Phishing & Fraud Awareness
Finesse Capital ("the Firm", "we", "us", or "our") is aware that fraudsters may attempt to impersonate the Firm, its staff, or its official channels, in order to deceive clients and members of the public into disclosing personal or financial information, or making payments to fraudulent accounts. Fraud tactics evolve constantly, and no notice can cover every scenario, but this notice explains what phishing is, common methods used, warning signs, and how to protect yourself.
What Is Phishing?
Phishing is the practice of sending fraudulent communications that appear to come from a genuine and trusted source, such as the Firm, a bank, or a regulator, in order to trick you into revealing sensitive information, clicking a malicious link, opening a malicious attachment, or making a payment. Phishing is usually carried out by email, but related methods are used across text messages, phone calls, and social media, as described below.
Types and Common Methods of Phishing and Fraud
- Phishing emails: fraudulent emails that appear to come from the Firm, a bank, or a regulator, asking you to "verify," "update," or "confirm" your account by clicking a link or opening an attachment.
- Smishing: the same tactic carried out by text message rather than email.
- Vishing: fraudulent phone calls in which a caller impersonates the Firm or a regulator and asks you to disclose personal, account, or security information, or to move funds "for your protection."
- Website or brand cloning: fake or cloned websites that closely resemble our official website, sometimes accessed through a slightly altered web address or a paid advertisement, designed to capture your login details or payment information.
- Staff impersonation: use of a genuine staff member's name, title, or photograph, on email, phone, or social media, to build false trust before requesting information or payment.
- Fraudulent investment schemes: schemes or "opportunities" that use the Firm's name or branding without authorization, often promising unusually high, fixed, or guaranteed returns, or pressuring you to invest quickly before an offer "closes."
- Business email compromise: a fraudster gains access to, or spoofs, an email account, then sends altered payment or account instructions that appear to come from a genuine contact.
- Remote-access scams: requests to install remote-access software, or to grant access to your device, computer, or online banking, under the guise of technical support or account assistance.
- SIM-swap fraud: a fraudster fraudulently takes control of your phone number in order to intercept OTPs or account recovery messages; unexpected loss of phone network signal or account lockout notices can be an early warning sign.
- Recovery scams: a fraudster contacts a person who has already lost money to a scam, claiming to be able to recover the funds in exchange for an upfront fee.
What We Will Never Do
We will never ask you, by email, phone call, text message, or social media, to disclose your password, PIN, one-time password (OTP), or full bank account or card details. We will never ask you to make an urgent payment or transfer to an account other than one you have independently verified through our official channels, and we will never pressure you to bypass our standard onboarding, suitability, or due diligence process. We do not conduct business, solicit investment, or request payment through WhatsApp or other social media direct messages. Any genuine request for documentation or verification during onboarding or account maintenance will be made through the channels set out in your Client Agreement, and you are always entitled to independently verify such a request before responding to it.
Warning Signs to Watch For
Be alert to unsolicited communications that create urgency or pressure to act immediately, requests to disclose passwords, PINs, OTPs, or full account or card details, requests to pay into an account that differs from one you have already verified, communications from addresses or numbers that closely resemble but do not exactly match our official details, and poor spelling, grammar, or formatting inconsistent with our usual communications.
How to Protect Yourself
Use a strong, unique password for your account and never reuse it elsewhere, enable multi-factor authentication where available, keep your device and browser software up to date, and avoid accessing your account over public or unsecured Wi-Fi. If you receive a request that appears to come from us or from someone you know, verify it through a second channel, such as calling a phone number you already have on file, rather than replying to the message or using any contact details it provides.
Before acting on any communication purporting to be from us, take a moment to verify it. Check the sender's email address or number carefully rather than relying on the displayed name, hover over links to check the destination before clicking, and look for the correct spelling of our website address and a secure connection when visiting our site. If in doubt, do not click any links, open any attachments, disclose any information, or make any payment. Instead, contact us directly using the official contact details on our website, rather than any contact details provided in the suspicious communication itself, and independently confirm any request, particularly one involving payment or a change to existing payment instructions.
If You Suspect Fraud
If you believe you have been targeted by, or have fallen victim to, a phishing or fraud attempt involving our name, please report it to us immediately using the contact details on our website. If you have disclosed account, card, or banking information, or made a payment, contact your bank without delay to report the incident and seek to have any payment recalled or your account secured, and change any passwords or PINs that may have been compromised. Where applicable, you should also report the matter to the relevant law enforcement or regulatory authority. Acting quickly can help limit any potential loss.
We may update this notice from time to time to reflect new or evolving fraud tactics.