You are currently viewing Brokerage Account Fraud Is Rising: What U.S. Investors Need to Know About Protecting Their Money

Brokerage Account Fraud Is Rising: What U.S. Investors Need to Know About Protecting Their Money

  • Post author:
  • Post last modified:August 21, 2026

Sharing articles

Brokerage account fraud is becoming a more sophisticated threat for U.S. investors as criminals combine stolen personal information, phishing, account takeovers, artificial intelligence and fraudulent account-transfer requests to target investment assets.

The risk is not limited to someone guessing a password and placing an unauthorized trade. Regulators have identified schemes in which criminals use stolen identities to establish new brokerage accounts and then attempt to transfer legitimate investors’ assets into those fraudulent accounts through the Automated Customer Account Transfer Service, commonly known as ACATS. FINRA has described ACATS fraud as an emerging risk and has continued to highlight fraudulent account transfers, account takeovers and new-account fraud in its recent regulatory oversight work.

The SEC also issued updated investor alerts in April 2026 warning about identity theft, data breaches, phishing, smishing and vishing involving investment accounts. The agency specifically warned that criminals may impersonate legitimate investment firms and attempt to steal usernames, passwords, multifactor-authentication codes and other sensitive information.

For investors, the lesson is straightforward: SIPC protection is important, but it is not a substitute for account security. SIPC generally protects customers when a SIPC-member brokerage fails financially, subject to statutory limits. It does not function like insurance against every type of cybercrime, unauthorized transaction or investment loss.

Why Brokerage Account Fraud Is Becoming More Sophisticated

Modern brokerage accounts contain valuable assets and can often be accessed digitally from anywhere. That combination makes them attractive targets for criminals who obtain personal information through phishing campaigns, data breaches, social engineering, malware or other methods.

GFKJUOL

FINRA’s 2025 regulatory oversight report identified account takeovers and new-account fraud as continuing threats. It also noted that criminals are increasingly using generative AI to create synthetic identities, deepfake media and more convincing social-engineering attacks. According to FINRA, these techniques can be used to establish fraudulent brokerage accounts, take over legitimate accounts, initiate fraudulent ACATS requests and conduct other financial crimes.

The SEC’s April 2026 investor alert provides another warning sign. Fraudsters may purchase online advertisements associated with well-known investment professionals or firms and direct users to imitation websites. An investor who believes the website is legitimate may unknowingly provide login credentials or multifactor-authentication information to the criminal.

That makes the traditional advice of “use a strong password” necessary but insufficient. Investors increasingly need to protect their identity, email account, phone number, brokerage credentials and transfer instructions as one connected security system.

A compromised email account, for example, can become a gateway to a brokerage account if criminals use it to reset credentials or intercept communications. Similarly, stolen personal information can potentially be used to create a fraudulent account at another broker and then initiate an unauthorized transfer.

How ACATS Fraud Can Move Your Investments

ACATS is not itself a fraudulent system. It is a legitimate industry mechanism designed to make transfers between brokerage firms more standardized and efficient.

FINRA explains that most customer account transfers between brokerage firms occur through ACATS, an electronic transfer system developed by the National Securities Clearing Corporation. A normal transfer begins when the customer submits a Transfer Initiation Form to the receiving brokerage firm.

FXHGTJ

The problem occurs when criminals manipulate the legitimate transfer process.

FINRA has described a typical ACATS fraud scenario in which a criminal first obtains enough personal information about a legitimate investor to open a new brokerage account in that person’s name. The criminal may then submit an ACATS request to move assets from the investor’s genuine account at another brokerage into the fraudulent account. After the assets arrive, the criminal may attempt to transfer them elsewhere or liquidate securities and move the proceeds.

FINRA has also identified warning signs that firms can use to detect potentially fraudulent transfers. These include repeated rejected transfer requests, a transfer request shortly after a new account is opened, unusual changes in how the customer communicates with the firm and rapid attempts to move assets after an account transfer.

For investors, this means an account can potentially be compromised without the criminal immediately placing a suspicious stock trade.

The attacker may instead try to move the entire account.

That is why investors should pay attention to notifications about account transfers, new account openings, changes to contact information and other account-security events even when their portfolio appears unchanged.

What SIPC Protection Actually Covers

One of the most important misunderstandings investors have about brokerage security involves SIPC protection.

The Securities Investor Protection Corporation says that its role is to help protect customers when a SIPC-member brokerage firm fails financially and customer cash or securities are missing. The standard statutory protection is up to $500,000 per customer, including up to $250,000 for cash.

That does not mean an investor automatically receives $500,000 from SIPC after being hacked.

SIPC protection is primarily connected to the failure or liquidation of a qualifying brokerage firm. It is not equivalent to FDIC deposit insurance and does not protect investors from normal market losses. SIPC also does not cover every type of investment or every type of fraud.

GJGHL

There is an important nuance involving unauthorized transactions. Investor.gov explains that unauthorized transactions can raise difficult questions in SIPC proceedings and that investors should make written complaints to their broker promptly when they discover an unauthorized transaction. Documentation can become important in establishing that the investor did not authorize the activity.

SIPC also warns investors about criminals who misuse SIPC’s name. Fraudsters may falsely claim to represent SIPC, imitate legitimate financial companies or create convincing websites to obtain personal information or money. Investors should verify information directly through official sources rather than trusting unexpected messages or links.

The bottom line is simple:

SIPC can be an important layer of investor protection, but investors should not treat it as cybersecurity insurance.

What This Means for You

For U.S. investors, protecting a brokerage account starts with reducing the opportunities criminals have to obtain account credentials and impersonate the account owner.

Use a unique, strong password for your brokerage account and avoid reusing that password elsewhere. Enable multifactor authentication whenever the brokerage provides it. The SEC specifically recommends protecting sensitive financial information and being cautious about requests for login credentials and authentication codes.

Your email account deserves the same level of protection as the brokerage account itself. If a criminal controls the email address connected to an investment account, they may have a much easier path toward intercepting security notifications or initiating password-reset procedures.

GCJMGHL

Investors should also be cautious with links received through email, text messages and social media. Instead of clicking a message claiming to be from a brokerage, open the brokerage’s official app or type the known website address yourself.

Another important step is monitoring account activity.

Review statements, trade confirmations, account balances and security notifications regularly. SIPC specifically advises investors to review confirmations and statements carefully and promptly notify their brokerage in writing when they identify an error or suspicious activity.

Investors should also understand their brokerage’s policies for unauthorized transactions, account transfers and cybersecurity incidents. The specific contractual protections and procedures can vary among firms.

Finally, never assume that a message is legitimate simply because it uses the name of a major brokerage, financial regulator or investor-protection organization.

What to Do If Your Brokerage Account Is Compromised

If you notice suspicious activity, speed matters.

First, contact your brokerage immediately. Use a verified telephone number from the firm’s official website, statement or app rather than a phone number supplied in a suspicious email or text.

Ask the firm to investigate the activity and, where appropriate, place restrictions on further transactions or transfers.

CGMGHL

Second, change compromised credentials. If you believe your password has been exposed, change it immediately. If your email account may also be compromised, secure that account as well. Review recovery email addresses, telephone numbers, authentication methods and recently authorized devices.

Third, document everything. Save account statements, trade confirmations, transfer notices, emails, text messages, screenshots and dates of conversations with the brokerage.

Written documentation can be particularly important. Investor.gov notes that investors should complain promptly in writing about unauthorized transactions because establishing that a transaction was unauthorized can become important later.

Fourth, report the problem to the appropriate authorities when necessary. The SEC provides an investor complaint process for problems involving investment accounts and financial professionals.

Depending on the circumstances, investors may also need to contact FINRA, their state securities regulator, law enforcement or other relevant agencies.

Fifth, watch for follow-up scams. This step is often overlooked.

Someone who knows that you have already suffered an investment-account problem may contact you pretending to be a regulator, recovery company, lawyer or investor-protection organization. SIPC has warned about scams involving people falsely claiming to represent investor-protection entities.

Never send additional money simply because someone promises to recover your stolen investment.

Investor Takeaway

The biggest change investors should recognize is that brokerage fraud is no longer limited to unauthorized stock trades.

Today’s threat landscape can involve identity theft, phishing, account takeovers, fraudulent new accounts, ACATS transfers, synthetic identities, social engineering and AI-generated impersonation. FINRA’s recent regulatory materials specifically identify these evolving threats and describe measures firms are using to detect suspicious activity.

That makes account monitoring just as important as portfolio monitoring.

An investor who checks a brokerage account only once every few months could miss a suspicious login, transfer instruction or contact-information change. Regular monitoring gives the investor a better chance of identifying unusual activity early.

Investors should also understand the difference between brokerage protection and bank protection.

SIPC protection applies under specific circumstances involving eligible customers of SIPC-member brokerage firms. FDIC insurance, by contrast, applies to qualifying bank deposits. The two systems serve different purposes and should not be treated as interchangeable.

The SIPC limit is generally $500,000 per customer, including up to $250,000 for cash, subject to the rules governing separate capacities and eligible assets.

Investors with large portfolios should therefore understand exactly how their accounts are titled, which entities hold their assets and which protections apply to each account.

Future Outlook

The brokerage-security problem is unlikely to disappear as financial services become increasingly digital.

In fact, artificial intelligence could make some forms of fraud more convincing. FINRA has already highlighted the use of generative AI, deepfake media and synthetic identities in investment-related fraud and account-takeover activity.

That does not mean investors should avoid online brokerage accounts. Digital investing remains one of the most convenient ways to save and participate in financial markets.

Instead, investors should expect security systems to become increasingly layered.

Brokerages are likely to continue strengthening identity verification, transaction monitoring, device analysis, behavioral analytics and notifications around suspicious transfers. FINRA’s 2026 regulatory report describes practices such as reviewing identifying information, examining IP and location information, verifying account statements and sending account-owner notifications when ACATS transfers are initiated.

Regulatory attention is also evolving. In February 2026, FINRA issued Regulatory Notice 26-03 concerning the use of negative consent for certain bulk transfers or assignments of customer accounts. This is different from fraudulent ACATS transfers, but it demonstrates why investors should pay attention to communications about account transfers and understand whether a transfer is one they actually expect.

For individual investors, the future of brokerage security will probably involve a shared responsibility between the investor, brokerage firm and financial regulators.

Brokerages must improve their systems for detecting unusual behavior. Regulators must continue adapting rules to new fraud techniques. Investors must protect their credentials, identity information and communications channels.

The strongest defense is therefore not one security feature. It is a combination of multifactor authentication, unique passwords, secure email, careful verification, account monitoring, rapid reporting and good documentation.

Brokerage account fraud is a serious financial risk, but understanding how criminals operate can make investors harder targets.

The most important step is not waiting until money disappears.

Check your account. Read your notifications. Verify unexpected transfer requests. Protect your identity. And if something looks wrong, contact the brokerage immediately through an independently verified channel.

For investors building long-term wealth, protecting the assets they already have can be just as important as finding the next investment opportunity.

Subscribe to trusted news sites like USnewsSphere.com for continuous updates.

Sharing articles