Fri. Sep 25th, 2026

CNMV Warning Database Keeps Surfacing Broker Clones and Unauthorized Investment Sites

ByJohan Shamshad

September 25, 2026 #CNMV
Spain’s securities regulator is continuing to flag unauthorized investment websites and clone firms in 2026, with its warning database offering an unusually detailed view of websites attempting to reach European investors without the regulatory status their branding may suggest.

The Comisión Nacional del Mercado de Valores, or CNMV, published another batch of directly issued warnings on September 21 covering six names and websites: Skelvurizont, Pelkruvilanz, Onkel Invest, Trilessyum, Global Mercado and BRX-Global.

The entries appear in the regulator’s database of entities that are not authorized to provide regulated investment services.

But the database is broader than Spain alone. CNMV also republishes warnings issued by foreign securities regulators, creating a searchable collection of threats identified across Europe and other jurisdictions.

That second category has become particularly useful for detecting clone firms.

Clone operations differ from ordinary unlicensed investment websites because they attempt to borrow credibility from real financial companies. A fraudulent website may copy the name of a regulated broker, investment firm or asset manager, reference a genuine registration number or use branding close enough to an authorized company that an investor assumes the two are connected.

This makes checking the exact legal entity and website particularly important. The issue is similar to the distinction highlighted by regulatory licensing records, where an authorization belongs to a specific company and approved operation rather than automatically covering every website or service associated with a broader brand.

Recent CNMV Records Show How Clone Sites Borrow Legitimate Names

CNMV’s August 31 warnings offer several direct examples.

The regulator identified ibrokergm.com and the name IBROKERGM as clones unrelated to iBroker Global Markets, S.V., S.A., a legitimate Spanish investment firm registered under number 260.

It also warned about Olympus-capitallimited.com and related Olympus Capital branding, stating that they were unrelated to the registered fund Olympus Equity Europe.

Other entries included websites using versions of the Solventis name despite having no relationship with regulated Spanish investment firm Solventis, as well as a website imitating GPB Financial Services Ltd.

The pattern demonstrates why recognizing a financial brand is not enough. A legitimate company can coexist with a fraudulent website using nearly the same name.

Investors already face a similar problem when legitimate brokerage groups operate through several companies. Dave Finances’ examination of multi-jurisdiction broker licensing showed how the same commercial brand can sit above separate regulated entities depending on where the customer lives.

Clone sites exploit that complexity. Instead of merely claiming to be regulated, they can copy details from a company that genuinely is.

Nexora.finance Warning Dates Back to January, Not September

One 2026 example worth clarifying is Nexora.finance.

CNMV’s searchable database lists www.nexora.finance as a clone, but the entry is dated January 7 rather than September 2. The underlying warning came from Luxembourg regulator CSSF.

According to the database entry, the website made fraudulent reference to Nexora SARL-S, with which it had no relationship.

The September 2 foreign-regulator warning batch contains a similarly named but separate case: www.nexusgroup.eu.com. CSSF identified that website as a clone impersonating authorized firm Nexus Global Group S.A.

Other September 2 entries included Motionasset.io, described as impersonating Finance in Motion Asset Management, along with Q-Bit and Bull-Verse.org.

The distinction illustrates one of the advantages of regulator databases over general web searches. Similar names, multiple domains and repeated use of legitimate corporate identities can make suspicious investment operations difficult to trace without checking the precise URL and warning date.

September Brought Another Wave of European Clone Warnings

The pattern continued into September.

Warnings from Luxembourg’s CSSF republished through CNMV on September 9 included websites impersonating or fraudulently referring to firms such as Clearstream Banking, European Broker S.A. Luxembourg, Hautfort Partners, Neventa Management, BVF Capital and other financial businesses.

Some clone operations used misleading websites. Others used email addresses designed to appear connected to the genuine firm.

That matters because financial authorization is becoming increasingly entity-specific. Recent cases such as Eurotrader’s loss of its Cyprus licence demonstrate that regulatory status can change even when a familiar brokerage brand continues operating elsewhere.

At the other end of the spectrum, firms can obtain new permissions as they expand into regulated activities, as seen when Deriv secured conditional Cayman regulatory approval.

For an investor, the practical question is therefore more specific than “Is this brand regulated?” It is whether the company named in the account agreement, operating the exact website being used, has authorization to provide that service in the investor’s jurisdiction.

Analysis: Clone Brokers Exploit a Weakness in How Investors Check Regulation

Clone firms work because most people verify regulation backwards.

They visit a trading website first, see a regulator’s name or licence number somewhere near the bottom of the page, and then assume the platform must have passed some regulatory test.

But copying a licence number takes seconds.

The meaningful verification runs in the opposite direction: start with the regulator’s official register and use it to identify the company, approved website and regulatory status.

That sounds like a small difference. In practice, it closes one of the easiest loopholes available to impersonators.

A clone does not need to invent an elaborate regulatory history when a real one already exists. It can copy a legitimate company name, registration number, address and legal language. It may even reproduce risk warnings normally associated with regulated CFD or FX brokers.

The scam becomes more convincing precisely because much of the information shown to the potential customer is technically real. It simply belongs to somebody else.

Local Regulatory Databases Can Surface Risks Before They Become Major Stories

The CNMV database is particularly useful because it combines domestic Spanish warnings with alerts originating from other supervisors.

That creates an early-warning stream that is easy to overlook if research is limited to English-language broker news.

A suspicious website may initially target Spanish, French, German or other European users and attract a regulator warning long before enough complaints accumulate to produce broader media coverage.

This matters in an industry where customer complaints often surface only after money has already become difficult to recover. Recent broker withdrawal complaints show how public warning signals can emerge gradually through reviews and customer reports rather than through one dramatic enforcement event.

Regulatory databases can move earlier because authorization is a binary question. A supervisor does not necessarily need to prove fraud before warning that a website is not authorized to provide investment services or is impersonating another company.

The Bigger Regulatory Story Is Moving From Products to Distribution

Regulators are also looking more closely at how online investment products reach retail customers.

Australia’s ASIC, for example, recently raised concerns about online brokers, leveraged products and trading incentives, focusing not only on whether firms hold licences but also on onboarding, promotions and whether complex products are being distributed to appropriate customers.

Clone firms sit at the extreme end of the same distribution problem. Instead of stretching the boundaries of a valid licence, they may have no valid connection to the licence at all.

That makes website-level monitoring increasingly valuable.

A broker can change domains. An unauthorized platform can disappear and reopen under another name. A clone can alter a single character in a legitimate company’s URL and immediately look more credible than a completely invented financial brand.

The CNMV database captures those details in a way broader enforcement statistics do not.

For investors and anyone monitoring the FX and CFD industry, the most useful signal may therefore be the URL rather than the company name.

A familiar name can be copied. A licence number can be copied. A corporate address can be copied.

The exact domain listed by the regulator is much harder to explain away.

That is why CNMV’s warning database is worth treating as more than a list of obvious scams. It is also a running record of how unauthorized brokers and investment websites adapt their identities, borrow regulated names and target European customers.

And because many of those warnings originate in local European supervisory channels before receiving wider coverage, the database can provide an unusually early look at the next broker or clone-firm problem before it becomes a larger industry story.

Financial Markets Analyst and Journalist at  |  More Posts

Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.

His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.

Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape.

Leave a Reply

Your email address will not be published. Required fields are marked *