Skip to content
RiskTemplates · The Daily Brief Friday, August 28, 2026
Wire SEC False Form ADV Cases: 38 Fake Advisers Turned a Public Filing Into a Trust Signal AUG 27

Breaking Regulatory Compliance

SEC False Form ADV Cases: 38 Fake Advisers Turned a Public Filing Into a Trust Signal

The SEC sued 38 entities over false Form ADV filings. Here is how compliance teams should verify advisers when a public filing is not proof of approval.

By Rebecca Leung · August 28, 2026 ·
Table of Contents

TL;DR

  • On August 27, 2026, the SEC sued 38 entities that allegedly used false Form ADV filings to look like legitimate U.S. investment advisers.
  • The alleged pattern included false Colorado offices, dead phone numbers, copy-pasted fund data, phantom auditors, missing commodity registrations, and fake SEC certificates.
  • There is no announced settlement or fixed penalty yet. The SEC is asking federal courts for injunctions and civil penalties.
  • The control lesson is blunt: a public regulatory filing is evidence to verify, not proof that the regulator approved the firm.

A record in an SEC database looks official. That is exactly why the alleged scheme worked.

In the SEC false Form ADV cases filed Thursday, 38 entities allegedly turned a reporting mechanism into a borrowed badge of legitimacy. They filed Forms ADV, appeared in the public Investment Adviser Public Disclosure database, and then—according to the SEC—used that visibility to make themselves look like real U.S. advisory firms to retail investors.

The SEC’s August 27 litigation release says the entities made material misrepresentations in Forms ADV during 2025 and 2026. Several connected to the filing system from IP addresses traced to foreign jurisdictions. The forms listed Colorado offices where the entities had no presence, phone numbers that were disconnected or belonged to unrelated businesses, nearly identical private-fund data, and audits by firms that could not be found in public accountancy registries.

This is more than an investor-scam warning. It exposes a due-diligence failure mode inside banks, wealth platforms, fund administrators, fintechs, and vendor-management programs: treating database presence as validation instead of the beginning of validation.

What the SEC’s 38 false Form ADV complaints allege

The SEC filed 38 separate complaints in the U.S. District Court for the District of Colorado. The defendants include names such as Abrdn Canada Limited, CryptoOrbit Ltd, LinkedIn Research Institute Ltd, Pinnacle Crypto Exchange Inc., Robin Markets Inc., Web3 University, and Wingspan Advisors LLC.

The cases are allegations, not final findings. But the repeated pattern matters because it shows how low-cost data inconsistencies can expose a supposedly regulated-looking identity.

Alleged representationWhat the SEC says it foundDue-diligence test that should catch it
A principal office in ColoradoNo presence at the listed address; SEC mail was returnedAddress validation using state records, independent business data, and live contact testing
A working business phoneDisconnected numbers or numbers belonging to unrelated businessesCall the number; independently source a second contact channel
A legitimate private-fund adviserOwnership and numerical data identical or nearly identical across many filingsCompare fund data against related filings and offering documents; flag improbable repetition
Audited private-fund financialsTwo named accounting firms could not be found in public federal or state registriesVerify firm licensing and partner identity directly with the applicable accountancy board
Commodity pool or trading-adviser activityNo corresponding registration in the entity’s nameReconcile the claim to CFTC and NFA records
SEC legitimacyWebsites allegedly displayed fake certificates claiming SEC registrationCompare the website claim with the exact status shown in IAPD; the SEC does not issue these certificates
Records supporting Form ADVEntities did not substantiate their claims after SEC requestsRequire source documents before onboarding or approving a relationship

One complaint shows how specific the pattern became. In SEC v. Abrdn Canada Limited, No. 1:26-cv-03951, the SEC alleges that the entity filed Form ADV on October 22, 2025, claiming one private fund with 89 investors, gross assets of $78,960,522, and a $50,000 minimum investment. It identified an auditor called Indicator Global and said the fund’s financial statements had received an unqualified audit opinion.

The SEC alleges the Denver address was not valid for the entity, the Arkansas-area-code phone number was disconnected, and Indicator Global was absent from public accountancy registries. The complaint also says the same filing pattern appeared across at least 37 other purported exempt reporting advisers, often using one of two gross-asset figures—$78,960,522 or $48,960,522—and one of two investor counts: 89 or 33.

Those repeated numbers are the kind of signal a human reviewer misses when each case is examined in isolation. They are also exactly the kind of signal a basic entity-resolution or duplicate-pattern rule can surface.

Why the filing appeared before the claims were tested

The operational detail buried in the Abrdn Canada complaint is the most important one for compliance teams: the SEC says exempt reporting adviser filings become available to the public without the Commission first reviewing and approving them.

Form ADV is filed through the Investment Adviser Registration Depository, or IARD, which FINRA operates under contract with the SEC. Public information then appears through IAPD. That system creates transparency. It does not convert every representation into a verified fact.

An exempt reporting adviser, or ERA, is also not the same thing as an SEC-registered investment adviser. The SEC’s accompanying Investor Alert on ERA filing scams says this directly:

  • An ERA is not registered with the SEC.
  • An ERA may advise private funds such as hedge funds, venture-capital funds, and private-equity funds.
  • An ERA cannot provide investment advice directly to individual investors.
  • The SEC does not issue certificates to ERAs or registered advisers.
  • The SEC does not review an ERA’s abilities or qualifications merely because information appears on its websites.

That distinction needs to appear in onboarding procedures and customer-facing escalation scripts. “We found them in IAPD” is not a conclusion. The next questions are: What status does the record actually show? Does the firm’s pitch match that status? Can every critical identity and business claim be corroborated elsewhere?

This also sharpens the lesson in the Spartan Trading investment-adviser fraud case. Checking IAPD remains necessary. The new cases show why it cannot be the only check.

What the SEC charged—and what it did not

The complaints charge the defendants with violating Sections 204(a) and 207 of the Investment Advisers Act of 1940.

Section 204(a) supports the SEC’s recordkeeping and examination authority. Even though ERAs rely on exemptions from registration, the Abrdn Canada complaint says their books and records remain subject to SEC examination. Section 207 addresses material misstatements or omissions in reports or documents filed with the Commission.

ItemStatus as of August 28, 2026
Defendants38 entities in separate Colorado federal cases
Charged provisionsInvestment Advisers Act Sections 204(a) and 207
Relief requestedPermanent securities-law injunctions, injunctions against filing Form ADV as an ERA, civil penalties, and other appropriate relief
Announced fixed penaltyNone; the complaints ask the courts to impose civil penalties
Form ADV recordsSEC says the 38 entities’ ERA filings were removed from IAPD
Supporting agencySEC thanked the FBI and its Operation Level Up

Do not turn “civil penalties sought” into “the SEC fined 38 firms.” It has not announced a settlement amount in this action. These are newly filed civil cases, and the relief remains for the courts to determine.

The litigation release also says the SEC’s Cyber and Emerging Technologies Unit conducted the investigation. That detail fits the method: digital filing access, foreign-jurisdiction IP indicators, fake web certificates, and online investor solicitation. The SEC credited the FBI’s Operation Level Up, an initiative focused on identifying and notifying victims of cryptocurrency investment fraud.

The control failure is “single-source trust”

Most onboarding procedures have a field labeled “regulatory registration verified.” The reviewer searches a database, saves a screenshot, checks the box, and moves on.

That control proves only that a record existed at a point in time. It does not prove that:

  • the person communicating with you controls the listed entity;
  • the address, phone number, assets, investors, auditor, or fund exists;
  • the record reflects registration rather than exempt-reporting status;
  • a website’s “SEC registered” statement accurately describes the filing;
  • a regulatory identifier was not copied into a fake certificate or impersonation site.

The better control is multi-source identity and authorization verification. The owner should be named. At an RIA or wealth platform, that is usually Compliance Operations or the CCO’s delegate. At a bank or fintech onboarding an investment manager, the work may sit with Third-Party Risk, Financial Crimes, or Legal—with Compliance responsible for interpreting regulatory status.

Control stepOwnerEvidence to retainEscalation trigger
Pull IAPD record and identify the exact statusCompliance analystTimestamped PDF or system exportERA marketed as “SEC registered”
Match legal name and formation recordLegal ops or onboardingSecretary-of-state record and entity IDRecent formation, agent-only address, or name mismatch
Validate physical address and phoneOnboarding operationsIndependent address source and call logReturned mail, virtual-only location, dead or unrelated number
Verify auditor and other licensesCompliance or fund due diligenceRegistry result and direct confirmationAuditor absent from registry; CFTC/NFA claim has no match
Reconcile fund factsFund due diligencePPM, financial statements, administrator/custodian confirmationRepeated figures, inconsistent ownership, or unverifiable service providers
Compare public claims to filing statusMarketing compliance or investigationsWebsite capture and claim-to-source matrixFake certificate, approval language, or retail solicitation by an ERA
Resolve anomalies before approvalCCO or designated escalation ownerIssue record, disposition, approver, and closure evidenceAny critical claim supported only by the subject entity itself

A practical aside: requesting another document from the same questionable counterparty is not independent verification. A certificate, audit letter, business license, and Form ADV can all sit inside the same manufactured evidence chain. Independence means the reviewer obtains evidence from the regulator, licensing body, service provider, custodian, or another authoritative source—not from a PDF bundle supplied by the applicant.

Five things to check Monday morning

1. Fix the “registration verified” field

Split it into at least three fields: record found, regulatory status interpreted, and identity independently corroborated. Require the reviewer to record whether the firm is SEC-registered, state-registered, an ERA, withdrawn, or absent.

2. Add a prohibited-claim rule for ERAs

Flag any ERA that offers advice directly to individual investors or says it is SEC-registered, approved, licensed, or certified. Those statements conflict with the SEC Investor Alert. Preserve the exact webpage, ad, email, or group-chat message before it disappears.

3. Run cross-record pattern detection

For higher-risk investment firms, compare addresses, phone numbers, fund names, asset figures, investor counts, auditors, websites, email domains, and ownership percentages across your portfolio. Repeated unusual figures should create a case for review, not an automatic rejection. The evidence in the 38 complaints shows why portfolio-level analysis catches what one-file-at-a-time due diligence does not.

4. Test service providers directly

Confirm the auditor through the relevant state board or other applicable public registry. Confirm the fund administrator and custodian using contact details obtained independently. If the firm claims commodity pool operator or commodity trading adviser status, search NFA BASIC and reconcile the exact legal name.

5. Reopen the last 12 months of higher-risk approvals

Prioritize ERAs, recently formed entities, firms using virtual addresses, crypto-related managers, and firms that supplied regulatory certificates. This is a risk-based lookback, not a demand to repeat every review. Record each anomaly in an issue log, assign an owner and due date, and preserve the closure evidence.

If the review produces a queue of exceptions, the Issues Management Tracker & Template gives you a clean way to assign owners, document decisions, and prove that red flags were resolved rather than merely noted.

The takeaway for adviser and vendor due diligence

The SEC’s false Form ADV cases do not make IAPD less useful. They define its limit.

Use the database to identify the record, status, filing history, and disclosures. Then corroborate the identity and the claims. A filing is one source in the evidence stack. It is not a regulator’s warranty.

For teams preparing for an SEC exam, this is also a reason to tighten the filing process itself. The SEC’s 2026 investment-adviser examination priorities and the site’s recent breakdown of Form ADV conflict-disclosure deficiencies address accuracy from the legitimate adviser’s side. The new cases show the mirror image: false data deliberately entered to exploit public trust.

The first control change is small. Replace “verified in IAPD” with “status confirmed in IAPD and identity corroborated independently.” Then make the reviewer show the evidence.

That one sentence closes the gap the alleged scheme was built to exploit.

Sources

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did the SEC allege in the false Form ADV cases?
The SEC alleged that 38 entities made material misrepresentations in Forms ADV filed in 2025 and 2026 to look like legitimate U.S. advisory firms. Alleged red flags included false Colorado addresses, disconnected or unrelated phone numbers, repeated fund data across filings, auditors absent from public accountancy registries, missing CFTC or NFA registrations, and failures to provide records requested by SEC staff.
Does appearing in the SEC IAPD database mean an adviser is SEC-approved?
No. IAPD is a public disclosure system, not an SEC endorsement. The SEC complaint says exempt reporting adviser filings become public without pre-publication review and approval. An IAPD record is a useful due-diligence input, but the identity, registration status, business claims, address, personnel, auditor, and other licenses still need independent verification.
Is an exempt reporting adviser registered with the SEC?
No. The SEC's August 27, 2026 Investor Alert states that an exempt reporting adviser, or ERA, is not registered with the SEC. An ERA reports limited information on Form ADV and may advise private funds, but it cannot offer investment advice directly to individual investors.
Which Investment Advisers Act provisions did the SEC charge?
The 38 complaints charge violations of Sections 204(a) and 207 of the Investment Advisers Act of 1940. The SEC seeks permanent injunctions, conduct-based injunctions preventing the entities from filing Form ADV as exempt reporting advisers, civil penalties, and other relief the courts consider appropriate.
What should a compliance team verify beyond Form ADV?
Verify the address and phone through independent sources; confirm entity status with the relevant secretary of state; validate named auditors in state or federal registries; reconcile claimed commodity activity to CFTC and NFA records; compare website claims with the exact Form ADV status; contact known personnel using independently sourced details; and preserve the evidence and reviewer sign-off.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

● Don't wait for your own enforcement action

Every case like this started with a gap someone knew about but hadn't documented. The template below gives you the framework to get ahead of it.

Issues Management Tracker & Template

End-to-end issues tracking and remediation management for risk and compliance teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.