Breaking Regulatory Compliance
SEC False Form ADV Cases: 38 Fake Advisers Turned a Public Filing Into a Trust Signal
The SEC sued 38 entities over false Form ADV filings. Here is how compliance teams should verify advisers when a public filing is not proof of approval.
Table of Contents
TL;DR
- On August 27, 2026, the SEC sued 38 entities that allegedly used false Form ADV filings to look like legitimate U.S. investment advisers.
- The alleged pattern included false Colorado offices, dead phone numbers, copy-pasted fund data, phantom auditors, missing commodity registrations, and fake SEC certificates.
- There is no announced settlement or fixed penalty yet. The SEC is asking federal courts for injunctions and civil penalties.
- The control lesson is blunt: a public regulatory filing is evidence to verify, not proof that the regulator approved the firm.
A record in an SEC database looks official. That is exactly why the alleged scheme worked.
In the SEC false Form ADV cases filed Thursday, 38 entities allegedly turned a reporting mechanism into a borrowed badge of legitimacy. They filed Forms ADV, appeared in the public Investment Adviser Public Disclosure database, and then—according to the SEC—used that visibility to make themselves look like real U.S. advisory firms to retail investors.
The SEC’s August 27 litigation release says the entities made material misrepresentations in Forms ADV during 2025 and 2026. Several connected to the filing system from IP addresses traced to foreign jurisdictions. The forms listed Colorado offices where the entities had no presence, phone numbers that were disconnected or belonged to unrelated businesses, nearly identical private-fund data, and audits by firms that could not be found in public accountancy registries.
This is more than an investor-scam warning. It exposes a due-diligence failure mode inside banks, wealth platforms, fund administrators, fintechs, and vendor-management programs: treating database presence as validation instead of the beginning of validation.
What the SEC’s 38 false Form ADV complaints allege
The SEC filed 38 separate complaints in the U.S. District Court for the District of Colorado. The defendants include names such as Abrdn Canada Limited, CryptoOrbit Ltd, LinkedIn Research Institute Ltd, Pinnacle Crypto Exchange Inc., Robin Markets Inc., Web3 University, and Wingspan Advisors LLC.
The cases are allegations, not final findings. But the repeated pattern matters because it shows how low-cost data inconsistencies can expose a supposedly regulated-looking identity.
| Alleged representation | What the SEC says it found | Due-diligence test that should catch it |
|---|---|---|
| A principal office in Colorado | No presence at the listed address; SEC mail was returned | Address validation using state records, independent business data, and live contact testing |
| A working business phone | Disconnected numbers or numbers belonging to unrelated businesses | Call the number; independently source a second contact channel |
| A legitimate private-fund adviser | Ownership and numerical data identical or nearly identical across many filings | Compare fund data against related filings and offering documents; flag improbable repetition |
| Audited private-fund financials | Two named accounting firms could not be found in public federal or state registries | Verify firm licensing and partner identity directly with the applicable accountancy board |
| Commodity pool or trading-adviser activity | No corresponding registration in the entity’s name | Reconcile the claim to CFTC and NFA records |
| SEC legitimacy | Websites allegedly displayed fake certificates claiming SEC registration | Compare the website claim with the exact status shown in IAPD; the SEC does not issue these certificates |
| Records supporting Form ADV | Entities did not substantiate their claims after SEC requests | Require source documents before onboarding or approving a relationship |
One complaint shows how specific the pattern became. In SEC v. Abrdn Canada Limited, No. 1:26-cv-03951, the SEC alleges that the entity filed Form ADV on October 22, 2025, claiming one private fund with 89 investors, gross assets of $78,960,522, and a $50,000 minimum investment. It identified an auditor called Indicator Global and said the fund’s financial statements had received an unqualified audit opinion.
The SEC alleges the Denver address was not valid for the entity, the Arkansas-area-code phone number was disconnected, and Indicator Global was absent from public accountancy registries. The complaint also says the same filing pattern appeared across at least 37 other purported exempt reporting advisers, often using one of two gross-asset figures—$78,960,522 or $48,960,522—and one of two investor counts: 89 or 33.
Those repeated numbers are the kind of signal a human reviewer misses when each case is examined in isolation. They are also exactly the kind of signal a basic entity-resolution or duplicate-pattern rule can surface.
Why the filing appeared before the claims were tested
The operational detail buried in the Abrdn Canada complaint is the most important one for compliance teams: the SEC says exempt reporting adviser filings become available to the public without the Commission first reviewing and approving them.
Form ADV is filed through the Investment Adviser Registration Depository, or IARD, which FINRA operates under contract with the SEC. Public information then appears through IAPD. That system creates transparency. It does not convert every representation into a verified fact.
An exempt reporting adviser, or ERA, is also not the same thing as an SEC-registered investment adviser. The SEC’s accompanying Investor Alert on ERA filing scams says this directly:
- An ERA is not registered with the SEC.
- An ERA may advise private funds such as hedge funds, venture-capital funds, and private-equity funds.
- An ERA cannot provide investment advice directly to individual investors.
- The SEC does not issue certificates to ERAs or registered advisers.
- The SEC does not review an ERA’s abilities or qualifications merely because information appears on its websites.
That distinction needs to appear in onboarding procedures and customer-facing escalation scripts. “We found them in IAPD” is not a conclusion. The next questions are: What status does the record actually show? Does the firm’s pitch match that status? Can every critical identity and business claim be corroborated elsewhere?
This also sharpens the lesson in the Spartan Trading investment-adviser fraud case. Checking IAPD remains necessary. The new cases show why it cannot be the only check.
What the SEC charged—and what it did not
The complaints charge the defendants with violating Sections 204(a) and 207 of the Investment Advisers Act of 1940.
Section 204(a) supports the SEC’s recordkeeping and examination authority. Even though ERAs rely on exemptions from registration, the Abrdn Canada complaint says their books and records remain subject to SEC examination. Section 207 addresses material misstatements or omissions in reports or documents filed with the Commission.
| Item | Status as of August 28, 2026 |
|---|---|
| Defendants | 38 entities in separate Colorado federal cases |
| Charged provisions | Investment Advisers Act Sections 204(a) and 207 |
| Relief requested | Permanent securities-law injunctions, injunctions against filing Form ADV as an ERA, civil penalties, and other appropriate relief |
| Announced fixed penalty | None; the complaints ask the courts to impose civil penalties |
| Form ADV records | SEC says the 38 entities’ ERA filings were removed from IAPD |
| Supporting agency | SEC thanked the FBI and its Operation Level Up |
Do not turn “civil penalties sought” into “the SEC fined 38 firms.” It has not announced a settlement amount in this action. These are newly filed civil cases, and the relief remains for the courts to determine.
The litigation release also says the SEC’s Cyber and Emerging Technologies Unit conducted the investigation. That detail fits the method: digital filing access, foreign-jurisdiction IP indicators, fake web certificates, and online investor solicitation. The SEC credited the FBI’s Operation Level Up, an initiative focused on identifying and notifying victims of cryptocurrency investment fraud.
The control failure is “single-source trust”
Most onboarding procedures have a field labeled “regulatory registration verified.” The reviewer searches a database, saves a screenshot, checks the box, and moves on.
That control proves only that a record existed at a point in time. It does not prove that:
- the person communicating with you controls the listed entity;
- the address, phone number, assets, investors, auditor, or fund exists;
- the record reflects registration rather than exempt-reporting status;
- a website’s “SEC registered” statement accurately describes the filing;
- a regulatory identifier was not copied into a fake certificate or impersonation site.
The better control is multi-source identity and authorization verification. The owner should be named. At an RIA or wealth platform, that is usually Compliance Operations or the CCO’s delegate. At a bank or fintech onboarding an investment manager, the work may sit with Third-Party Risk, Financial Crimes, or Legal—with Compliance responsible for interpreting regulatory status.
| Control step | Owner | Evidence to retain | Escalation trigger |
|---|---|---|---|
| Pull IAPD record and identify the exact status | Compliance analyst | Timestamped PDF or system export | ERA marketed as “SEC registered” |
| Match legal name and formation record | Legal ops or onboarding | Secretary-of-state record and entity ID | Recent formation, agent-only address, or name mismatch |
| Validate physical address and phone | Onboarding operations | Independent address source and call log | Returned mail, virtual-only location, dead or unrelated number |
| Verify auditor and other licenses | Compliance or fund due diligence | Registry result and direct confirmation | Auditor absent from registry; CFTC/NFA claim has no match |
| Reconcile fund facts | Fund due diligence | PPM, financial statements, administrator/custodian confirmation | Repeated figures, inconsistent ownership, or unverifiable service providers |
| Compare public claims to filing status | Marketing compliance or investigations | Website capture and claim-to-source matrix | Fake certificate, approval language, or retail solicitation by an ERA |
| Resolve anomalies before approval | CCO or designated escalation owner | Issue record, disposition, approver, and closure evidence | Any critical claim supported only by the subject entity itself |
A practical aside: requesting another document from the same questionable counterparty is not independent verification. A certificate, audit letter, business license, and Form ADV can all sit inside the same manufactured evidence chain. Independence means the reviewer obtains evidence from the regulator, licensing body, service provider, custodian, or another authoritative source—not from a PDF bundle supplied by the applicant.
Five things to check Monday morning
1. Fix the “registration verified” field
Split it into at least three fields: record found, regulatory status interpreted, and identity independently corroborated. Require the reviewer to record whether the firm is SEC-registered, state-registered, an ERA, withdrawn, or absent.
2. Add a prohibited-claim rule for ERAs
Flag any ERA that offers advice directly to individual investors or says it is SEC-registered, approved, licensed, or certified. Those statements conflict with the SEC Investor Alert. Preserve the exact webpage, ad, email, or group-chat message before it disappears.
3. Run cross-record pattern detection
For higher-risk investment firms, compare addresses, phone numbers, fund names, asset figures, investor counts, auditors, websites, email domains, and ownership percentages across your portfolio. Repeated unusual figures should create a case for review, not an automatic rejection. The evidence in the 38 complaints shows why portfolio-level analysis catches what one-file-at-a-time due diligence does not.
4. Test service providers directly
Confirm the auditor through the relevant state board or other applicable public registry. Confirm the fund administrator and custodian using contact details obtained independently. If the firm claims commodity pool operator or commodity trading adviser status, search NFA BASIC and reconcile the exact legal name.
5. Reopen the last 12 months of higher-risk approvals
Prioritize ERAs, recently formed entities, firms using virtual addresses, crypto-related managers, and firms that supplied regulatory certificates. This is a risk-based lookback, not a demand to repeat every review. Record each anomaly in an issue log, assign an owner and due date, and preserve the closure evidence.
If the review produces a queue of exceptions, the Issues Management Tracker & Template gives you a clean way to assign owners, document decisions, and prove that red flags were resolved rather than merely noted.
The takeaway for adviser and vendor due diligence
The SEC’s false Form ADV cases do not make IAPD less useful. They define its limit.
Use the database to identify the record, status, filing history, and disclosures. Then corroborate the identity and the claims. A filing is one source in the evidence stack. It is not a regulator’s warranty.
For teams preparing for an SEC exam, this is also a reason to tighten the filing process itself. The SEC’s 2026 investment-adviser examination priorities and the site’s recent breakdown of Form ADV conflict-disclosure deficiencies address accuracy from the legitimate adviser’s side. The new cases show the mirror image: false data deliberately entered to exploit public trust.
The first control change is small. Replace “verified in IAPD” with “status confirmed in IAPD and identity corroborated independently.” Then make the reviewer show the evidence.
That one sentence closes the gap the alleged scheme was built to exploit.
Sources
- SEC Litigation Release No. 26622, “False Forms ADV Filings,” August 27, 2026
- SEC v. Abrdn Canada Limited, Complaint, No. 1:26-cv-03951 (D. Colo. filed August 27, 2026)
- SEC Office of Investor Education and Assistance, “Scammers Using SEC Exempt Reporting Adviser Filings to Look Legitimate,” August 27, 2026
- FBI Operation Level Up
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What did the SEC allege in the false Form ADV cases?
Does appearing in the SEC IAPD database mean an adviser is SEC-approved?
Is an exempt reporting adviser registered with the SEC?
Which Investment Advisers Act provisions did the SEC charge?
What should a compliance team verify beyond Form ADV?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
● Don't wait for your own enforcement action
Every case like this started with a gap someone knew about but hadn't documented. The template below gives you the framework to get ahead of it.
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Keep reading
Related posts.
Regulatory Compliance
FinCEN’s Banque Misr UAE Section 311 Rule: What U.S. Banks Need to Build Now
FinCEN’s Banque Misr UAE Section 311 proposal would require screening, correspondent notices, and documented controls at U.S. financial institutions.
Aug 28, 2026
Regulatory Compliance
The DOL Reverts to 1975: What the Retirement Security Rule Vacatur Means for Rollover Recommendations, PTE 2020-02, and Your Compliance Program
The DOL's 2024 Retirement Security Rule was vacated by the courts. The 1975 five-part test is back. Here's what that means for rollover recommendations, PTE 2020-02, and investment advice compliance programs that built controls around a rule that no longer exists.
Aug 27, 2026
Regulatory Compliance
SEC Free-Riding Case: The Instant Deposit Credit Controls Broker-Dealers Need to Test
The SEC's Mayur Baviskar free-riding case exposes instant deposit credit gaps across nine broker-dealers. Here is the control test to run now.
Aug 26, 2026