The Name Is Real, the Firm Is Not — Why Clone Scams Are Becoming Harder to Spot in Ireland

Ireland Ireland Newspaper Report
By 31 min read
Share X Facebook Email

The most dangerous financial scam may no longer arrive under a ridiculous company name promising impossible riches. It may appear to come from a business that genuinely exists. On 1 and 2 September 2026, the Central Bank of Ireland issued warnings concerning Vinvory Capital, Carrowmore Financial Services and Atlas Group AG. Carrowmore Financial Services was explicitly identified as a clone of a legitimate authorised Irish firm. By 4 September, the Central Bank had added another particularly striking warning: an unauthorised entity calling itself DAVY Unlimited was using the name of one of Ireland’s best-known investment businesses.

The timing coincides with another sobering measure of financial crime. Figures published by the Central Bank on 4 September show that the value of fraudulent payments reported by Irish-resident payment service providers reached €179.04 million in 2025, up 27.2% from €140.80 million in 2024. That total covers payment fraud much more broadly than investment scams or clone firms, but it illustrates the financial environment in which increasingly sophisticated impersonation operates.

Clone fraud works because criminals have identified one of the fundamental weaknesses in the way people establish trust online. Consumers have been taught to look for a recognised name, a professional website, a company address, a registration number, polished documentation and apparently knowledgeable staff. Modern fraudsters can copy every one of those signals without acquiring the regulation, assets, expertise or legal responsibilities of the company they are impersonating.

The result is a reversal of the traditional scam. Instead of asking a potential victim to trust an unknown business, the criminal steals trust that another organisation has spent years building. The website can be fake, the adviser fictitious and the bank account controlled by criminals while the company name displayed at the top of the page is entirely real.

Financial fraud in Ireland

  • The Central Bank warned about Carrowmore Financial Services and Atlas Group AG on 2 September 2026 and Vinvory Capital on 1 September.
  • Carrowmore Financial Services was identified as a clone of a legitimate Central Bank-authorised business.
  • On 4 September the Central Bank also warned about DAVY Unlimited, a clone using the name of J&E Davy Unlimited Company trading as Davy.
  • Fraudulent payments reported by Irish-resident payment service providers reached €179.04 million in 2025.
  • Central Bank research published in April 2026 found that 35% of Irish adults surveyed had experienced fraud or scams.
  • Thirty-eight per cent of victims in that research had never reported the experience to their financial provider or an authority.

A Clone Firm Borrows Trust Instead of Building It

A clone firm is not simply an unauthorised financial company with a misleading website. In its most developed form, it impersonates a genuine organisation by copying enough of its identity to make independent verification appear to succeed. Fraudsters can appropriate a legal company name, business address, Central Bank reference number, Companies Registration Office information, staff names, logos and wording from the real organisation’s website.

The criminal then changes the elements that direct the consumer towards the scam: the domain name, email address, telephone number or payment instructions. The difference can be obvious when examined closely, but almost invisible to somebody who sees the material for the first time. A legitimate firm might use one domain while the clone adds a word such as “wealth”, “capital”, “private”, “Ireland”, “EU” or “investments”, or substitutes a hyphen that seems entirely plausible.

This explains why simply searching a business name online is no longer a reliable safety test. A scammer wants the victim to perform a superficial check. If the consumer searches the company’s name and discovers that a real regulated business exists, the stolen identity has done its job. The important question is not merely whether the company exists, but whether the website, email, phone number, individual and financial product being presented actually belong to that authorised company.

The September Warnings Show Several Versions of the Same Problem

The recent Central Bank notices demonstrate that “unauthorised firm” and “clone firm” are related but not identical descriptions. Vinvory Capital was warned against on 1 September because it was not authorised to operate as an investment firm, investment business firm or crypto-asset service provider in Ireland. Its warning did not identify it as a clone of a legitimate Irish financial firm.

Carrowmore Financial Services was different. The Central Bank stated on 2 September that the unauthorised entity had cloned the name and details of legitimate Carrowmore Financial Services Limited. The clone used its own web addresses, telephone number and email address while presenting itself under the borrowed identity. The regulator explicitly stated that there was no connection between the authorised company and the fraudulent entity.

Atlas Group AG was also labelled a clone by the Central Bank on 2 September and was not authorised to operate as an investment firm in Ireland. Two days later, the regulator issued the DAVY Unlimited warning. The unauthorised website was using a name closely associated with authorised J&E Davy Unlimited Company, trading as Davy, whose Central Bank registration number is C775. Again, the legitimate business had no connection with the clone.

A second warning on 4 September concerned Personal Financing, which the Central Bank said was not authorised to provide retail credit services in Ireland. The cluster of notices matters because it demonstrates the range of financial needs that criminals target. Someone looking for an investment, crypto service or loan can encounter essentially the same deception adapted to a different product.

Recent Central Bank Warning Notices

Date Name used Central Bank status
1 Sep 2026 Vinvory Capital Unauthorised investment and crypto provider
2 Sep 2026 Carrowmore Financial Services Clone of authorised firm
2 Sep 2026 Atlas Group AG Clone; unauthorised investment firm
4 Sep 2026 DAVY Unlimited Clone of authorised Davy business
4 Sep 2026 Personal Financing Unauthorised retail credit firm

Source: Central Bank of Ireland warning notices, 1–4 September 2026.

The Legitimate Company Is Usually a Victim Too

One of the most important facts about clone scams is easily lost when a famous or convincing company name appears in a fraud warning. The genuine company whose identity has been copied is not necessarily implicated in the scam. In the recent Carrowmore and Davy notices, the Central Bank specifically separated the authorised firms from the fraudulent entities impersonating them.

This distinction matters both legally and practically. Criminals deliberately choose real identities because those identities carry something valuable: reputation. A consumer may recognise a brand from advertising, financial news or previous business dealings. Even an obscure regulated firm can be valuable to a fraudster because its Central Bank registration can be copied onto fake paperwork.

The damage therefore extends beyond the money stolen from consumers. The legitimate business can face confused telephone calls, reputational damage and the administrative burden of warning customers and regulators about websites, email addresses and advertisements over which it has no control. Identity theft in financial services can affect companies in much the same way that personal identity theft affects individuals.

Why the Digital Economy Made Cloning So Much Easier

Financial impersonation is not new. Boiler-room operations, fraudulent brokers, fake loan providers and investment schemes existed long before social media. What has changed is the cost and speed with which a convincing financial identity can be manufactured and distributed.

A criminal no longer needs an expensive office or professionally printed prospectus to appear established. A website can reproduce the visual language of a bank or investment manager almost immediately. Public company registers provide legitimate names and addresses. Regulatory registers provide reference information. Corporate websites identify executives and employees. LinkedIn and other professional networks reveal job titles. Press releases supply photographs and quotations. Social-media platforms provide access to potential victims at enormous scale.

The information exists for legitimate reasons. Transparency allows consumers, investors and counterparties to understand who owns and operates a business. Yet the same public data can be harvested by criminals seeking to construct an imitation. The problem is not that regulatory registers publish too much information; the problem is that digital copying makes authentic information easy to detach from its authentic source.

Domain registration adds another layer. A website address that resembles an established firm’s domain may be obtained separately from the company itself. The Central Bank now specifically advises consumers to examine when a domain was created. A website claiming decades of financial history but operating on a domain registered very recently deserves particular scrutiny.

A Fake Website Can Be Almost Completely True

The sophistication of clone fraud comes from selective falsification. A scam website does not have to invent everything. It can reproduce genuine biographies, regulatory language, product descriptions, photographs and office locations directly from the legitimate business. Ninety per cent of what the consumer reads may therefore be accurate information about somebody else’s company.

The critical falsehood may be only the contact channel. An email address directs to the criminal. A telephone number is answered by somebody impersonating an employee. A payment instruction sends money to an unrelated account. A customer portal records fictitious investments. The consumer may therefore spend hours checking the organisation’s history while never verifying the single detail that determines where the money goes.

Professional presentation should consequently be treated as neutral evidence rather than proof of legitimacy. Grammar errors and poor design remain warning signs, but their absence proves very little. Modern fraudulent websites can be cleaner than legitimate websites and can reproduce complex financial documents without the criminals having to understand the underlying products.

Artificial Intelligence Has Reduced the Cost of Looking Convincing

Generative artificial intelligence has accelerated this evolution. The Central Bank has warned that AI-generated videos, images and audio are being used to impersonate well-known businesspeople and public figures. These deepfakes commonly circulate through social-media advertisements before directing potential victims towards investment platforms, messaging groups or supposed financial advisers.

FraudSMART reported in May 2026 a surge in AI-generated advertisements promoting fictitious state-backed investment schemes. The advertisements used fake images or videos of prominent politicians and businesspeople, exploiting public discussion of legitimate government savings and investment initiatives to create plausibility. A real news story can therefore become raw material for a fabricated investment offer within hours.

AI also affects the quieter parts of fraud. It can generate polished emails, translate material into convincing English, construct sales scripts, imitate corporate tone and produce large quantities of personalised communications. Criminal groups can therefore interact with far more potential victims without every conversation sounding identical.

The technology does not remove the need for social engineering. It amplifies it. A deepfake may create the first moment of trust, but the financial loss usually depends on persuading a real person to enter details, answer a call, join a messaging group, transfer funds or install software. The fraud still succeeds through human decision-making; AI simply makes the deception surrounding that decision more credible and scalable.

Social Media Solved the Scammer’s Distribution Problem

Before digital advertising, finding people actively looking for an investment product was difficult and expensive. Social platforms changed that. Advertisements can reach large audiences, and an individual who clicks on investment, pension, savings or crypto content can be drawn into a sequence of related material.

Fraudsters do not necessarily begin with an aggressive sales pitch. A social-media advertisement may invite the user to request information, compare savings rates or join an educational discussion. The consumer voluntarily enters a name, telephone number or email address and may then expect somebody to make contact. That expectation makes the subsequent call less suspicious.

The Central Bank has also warned about fake comparison websites. These mimic the sites consumers legitimately use to compare financial products. A person may believe they are simply asking which bank offers the best savings rate or investment return. In reality, the form can operate as a lead-generation mechanism for criminals.

This is an important behavioural advantage. A completely unsolicited cold call naturally creates suspicion. A call received fifteen minutes after the consumer has requested information online feels like customer service.

The Most Effective Scams Are Becoming Less Spectacular

The traditional warning that an investment promising extraordinary returns is probably fraudulent remains useful, but criminals have adapted to it. The Central Bank warned in November 2025 that some scams were moving away from obviously extravagant returns and instead offering rates only somewhat above the market norm.

That is a sophisticated change in strategy. An investment supposedly paying 40% a year may trigger immediate scepticism. A bond, deposit or structured product apparently offering a few percentage points more than a familiar bank account can feel plausible, particularly when presented under the name of a genuine financial company.

The scammer is therefore not always trying to make greed overcome judgement. Increasingly, the aim is to make the offer look boring enough to be believable. The target may simply be somebody searching for a better return on retirement savings or a large cash balance.

This also explains why financially experienced people can be deceived. Knowledge of ordinary market returns can protect against ridiculous promises but provide less protection against a carefully constructed offer designed specifically to sit within the range a knowledgeable consumer might consider credible.

Investment Fraud Often Begins Long Before the First Transfer

The relationship between scammer and victim can develop over days, weeks or even months. FraudSMART has documented cases in which criminals communicate patiently rather than applying immediate pressure, allowing trust to accumulate before significant money is requested.

An apparent adviser may discuss the investor’s objectives, explain a product, provide brochures and answer questions. A fraudulent online account can display the investment after the initial payment and may even show gains. The first amount requested can be relatively modest, establishing the impression that the platform works before larger transfers are encouraged.

For victims, this creates a particularly powerful psychological trap. Each successful-looking stage validates the previous decision. The customer may have spoken repeatedly to the same adviser, received documents, logged into a portal and watched an apparent balance increase. When the fraudster asks for another transfer, the victim is not assessing an entirely new proposition; they are being asked to extend a relationship they have already accepted as legitimate.

The illusion usually breaks when the person attempts to withdraw money or when additional payments are demanded. A supposed tax, administrative charge, insurance payment or release fee may suddenly be required. At that stage the investor can be pressured to send more money in an attempt to recover what has already been transferred.

Then Comes the Second Scam: We Can Get Your Money Back

Victims of fraud face an additional risk after the original scam has been discovered. Criminal networks know that someone who has just lost a substantial amount is highly motivated to recover it. Contact details may remain with the original fraudsters, be shared between criminals or appear in other data sets.

The Central Bank has specifically warned about recovery scams. Someone may approach the victim claiming to be a lawyer, regulator, investigation company, financial specialist or asset-recovery service. They promise that the stolen money has been traced but demand an advance payment before it can be released.

The emotional dynamics make this especially destructive. The person is no longer evaluating an investment opportunity; they are trying to undo a loss. A payment that would have seemed irrational before the fraud can feel justified if it appears to be the final obstacle between the victim and the return of their savings.

For that reason, anyone who has already been defrauded should treat unsolicited offers of fund recovery with exceptional caution. The Central Bank advises consumers not to pay fees to anyone cold-calling or messaging them with promises of retrieving lost funds.

The Financial Numbers Are Large, but They Measure Different Types of Fraud

Today’s €179.04 million payment-fraud figure should not be presented as €179 million of clone-firm losses. It covers a broad range of fraudulent payments reported by Irish-resident payment service providers, including cards, credit transfers, e-money and other payment channels. Clone investment scams represent only one part of the wider fraud landscape.

Nevertheless, the data reveals how important manipulation has become. In 2025, €74.86 million of fraudulent payment value was attributed to authorised push payment fraud, also described as manipulation-of-the-payer fraud. In these cases, criminals socially engineer the customer into authorising the payment rather than simply stealing credentials and making an unauthorised transaction themselves.

This distinction is central to clone fraud. The banking system may correctly authenticate the genuine customer. The customer’s device may work exactly as intended. Two-factor authentication may be completed successfully. The problem is that the person has been deceived about who is receiving the money or why it is being sent.

Cross-border flows complicate recovery further. The Central Bank reported that 69.8% of fraudulent payment value in 2025 involved payments sent to accounts outside Ireland, amounting to €124.89 million. Again, that includes many forms of fraud, but it illustrates how quickly Irish consumers can become part of an international money trail.

Ireland’s 2025 Payment Fraud Picture

Measure 2025
Total fraudulent payment value €179.04m
Increase from 2024 27.2%
Manipulation-of-payer fraud €74.86m
Cross-border fraudulent payments €124.89m
Cross-border share 69.8%

Source: Central Bank of Ireland Payment Fraud Statistics, published 4 September 2026. Figures cover payment fraud broadly and are not specific to clone or investment scams.

Investment Fraud Alone Has Already Cost Irish Victims Tens of Millions

Investment fraud forms a separate but significant part of the problem. An Garda Síochána figures cited by FraudSMART in May 2026 showed that reports of investment fraud increased by more than 20% in 2025 compared with 2024 and that reported losses exceeded €20 million. Gardaí said at the time that the upward trend was continuing into 2026.

The sums involved can differ dramatically between cases. Small crypto-related frauds may begin with a few hundred euro. More elaborate scams involving supposed bonds, shares or investment products can start with five-figure transfers and escalate significantly. FraudSMART has previously recorded individual investment-scam cases involving very substantial sums.

This explains why criminals devote considerable effort to impersonating investment companies. A scammer seeking €50 from each target needs enormous volume. A convincing fictitious wealth manager or bond broker may need only a handful of victims prepared to transfer retirement savings or the proceeds of a property sale.

The economics of the crime therefore reward sophistication. Spending time constructing a clone website, conducting lengthy telephone conversations and imitating a real firm can be worthwhile when the potential transfer is measured in tens or hundreds of thousands of euro.

Fraud Is Not Simply a Problem of Older or Naive Consumers

The stereotype of the fraud victim as somebody unusually gullible is both inaccurate and potentially harmful. Central Bank research published in April 2026, based on a broadly nationally representative survey of almost 3,000 adults, found that 35% had experienced fraud or scams. Almost two-thirds of those victims had suffered a financial loss.

The most important predictor identified by the study was not age, income or education. It was risky online behaviour. This finding matters because it shifts prevention away from asking which demographic is supposedly easy to deceive and towards examining the environments and behaviours through which people encounter fraud.

Specific scam types can still target particular groups. Investment fraudsters often focus on people who have accumulated pensions or substantial savings, making middle-aged and older adults attractive because the potential balances are larger. Younger consumers may encounter crypto, social-media and digital-platform fraud more frequently. But no age group has a monopoly on either vulnerability or financial sophistication.

A professional qualification also provides limited protection against a false premise. If the victim believes that the person on the telephone genuinely represents a regulated institution, all subsequent reasoning takes place inside that assumption. Clone fraud attacks identity verification before it attacks investment judgement.

The Psychological Loss Can Continue After the Money Has Gone

Financial loss is only the most easily measured consequence. Central Bank research notes that fraud can impose lasting psychological costs and undermine trust in financial institutions. A victim may repeatedly reconstruct the conversation, website or transfer in an attempt to identify the moment at which the deception should have been recognised.

The consequences can be particularly severe when retirement savings, inheritance, redundancy payments or money accumulated over many years are involved. A large investment-fraud loss can alter housing plans, retirement timing or the financial security of an entire household. Family relationships can also come under strain when one member authorised the transfer.

Self-blame can create a second problem: silence. The Central Bank’s 2026 research found that 38% of fraud victims had never reported their experience to their financial service provider or any authority. That matters because the same study found that victims who reported fraud were more likely to recover money.

Under-reporting also protects the criminal rather than the victim. Banks lose information that could identify receiving accounts, regulators may remain unaware of an unauthorised operator and Gardaí cannot connect apparently separate cases. Reporting quickly can therefore protect both the person affected and subsequent potential targets.

A Central Bank Registration Number Is Not Enough

This is the most important practical lesson of clone fraud. Finding the same company name and Central Bank reference number on the regulator’s register does not automatically prove that the person contacting you is genuine. Criminals copy reference numbers precisely because consumers have been told to look for them.

The verification process has to continue one stage further. Consumers should independently open the Central Bank’s official website and access the Registers from there rather than following a link supplied by an adviser, advertisement, email or website. The genuine registration entry can then be compared with the details being used by the person offering the product.

The exact legal name matters, but so do telephone numbers, website addresses, email domains, registered activities and other contact information. If the salesperson is using a number different from the firm’s known contact details, the consumer should not ask that salesperson for reassurance. Instead, contact the legitimate firm independently using a number obtained from the official register or the firm’s established website.

A matching company name is not verification. A clone scam is designed to make the company name match.

How to Check a Financial Firm Properly

The safest approach is to separate discovery from verification. If an investment appears in a social-media advertisement, do not use the advertisement itself to verify the investment. If an adviser sends a link to a Central Bank registration, do not rely on that link. If an email contains a telephone number for the firm’s compliance department, do not assume the compliance department is genuine simply because the signature says it is.

Instead, begin again from an independent source. Type the Central Bank’s address into the browser yourself, navigate to the Registers and search for the firm. The official Registers include financial service providers and collective investment schemes regulated by the Central Bank as well as certain other providers that must appear on the registers.

Some financial businesses based elsewhere in the European Economic Area may be regulated by their home-state authority and permitted to provide services in Ireland through passporting arrangements. Absence from one particular category should therefore not be interpreted casually. When the position is unclear, the Central Bank advises consumers to contact it directly.

What to Compare Before Sending Money

Check What to verify Why it matters
Legal name Exact registered firm Similar names can mislead
CBI status Relevant authorisation A real company may not hold the required permission
Website Exact domain Clones use lookalike domains
Phone Independently sourced number Fake advisers control scam numbers
Email Exact company domain A subtle domain change can redirect replies
Product Offered by genuine firm Scammers can invent products under a real name
Warning list Central Bank notices Known unauthorised firms are published

Source: Central Bank of Ireland consumer guidance on unauthorised firms and financial scams.

Call the Real Firm Back — But Not on the Number You Were Given

This simple step defeats a large part of the clone model. After identifying the authorised company, locate its telephone number independently and call it. Ask whether the named employee works there, whether the email address belongs to the organisation and whether the product being offered actually exists.

The distinction between independently obtained and supplied contact information is crucial. Calling the number at the bottom of a suspicious brochure simply returns the consumer to the fraudster. Clicking a “contact us” button on the clone website does the same. Even a search-engine result should be examined carefully because sponsored advertisements and misleading results can appear around genuine company searches.

A legitimate firm should not object to a potential client ending a call and independently checking its regulatory status. Pressure not to do so is itself a warning sign. Genuine long-term financial decisions rarely depend on transferring substantial sums within minutes.

Check the Product, Not Only the Provider

A particularly effective scam can use the identity of a legitimate firm while offering a product the real business does not provide. The company is genuine. The regulation is genuine. The fabricated bond or deposit is not.

The Central Bank therefore advises consumers to check that the financial product being offered appears through the legitimate firm’s own channels. If somebody claims to offer a special bond, fixed-return investment or savings product unavailable on the firm’s real website, the customer should contact the business independently before proceeding.

This can also expose claims that exploit current news. A fraudulent advertisement may attach itself to a genuine government initiative, new savings scheme or high-profile company announcement. The existence of the underlying news story does not authenticate the investment being advertised alongside it.

The Warning List Is Valuable — but Silence Is Not Approval

The Central Bank regularly publishes names, websites, email addresses and telephone numbers associated with unauthorised firms. Checking that list is an important part of due diligence, especially when an unfamiliar company approaches a consumer.

But the regulator makes an equally important point: the absence of a firm from the warning list does not prove that it is legitimate. A new scam may not yet have been reported. Regulators need information before they can investigate and publish a warning, while a fraudulent website can begin operating immediately.

The warning list is therefore a negative test rather than a certificate. Finding the firm on it is a compelling reason to stop. Failing to find it is merely the beginning of further verification.

The Domain Name Can Reveal What the Logo Hides

Consumers should read a website address from right to left around the main domain rather than relying on the words appearing elsewhere on the page. A genuine logo can be copied in seconds; control over the legitimate company’s actual domain is much harder to imitate.

Misspellings, added words, alternative endings and unexpected hyphens deserve scrutiny. So does the age of the domain. The Central Bank specifically recommends checking whether the creation date makes sense in light of the firm’s claimed history.

A newly registered domain is not automatically fraudulent. New businesses and legitimate marketing projects launch websites every day. But a website claiming to represent a decades-old financial institution while operating from a domain created very recently creates an inconsistency that requires explanation.

A Padlock Does Not Mean a Financial Company Is Regulated

Another outdated assumption concerns the padlock displayed in a browser. HTTPS encryption is important because it protects information travelling between the user’s device and a website. It says nothing about whether the person operating that website is honest.

Fraudulent sites can obtain security certificates just as legitimate businesses can. A padlock may therefore confirm that the connection to the scammer’s website is encrypted. It does not transform the scammer into a regulated financial institution.

The same logic applies to professional email, Irish telephone numbers and polished customer portals. These are technical capabilities, not regulatory credentials.

Urgency Remains a Warning Sign, but Patience Can Be a Scam Tactic Too

Consumers are rightly told to distrust anyone demanding an immediate transfer. Scarcity claims, expiring offers and repeated pressure to act before checking with family or an adviser are classic social-engineering techniques.

But sophisticated fraudsters know this advice. Some deliberately avoid pressure in the early stages. A supposed adviser who tells a potential client to take their time can appear more trustworthy precisely because it contradicts the stereotype of a scammer.

Verification therefore has to be factual rather than based on personality. A patient, articulate and knowledgeable adviser can still be fictitious. A friendly relationship built over several weeks does not establish authorisation.

Loan Scams Use the Same Borrowed Credibility Against People Who Need Money

Clone techniques are not limited to affluent investors. Fraudulent loan providers can target people experiencing the opposite financial situation: they need credit rather than somewhere to invest savings.

The scam may promise quick approval despite previous credit difficulties and then request an upfront administration fee, insurance payment or refundable deposit. The Central Bank’s guidance is particularly clear on this point: if somebody seeking a loan is asked for an upfront fee before the loan is provided, they should stop engaging because this is a scam pattern.

Such fraud can be especially damaging because the victim may already be under financial pressure. Losing even a relatively small upfront payment can intensify an existing budgeting problem. The criminal exploits not greed but urgency and lack of alternatives.

The SAFE Test Is Designed to Interrupt the Decision

The Central Bank’s consumer guidance summarises its approach through the SAFE test. The usefulness of the method lies less in the acronym than in forcing a pause between receiving an offer and acting upon it.

The Central Bank SAFE test

  • Stop: ask who is contacting you, what is being offered and whether you feel pressured to act.
  • Assess: check the Central Bank registers and determine whether the firm is genuinely authorised.
  • Fact-check: verify the product and information through independent trusted sources.
  • Expose and report: report suspicious unauthorised activity to the Central Bank and, where fraud is suspected, An Garda Síochána.

In a digital environment built around one-click purchases and instant payments, delay itself is a security measure. A fraudster needs the victim to remain inside the information environment created by the scam. Calling a family member, bank, regulated adviser or legitimate company introduces an independent source of information and can break that control.

What to Do if Money Has Already Been Sent

Speed becomes critical once a suspicious payment has been made. The first contact should be the bank or payment service provider involved. A transfer may already have moved through several accounts, but providers can attempt recalls, alert receiving institutions or apply fraud procedures. The Central Bank’s 2026 research found that people who reported fraud were more likely to recover money.

Suspected fraud should also be reported to An Garda Síochána. Where the case involves an apparently unauthorised financial services provider, the Central Bank accepts reports and publishes warnings when appropriate. The regulator currently provides consumer contact numbers 0818 681 681 and +353 (0)1 224 5800 for queries concerning regulatory status and related matters.

Consumers should retain emails, messages, telephone numbers, account details, receipts, screenshots and other records rather than deleting them out of embarrassment. These can help banks, regulators and investigators understand how the fraud operated.

If passwords, card information or identity documents have been supplied, the problem may extend beyond the original transfer. Relevant passwords should be changed through genuine services, financial providers informed and unusual account activity monitored. Anyone persuaded to install remote-access software should treat the device and credentials as potentially compromised and seek appropriate technical assistance.

And once again, victims should be prepared for recovery fraud. The fact that someone knows the exact amount lost or the name of the original scam does not prove they are an investigator. That information may have come directly from the criminals responsible.

Why Banks Cannot Simply Block Every Suspicious Transfer

It is reasonable to ask why sophisticated banking systems cannot identify and stop all scam payments. In some cases they do. Banks use transaction monitoring, authentication controls, account restrictions and fraud detection systems, and Ireland’s regulatory framework places growing expectations on financial firms to protect consumers.

But authorised-payment fraud creates a difficult boundary. A legitimate customer may genuinely wish to transfer a large amount abroad to purchase an investment. The bank cannot assume that every unusual but lawful payment is fraudulent. Criminals exploit the fact that the customer can correctly pass security checks and may actively assure the bank that the transfer is intended.

Detection systems therefore look for patterns rather than certainty. Large new beneficiaries, unusual destinations, rapid movement of money and known high-risk accounts can trigger intervention, but criminals continually change receiving accounts and payment routes.

This is also why responsibility cannot rest entirely on consumers. The Central Bank has emphasised a whole-system approach involving regulated financial firms, technology companies, regulators and law enforcement. Its Consumer Protection Code places explicit expectations on firms around protecting and supporting customers affected by fraud and scams.

Online Platforms Are Part of the Financial Crime Environment Now

The rise of social-media investment fraud has changed the regulatory problem. A bank may never display the fraudulent advertisement that begins the scam, while a technology platform may never see the final bank transfer. The crime moves across systems operated by different companies and often different jurisdictions.

That fragmentation benefits criminals. One service hosts the advertisement, another hosts the fake website, a messaging platform manages the conversation, a telecommunications provider carries the call and a bank executes the transfer. Each individual service can function largely as designed while the combined sequence produces fraud.

Regulators have therefore been pushing for greater cooperation with technology platforms. The Central Bank has also used its status under European digital regulation to seek removal of criminal online content. Advertising-verification measures adopted by major platforms can make fraudulent financial promotion more difficult, but the continuing flow of warnings shows that technical controls have not eliminated the problem.

Artificial Intelligence Will Make Visual Evidence Less Valuable

The next phase of the problem may require consumers to abandon another long-standing instinct: believing something because they have seen or heard it. A realistic video of a chief executive recommending an investment can be fabricated. A familiar voice can be reproduced. A video meeting can potentially be manipulated. A photograph proves only that an image exists.

This does not mean consumers need to become experts in detecting deepfakes. In fact, relying on visual detection may become increasingly unrealistic as generation tools improve. The more durable defence is independent verification through a channel the fraudster does not control.

If a famous businessperson apparently promotes an investment, the relevant question is not whether the video looks authentic. It is whether the product exists on the official channels of the organisation concerned and whether the company offering it has the required regulatory permission.

This represents a profound change in digital literacy. Consumers once learned to inspect the message. Increasingly, they must verify the source outside the message.

The Most Reliable Defence Is to Break the Chain of Trust

Clone scams are designed as a chain. An advertisement produces curiosity. A professional website produces credibility. A recognised company name produces trust. A registration number produces reassurance. A knowledgeable caller develops a relationship. A customer portal appears to demonstrate that the investment exists. Each piece supports the next.

The defence is to deliberately step outside that chain. Open the Central Bank website independently. Search its register. Compare the exact details. Find the legitimate firm’s real contact information elsewhere. Call it. Ask whether the employee and product exist. Check the warning list. Discuss the offer with somebody who has no involvement in the sale.

That approach can feel excessively cautious when the company name is familiar. Clone fraud succeeds because it exploits exactly that feeling.

The Bigger Problem Is a Crisis of Digital Trust

The spread of corporate impersonation creates consequences beyond individual losses. Financial markets depend on trust. Consumers need to believe that a message from their bank is genuinely from their bank, that an adviser represents the company in their email signature and that a regulated firm’s website is actually controlled by that firm.

As imitation becomes easier, legitimate businesses may need increasingly secure ways to prove identity rather than expecting consumers to distinguish genuine communications from near-perfect copies. Stronger domain protection, verified communication channels, rapid removal of fraudulent advertisements and clearer regulatory data can all raise the cost of impersonation.

The challenge is asymmetric. A bank or investment company may spend decades establishing a reputation. A criminal may need only days to copy its public appearance. The legitimate institution then has to defend not only its own cybersecurity but the external identity that consumers associate with it.

The Warning Issued Today Captures the New Reality

The DAVY Unlimited warning of 4 September is a particularly clear illustration. The scam entity did not need to invent the reputation attached to the Davy name. It borrowed it. A consumer recognising the name could reasonably associate it with an established Irish investment business — which is precisely why the impersonation was useful to the criminals.

The correct conclusion is not that Davy itself was operating fraudulently. The Central Bank explicitly states the opposite: the unauthorised entity has no connection with the legitimate authorised firm. The warning demonstrates why well-known companies can become targets of identity theft rather than sources of the scam.

Carrowmore Financial Services demonstrates the same mechanism on a less nationally familiar name. A clone does not need mass brand recognition if it can reproduce an authentic regulatory identity convincingly enough for an individual consumer to believe it has passed due diligence.

Vinvory Capital demonstrates the other side of the market: not every suspicious provider is a clone. Some simply offer regulated activities without the required authorisation. Consumers therefore need to test both questions — is this company authorised, and am I actually dealing with the authorised company?

Two Questions Can Prevent a Large Number of Mistakes

The first question is straightforward: Is the firm legally authorised to provide this particular financial service? That can be checked through the Central Bank’s official Registers and, where relevant, the regulatory arrangements applying to firms authorised elsewhere in the European Economic Area.

The second is more important in the era of clone scams: Is the person, website and contact information in front of me genuinely connected with that authorised firm? The answer requires comparing details and making independent contact.

Consumers should also check the Central Bank’s Warning Notices. But absence from that list should never be treated as regulatory approval because a scam may simply be new.

When uncertainty remains, consumers can contact the Central Bank directly rather than asking the firm under investigation to prove its own legitimacy. A fraudulent adviser can manufacture another document. They cannot legitimately alter the Central Bank’s regulatory record.

Fraud Prevention Is Becoming Less About Spotting Bad Spelling and More About Verifying Identity

For years, scam advice focused on obvious clues: strange grammar, extravagant promises, foreign phone numbers and poorly designed websites. Those clues remain useful when they appear. They are no longer sufficient.

A modern fraudulent financial offer can use perfect English, Irish telephone numbers, an encrypted website, professional brochures, genuine company information, plausible investment returns and AI-generated endorsements. It may remain patient rather than applying pressure. It may even tell the consumer to check that the company is regulated because the criminals have already copied the regulated company’s details.

The fundamental defensive habit therefore has to change. Instead of asking whether the offer looks genuine, consumers increasingly need to establish whether its identity can be verified independently.

That is why the growing number of clone warnings should not be interpreted merely as a list of dubious websites to avoid. The websites will change. The phone numbers will change. The advertisements will disappear and reappear. The company names being imitated will change as criminals search for new reputations to borrow.

The durable lesson is simpler. A familiar financial name is now the beginning of verification, not the end of it.

If you suspect a financial scam: do not send additional money. Contact your bank or payment provider immediately if a transfer has already been made, report suspected fraud to An Garda Síochána, and report apparently unauthorised financial services activity to the Central Bank of Ireland. Be particularly cautious about anyone who subsequently offers to recover lost money in exchange for an upfront fee.

Sources

Central Bank of Ireland — Carrowmore Financial Services Clone Warning, 2 September 2026

Central Bank of Ireland — Atlas Group AG Clone Warning, 2 September 2026

Central Bank of Ireland — Vinvory Capital Warning, 1 September 2026

Central Bank of Ireland — DAVY Unlimited Clone Warning, 4 September 2026

Central Bank of Ireland — Personal Financing Warning, 4 September 2026

Central Bank of Ireland — Payment Fraud Statistics 2025, Published 4 September 2026

Central Bank of Ireland — Research on Fraud Incidence and Reporting in Ireland, April 2026

Central Bank of Ireland — Changing Fraud Landscape and AI-Enabled Scams

Central Bank of Ireland — How to Avoid Financial Services Scams and the SAFE Test

Central Bank of Ireland — Unauthorised Firms and Regulatory Status Checks

Central Bank of Ireland — Registers of Financial Service Providers

Banking & Payments Federation Ireland FraudSMART — AI-Generated Investment Scam Warning, May 2026

Competition and Consumer Protection Commission — Investment Scam Guidance

Source & Transparency

This article is published by Ireland Newspaper for editorial and informational purposes.

Published: 4 September 2026 · Updated: 4 September 2026

Newsroom Ireland Newspaper

Editorial Desk · Ireland Newspaper

Ireland Newspaper editorial team prepares daily news coverage for readers in Ireland and abroad.

Related posts

Leave the first comment