The FCA flagged FxBlue Bridge on 10 September 2026. Learn why an old address can mislead, how to check the genuine firm and what to do before paying.
The FCA has warned against FxBlue Bridge, identifying it as an unauthorised clone impersonating FXPRO UK Limited. The genuine firm has no connection with the clone. If you have been approached under that name, pause any payment and check the contact route independently—not just the licence number on a website. FCA warning, 10 September 2026.
The warning identifies fxbluebridges.com and says the clone uses the genuine firm's previous address. It names FXPRO UK Limited, reference number 509956, as the authorised business being impersonated, and lists www.fxpro.com as its website. These are two different identities, not interchangeable names for one service. The suspected domain is shown here for identification, not as a link to visit. Read the original notice.
An address that once belonged to a real business can make an old brochure, copied certificate or search result look convincing. But historical accuracy is not proof that today's sender represents that business. The useful question is not simply “Does this address exist?” It is “Can I independently connect this person, this website and this proposed account to the current authorised entity?”
That distinction changes the next step. Searching for the address again may only reproduce the same historical material. Instead, establish a fresh contact route from the regulator's own website and ask about the exact domain and person who contacted you.
The FCA explains that clones can combine genuine registration information with different phone numbers, websites or email addresses. It recommends checking both the firm's permissions and its contact details through Firm Checker. A caller saying that the register is outdated is not a reason to accept the caller's replacement details. FCA guidance on clone firms.
Use this short worksheet. For each item, record what you received and the independent answer. Do not let a match in one field substitute for checking the others.
Record the name, account handle and original message. Ask whether the genuine firm can confirm this person through a separately obtained contact route.
Record the exact hostname already present in the message. Check whether the current official record supports that domain. Watch for extra words and altered endings.
Record the full company name on the proposed agreement. Establish which entity would actually enter the contract with you, rather than relying on the brand at the top of the page.
Record the address shown on the document and its date. Ask whether the document is current and whether it establishes anything about the sender's identity.
Record the beneficiary, amount, currency and reference. Ask the genuine firm to confirm those instructions independently before acting on them.
Do not open the suspected site merely to complete the worksheet. Work from messages and records you already have. There is no need to install an app, upload identification or make a small deposit to test an identity claim.
When contacting the genuine business, make the question precise: “I received a message from [sender] directing me to [domain]. Is this person and this domain authorised to act for your company?” Ask about the proposed payment instructions separately. A general answer that a company is regulated does not answer either question.
Our official-register verification guide explains the wider licence-checking process. For the difference between a brand and the company on your agreement, see broker entity versus brand.
Stop the conversation long enough to make an independent check. Save the original message, the sender's account identifier and any attachment name without opening unfamiliar files. Note the date, time and how the approach began. If you report it, describe what happened rather than adding assumptions about who operates the account.
Keep a clean record of what was requested: account opening, an identification document, a payment, a remote-access session or something else. Separate those requests from actions you actually took. This makes the report more useful and avoids an ambiguous statement such as “they accessed my account” when all you received was an invitation.
Use the reporting route linked from the FCA warning. Do not send private documents to a contact supplied by the suspected sender as a supposed regulator or investigator.
Contact your bank or payment provider promptly using its independently verified support route. Explain that you suspect an impersonation scam and give the payment date, amount, recipient details and transaction reference. Ask what protective steps and reporting options apply to your particular payment. The FCA's fraudulent-payments guidance distinguishes between payment types; reimbursement should not be assumed.
Create a chronological evidence folder with original messages, transaction receipts and the agreement you were shown. Retain unedited originals and make redacted copies if you need to share information publicly. Do not post identity documents, complete bank details or authentication codes in a public review. Our complaint evidence template can help organise the record.
If you shared a password, change it through the real service and review account access. If you installed remote-access software or disclosed banking credentials, tell your bank explicitly rather than describing the problem only as a delayed withdrawal.
Be cautious of a second approach promising to recover the funds for an advance fee. The FCA describes recovery-room scams in which victims are targeted again with recovery offers. A person knowing the name of the platform or the amount lost is not, by itself, proof of official status. FCA recovery-room warning.
No. The notice expressly separates the impersonator from the genuine authorised business. Read that distinction before sharing the warning; it is not evidence against every business with a similar name.
No. It identifies a register entry, not necessarily the person sending you a message. Identity, permissions and the contact route still need checking. FCA clone-firm guidance.
Do not resolve the disagreement using another document supplied by the same sender. Ask the genuine business through independently sourced contact details. Treat the mismatch as an unresolved question and keep the payment paused.
A payment arriving would not prove who controls the website or whether your contract is with an authorised firm. Use identity verification, not another transaction, to answer that question.
This guide provides information, not a recovery service or a reimbursement promise. Your payment provider and the relevant authorities can explain the options for your circumstances. If you need advice about a legal claim, consult a qualified adviser.
Checked on 12 September 2026. This article analyses a specific UK regulatory warning; it is not an assessment of every service using similar words, and it is not a recommendation to open a trading account. The practical worksheet is FXCN's editorial guidance, not a regulator-issued form. We have not tested the suspected platform, verified individual customer losses or identified its operators.
The cover is an AI-generated editorial illustration of identity checks, not a screenshot of a regulator's records. Consult the linked FCA notice for the current official details, since warnings can be updated.