The Financial Conduct Authority escalated its long-running Hargreaves Lansdown clone warning this weekend after investigators tied a burst of SMS messages to fresh domains that replay the Bristol platform’s switchboard numbers while routing victims to payment pages outside any FCA-authorised perimeter, a pattern the regulator said surfaced in 47 consumer reports between Friday night and Sunday morning.

What broke

Recipients received texts claiming “urgent portfolio reviews” required immediate bank transfers to segregated accounts. Links landed on sites that copied Hargreaves Lansdown’s colour palette and footer addresses at One College Square South, but WHOIS records show registration through privacy proxies in jurisdictions the FCA cannot seize. Call-back numbers matched numbers listed on older clone warnings—0117 230 ranges that are not on the Firm Checker entry for Hargreaves Lansdown Asset Management Limited.

Hargreaves Lansdown’s security desk told InfoHandle it never cold-calls retail clients with transfer instructions and does not ask customers to move holdings to third-party “liquidity partners.” Genuine contact routes run through 0117 900 9000 or in-app secure messaging. Several victims who spoke to our desk said fraudsters coached them to ignore Confirmation of Payee mismatch alerts by claiming HL used nominee accounts during “market volatility windows.”

What the FCA confirmed

The regulator’s weekend notice restates that the clone entity has no connection to company registration 02122142 or authorised firms carrying FRN 115248. Dealing with the clone forfeits Financial Ombudsman Service access and Financial Services Compensation Scheme protection. The FCA urged consumers to verify every contact through the Firm Checker and to call the helpline on 0800 111 6768 if numbers on marketing materials diverge from register entries—even by a single digit.

Updated clone guidance published in May 2025 reminds firms that scammers may point victims at genuine websites while supplying alternative phone lines in PDF attachments. The weekend SMS campaign used shortened URLs that redirected twice, evading some carrier spam filters that block known phishing hosts outright.

Who has the file

Action Fraud has opened a cluster reference for the SMS wave; City of London Police’s Dedicated Card and Payment Crime Unit is sharing message templates with mobile networks. The FCA’s intelligence unit is tracing payment mule accounts receiving Faster Payments from victims aged 55–72, the cohort HL’s own fraud bulletins flag as highest risk for coached transfers.

Hargreaves Lansdown said it is refreshing in-app banners and emailing customers who have not enabled two-factor authentication on withdrawals. It cannot block third-party SMS gateways but is submitting domain takedown requests through its brand-protection vendor.

What is still unknown

Investigators have not published total losses from the weekend burst. The FCA declined to name hosting providers while preservation orders are served. It is unclear whether the same group operated earlier email clones flagged in 2021 warnings or whether this is a new affiliate replaying legacy scripts during quiet market hours when help desks run skeleton crews.

Some victims reported speaking to callers with plausible knowledge of ISA allowances, suggesting data bought from unrelated breaches rather than compromise of HL systems—something the platform stresses it has not detected in its own logs.

What savers should do

Anyone contacted should hang up, open the FCA Firm Checker independently, and dial only numbers listed there. Transfers already sent should be reported to the bank within 24 hours to preserve APP reimbursement eligibility under rules in force since October 2024. HL’s security pages recommend registering accounts for its outbound-call verification service so in-app banners show when the firm is genuinely ringing.

Savers with SIPP or ISA holdings should screenshot Firm Checker results when validating callbacks, storing FRN 115248 alongside the authorised firm names Hargreaves Lansdown Asset Management Limited and Hargreaves Lansdown Savings Limited. Clone sites often list the genuine FRN beside a fake trading name; matching legal entity names matters as much as recognising the marketing brand.

Weekend timing is deliberate: fewer branch staff are available to counsel anxious investors, and social feeds amplify “market crash” narratives after Friday closes. The FCA’s reissued warning is not a new authorised-firm failure—it is a reminder that clone firms recycle trusted brands whenever attention drifts. Treat every unsolicited investment SMS as hostile until the Firm Checker proves otherwise.

Industry read-through

Platform providers told the Economic Crime and Corporate Transparency Act implementation group that SMS origin spoofing outpaces SIM farm blocks. Banks are not liable for investment scams that begin off-channel, but payee banks receiving mule inflows still face reputational heat. The practical fix remains consumer verification discipline, reinforced this weekend by a regulator willing to re-broadcast a named clone before Monday trading opens.

Wealth managers with older client bases said they are adding weekend fraud-duty rotas after noticing spike patterns mirror pension-freedom withdrawal seasons. None reported direct HL systems compromise; the attack surface remains the SMS inbox and the human reflex to obey urgent financial instructions when markets look wobbly on Sunday news apps.