of the problem, not the shape of a solution.
What a licence does and does not give you
It is worth being precise, because both over-confidence and cynicism follow from vagueness here.
A licence does mean the entity has been assessed against the regulator's requirements, is subject to ongoing supervision and rules of conduct, and sits within a complaints and enforcement framework. That is genuinely valuable, and it is the difference between a bad outcome you can escalate and a bad outcome that simply happens to you.
A licence does not mean the investment is safe, that returns are assured, that the firm cannot fail, or that any loss will be reimbursed. It does not make a volatile asset less volatile. Compensation and depositor-protection arrangements vary by jurisdiction, product and firm, and they typically address firm failure rather than investment loss.
So verification protects you from a specific failure — dealing with an entity that is not who it claims to be — and from no other. Both halves of that sentence matter.
The habit worth keeping
Reduce all of this to one operating rule: **never verify a firm using information the firm gave you.**
Every step above is that rule applied at a different point. Reach the register yourself rather than through their link. Take contact details from the register rather than the brochure. Confirm the account exists by calling the published number rather than the direct line. Check the payee against the verified legal name rather than the invoice.
Clone firms are unusually good at surviving casual scrutiny, because they were built from the outputs of casual scrutiny. They survive the reverse lookup far less often, because the reverse lookup asks the one question they cannot answer: not "does this licence exist", but "does this licence belong to you".
This article is general education. It does not evaluate any specific firm, does not constitute financial or legal advice, and cannot confirm any entity's current licensing status — only where to look and in which direction to travel.
Sourcesource: Securities and Commodities Authority (UAE) — https://www.sca.gov.ae
Sourcesource: Central Bank of the UAE — https://www.centralbank.ae
Sourcesource: International Organization of Securities Commissions — https://www.iosco.org
Sources
- Securities and Commodities Authority — Securities and Commodities Authority (UAE)UAE · checked 29 July 2026
- Central Bank of the UAE — Central Bank of the UAEUAE · checked 29 July 2026
- International Organization of Securities Commissions — IOSCOInternational · checked 29 July 2026