Fictitious-Regulator & Fake Authority Scams via Email
Scammers email official-looking letters from an invented financial authority — or a spoofed real regulator — to endorse a bogus platform or demand a "release fee" before you can withdraw funds that never existed.
Part of: Fictitious-Regulator & Fake Financial-Authority Scams
Last reviewed: 24 July 2026
Email is the natural home for the fictitious-regulator scam because it lets a fraudster assemble the entire apparatus of officialdom — letterhead, crest, reference number, licence citation, and a signed PDF — inside a single message that looks exactly like formal correspondence. Real regulators do occasionally write to the public, so a well-formatted email demanding a "compliance release tax" reads as procedure rather than fraud. The medium also hides the tell: a display name can show "Financial Conduct Authority" while the actual address is a webmail account, and a reply routes to a stranger. The distinction that dissolves the whole thing: a genuine regulator never emails you an invoice to unlock your own money.
How this scam works on email
The email usually arrives mid-crisis — you've tried to withdraw from a trading or crypto platform and a "compliance department" now writes to you. The sender's display name reads like a real authority (an invented "Financial Regulation Bureau", or a cloned regulator's exact name), but the underlying address is free webmail or a lookalike domain with an extra word or a swapped letter. The body cites a case reference, a licence number, and legal-sounding clauses, often laid over an embedded logo image so scanners can't read the text. A PDF or DOCX attachment carries the "official" letter and the payment instructions — bank details or a crypto wallet — keeping the actual demand out of the scannable email body. The reply-to differs from the from address, links point to a cloned register or "verification portal" the scammer controls, and the subject line carries a deadline. The recovery variant cold-emails prior victims pulled from leaked lists, naming the regulator and offering to claw back losses for a "processing fee".
Common red flags
- The sender's display name shows a regulator's name but the real address is webmail or a lookalike domain
- An attached PDF or letter carries the fee demand and payment details, keeping them out of the email text
- The reply-to address differs from the address the email claims to be from
- A case or reference number in the subject line pressing you to act within hours
- Links point to a 'verification portal' or register on a domain you didn't reach yourself
- Logos and letterhead arrive as embedded images rather than selectable text
- An unsolicited email from an 'authority' offering to recover money you already lost, for a fee
How to protect yourself
- Inspect the full sender address, not just the display name, and treat any webmail or lookalike domain as fraud
- Never act on payment instructions in an attached invoice or letter from an authority you haven't independently verified
- Look up the regulator through the official government site and phone the number listed there, never one in the email
- Confirm any firm, licence, or reference number on the regulator's own public register that you reached yourself
- Remember that no genuine regulator, tax office, or court emails you a fee to release or recover your own money
- Delete and report follow-up 'recovery' emails, which specifically target people who have just paid
How to report it
- Forward the email to the real regulator being impersonated and to your national anti-phishing reporting address
- Report to your national fraud service, such as reportfraud.ftc.gov in the US or Action Fraud in the UK
- Mark the message as phishing in your email client so the sender and domain are flagged to your provider
- Contact your bank, card provider, or crypto exchange about recalling or freezing any payment already sent
- Preserve the full email with headers, attachments, and links before deleting anything
Frequently asked questions
How can I tell if an email from a financial regulator is genuine?
Look past the display name to the actual sender address — a real regulator writes from its own official government domain, not webmail or a near-miss lookalike. Check the reply-to as well, since scammers often route responses elsewhere. Then verify independently: find the regulator through the official government site, confirm any firm or reference number on its public register yourself, and phone the number listed there rather than any number in the email.
The email has an official PDF letter with a crest and a case number. Doesn't that make it real?
No. Anyone can build a letterhead, paste a crest, and invent a reference number, and scammers put the fee demand and payment details inside an attachment precisely because it slips past filters that only scan the email body. A convincing crest and case number prove nothing on their own. Verify the authority and the case through the regulator's official channels, and remember that no genuine regulator emails you an invoice to unlock your own funds.
I got an email from a regulator offering to recover money I lost in an earlier scam. Is it real?
Treat it as a second scam targeting the first one's victims. Fraudsters buy and reuse lists of people who have already lost money, then email posing as a regulator, investigator, or law firm 'recovering' it for a processing or legal fee. Real regulators and police don't cold-email victims and charge to return funds. If you want your case reviewed, contact the real regulator and your national fraud service through their official sites.