How Scammers Turn Real Financial Advisers into Investment Scam Bait

Somewhere on the open web today, a real financial adviser is being impersonated. She has 26 years in the industry, a clean regulatory record, a real FINRA CRD number, and a real employer. All of that information is currently being used on a website she does not own, to defraud people she has never met.
Her name and CRD appear on the site. The site claims she works for a firm she has never worked for, at an address in a city she has never held an office in. It links to her genuine BrokerCheck page, which is real, because linking to real credentials is the point. Below the link sits a "trusted partners" strip that includes a bank that has not existed since 2008. There are testimonials from people who do not exist, with stock photos that do not always match the roles being claimed. At the bottom of the page there is a WhatsApp shortcut. The people who reach that WhatsApp number are pitched cryptocurrency contracts for a difference that will never settle in their favor.
This is the current archetype of a documented category of scam that regulators have already flagged, repeatedly. FINRA warned investors about it in December 2025; the California Department of Financial Protection and Innovation has published named-number alerts against it; and the Washington State Department of Financial Institutions issued specific guidance in February 2025. The public paper trail on this scam category is already substantial.
The interesting problem here is one of scale. How do you find these kits before they accumulate victims?
Every Kit Follows the Same Playbook
The kits share enough construction details to treat as a repeatable playbook. Take a real FINRA-registered adviser. Fabricate an alternate biography, usually swapping the real employer for a better-known brand and moving the office to a different metropolitan area. Upload three or four studio-style portraits of someone who is not the real adviser. Add generic testimonials that trade on aspiration ("realtor," "designer," "small business owner"), sometimes with photos that do not visually match the claimed profession. Put the real BrokerCheck link on the About page for credibility. Put a WhatsApp shortcut on every other page for conversion.
The end state is a wire transfer, or a crypto deposit, to an account under operator control, with no possibility of recovery. FINRA's December 2025 investor alert on social media investment group imposter scams describes this exact playbook and calls it out as a rapidly growing complaint category.
A word on WhatsApp specifically, because the platform choice matters and is worth being precise about. Threat actors gravitate to WhatsApp because that is where their target audience already is, and because encrypted messaging shields the pitch from outside observation. This is abuse of the platform, not sanctioned use. Meta actively fights this category of activity, and responds very fast to our reports.
From Domain Registration to Live Kit in Twelve Hours
The infrastructure story matters because it defines what defenders can act on. In the case we investigated most deeply, the timeline compressed into a single working day. The domain was registered at a low-cost registrar at 14:40 UTC. Testimonial imagery was edited in Adobe Photoshop CC 2019 on Windows at 16:09 UTC. Portrait imagery was edited between 06:14 and 06:22 UTC the next morning. Nameservers moved to Cloudflare by 02:05 UTC on the second day. The site was live within twelve hours of registration.
Two conclusions matter for defenders. First, this is a purpose-built kit, not a compromised legitimate site whose owner should be alerted. Its operator sat at a workstation with Photoshop open and built it in one contiguous shift. Second, the twelve-hour setup window is the enforcement window. If a defender is watching for the pattern, there is time to act before the site accumulates victim traffic.
The source images on the site we examined were named following a timestamped export convention (PHOTO-YYYY-MM-DD-HH-MM-SS.jpg), consistent with a cloud backup or photo-sync service rather than original camera output. That naming tells us the photos were exported from a third-party platform at some point before landing on the operator's Photoshop workstation, and nothing more. It does not tell us who provided them, or how they were obtained originally. The woman in those photos is not the impersonated adviser. If she is a real third party, her likeness is being misused.
Reverse-Engineering the Search Problem
There are over 600,000 individuals in the FINRA BrokerCheck and SEC Investment Adviser databases. Monitoring the entire population for name-based domain impersonation, by taking each name and running passive DNS lookups on likely domain permutations, is neither practical nor efficient. Most of those name-domains, when they exist, legitimately belong to the person they refer to.
The ZeroFox Signals Research Team inverted the search. Instead of starting with the victim population, we started with the infrastructure that kits favor and worked backward to the victims. That meant compiling a candidate list from three low-cost signals: cheap-registrar new registrations, cheap-hosting IP ranges, and cheap-mail customer sets. Cheap because kit economics are thin. Kits do not use premium infrastructure.
For each candidate domain, we ran a three-stage filter. Stage one is a name-shape check: the domain stem must segment into two to four alphabetic tokens beginning with a recognized personal first name. Stage two is a registration-age check via RDAP (the registration information protocol that replaced WHOIS): the domain must have been registered within the last eighteen months to qualify as a fresh kit. Stage three is a strict match against BrokerCheck: the segmented tokens, concatenated and normalized, must exactly equal at least one permutation of a real registered adviser's first, middle, and last name. Only candidates that clear all three stages get flagged.
The strict-match stage matters because BrokerCheck's search endpoint matches loosely by design. We accept a candidate only when the domain stem, letter for letter, equals a concatenation of the returned adviser's first, middle, and last name. Anything less is a coincidence.
Findings from 78,000 Domains
We ran the pipeline against roughly 78,000 personal-name-shape candidates drawn from three separate infrastructure sources: a large European shared-hosting provider's customer base, Cloudflare Email Routing's 2025+ customer base, and a broader hosting range that included our original case. About 97 percent were filtered out at the name-shape stage because their segmentations did not begin with a recognized first name. Another one percent were dropped because their domain registration predated 2025. Roughly 100 candidates cleared all three stages and were queried against BrokerCheck.
Twelve produced strict matches, and the twelve fell into three distinct categories.
The first category is the full website kit, of the kind we started this investigation on. Registered at a low-cost registrar, WordPress and Elementor running on cheap shared hosting, fronted by Cloudflare, with a real MX record delivering to the operator, and with active site content that includes the fabricated biography, the stock testimonial photos, and the WhatsApp funnel. The case that opened this post fits this profile. It is the highest-effort variant and the one most likely to convert a search-engine visitor into a fraud victim.
The second category is the email-only impersonation setup, and we did not expect to find it here. Two of the twelve matched active advisers at major banks, both were registered at Cloudflare Registrar, both configured Cloudflare Email Routing on unusual top-level domains, and neither served an A record at the apex. There is no website. There is only the domain and the mail plumbing. The operational read is that the domain exists to send outbound messages that look like they come from the real adviser, with a lookalike email address on a domain that visually reads as their personal site. Cloudflare Email Routing is free, receiving mail at the domain lets the operator reply to whoever engages, and a registered adviser's name plus a real firm plus a plausible email address is a working phishing lure on its own. This variant is cheaper to run than a website kit and harder for a victim to sanity-check, because there is no page to visit that would raise a flag.
The third category is the same-name collision. Several matches were domains legitimately owned by a different person with the same name, sometimes in a different country. One in that group was a Portuguese-language wealth-consulting site run by a Brazilian adviser who happens to share a name with a US LPL Financial representative. Both people are real, and neither is impersonating the other.
Why This Post Does Not Name Names
Every strict match in the pipeline traces back to a real financial adviser. Many of them probably do not know they are being impersonated. Publishing the specific domains alongside a blog post that will be indexed by search engines would push those scam sites higher in results for the impersonated adviser's own name. That is the exact opposite of what a victim of impersonation needs. It re-victimizes the person the operator was already exploiting.
We send indicators to the registrar of the domain in question, because that is the fastest disruption path. The reference case is already in enforcement. If you are an impersonated adviser or a firm's brand protection or compliance team and you believe you have a case that matches this pattern, get in touch and we will hand off what we have. Public disclosure comes after takedown, not before it.
The Common-Name Problem Is the Hard Problem
The methodology works cleanly on distinctive three-token names and struggles on common two-token combinations. There are dozens of people named John Smith in BrokerCheck, and a domain matching one of them is more likely to be a legitimate personal site than an impersonation. At that end of the distribution, only a browser visit to the actual site tells you what it really is.
Insight for Financial Brand and Fraud Teams
There are three main takeaways here.
First, regulators have already documented this scam category. FINRA warned investors about the exact pattern in a December 2025 alert. The California DFPI has published named consumer alerts naming specific WhatsApp numbers used by imposter accounts posing as real registered advisers. The Washington State DFI issued similar guidance in February 2025. A referral to the impersonated adviser's home-state securities regulator lands in a workflow those bodies have already documented.
Second, the fastest disruption vector is the registrar-side. A domain has to live somewhere, and reputable registrars enforce against impersonation and financial fraud content when they get a well-packaged submission. For a website kit the evidence bundle is the real CRD, the fabricated employer claim, screenshots of the conversion funnel, and passive DNS evidence of the setup timeline. For an email-only setup the bundle looks different: the real CRD, the fabricated employer, evidence that the MX is configured but no site is being served, and any captured messages sent from the domain if a target reports them.
Third, the infrastructure signature is stable enough to monitor for. Fresh registrations at ultra-cheap registrars, on Cloudflare with Cloudflare Email Routing configured, with no other legitimate content history, and matching an active adviser's name to strict concatenation, is a narrow enough combination that a small analyst team can review the daily output. The signal is present. It just requires the right filter chain to surface it, and human hand-review at the end to separate real impersonation from same-name collision.
If your firm has registered financial advisers being impersonated in this way, we would like to hear about it. Every additional confirmed case sharpens the picture. Reach out to us at [email protected].
Carlos Alvarez
Director, Disruption Partnership Program | Signals Research Program
Carlos is Director of ZeroFox's Disruption Partnerships and Signals Research Programs, where he leads threat intelligence research and coordinates abuse mitigation efforts across domain registrars, hosting providers, and social media platforms. With over 25 years of experience in cybersecurity, internet governance, and intellectual property enforcement, his career began in Bogotá leading software anti-piracy initiatives led by the Business Software Alliance and serving as Head of Legal for Sony Music's Andean region. He then spent nearly 15 years at ICANN, where he led Contractual Compliance Teams enforcing the rules on domain registrars and top level domains globally, before joining the Security Team, where he worked directly with global law enforcement, threat intelligence providers, and incident response teams on domain abuse and infrastructure threats.
Carlos currently sits on the Board of Directors for the Forum of Incident Response and Security Teams (FIRST) and the Internet Fire Brigade Society, and serves as a Strategic Advisor to the Global Cyber Alliance. He co-founded the Anti-Phishing and DNS Abuse Special Interest Groups at the Malware, Messaging and Mobile Anti-Abuse Working Group (M3AAWG), where he remains co-chair, and the DNS Abuse SIG at the Forum of Incident Response and Security Teams (FIRST). His background across the legal, regulatory, and technical sectors allows him to bridge the gap between policy and real-world threat mitigation.
Tags: Domain Protection, Impersonations