Client Security Advisory
Important Security Reminder — Protecting Your Accounts from Phishing and Impersonation Fraud
Reference: UCAM-SEC-2026-01 · Issued: 10 September 2026
Dear Investor,
We are issuing this security reminder to help you protect against phishing and impersonation fraud. Cybercriminals increasingly target wealth management clients by sending convincing emails, messages or phone calls that appear to come from trusted organisations. Advances in AI have made these attacks easier to carry out and harder to recognise, which means any individual can now be targeted convincingly.
Clients may receive fraudulent communications that impersonate UCapital Asset Management LLP, TPP and/or Interactive Brokers. These communications may attempt to obtain identity documents, login credentials, security codes or other sensitive account information.
Please remain vigilant and follow these security precautions:
Verify the sender. Genuine emails from UCapital will only be sent from our official domains:
- @ucapital.com
- @ucapital-am.com
Anything else is not us — including addresses that add a hyphen, a space, an extra letter, or a different ending. Always check the full sender address carefully for subtle misspellings or altered domains. Impersonation attempts typically differ from the real address by a single character, and the display name shown by your email software may look entirely correct even when the underlying address does not. Please check the full address, not the display name.
Never share passwords or security codes. Neither UCapital, TPP nor Interactive Brokers will ask you to disclose your passwords, PINs, one-time verification codes or authentication credentials by email, telephone or messaging apps.
Be cautious with links and invitations. Carefully consider emails you receive with embedded links, calendar invitations or unexpected attachments. Do not click on them unless you are confident they are genuine. These are common methods used by fraudsters to compromise computers, email accounts and online accounts. If in doubt, contact UCapital Asset Management.
Protect your email account. Use a strong, unique password, enable multi-factor authentication where available and update your password periodically.
Treat “urgent” requests with great caution. Be suspicious of messages creating urgency, requesting identity documents, asking you to verify your account or instructing you to change payment or banking details.
Do not move money. A common fraud is to suggest that the money held in your account is at risk from criminals, or that there is a security failing on the account, and to ask you to transfer it to a new account elsewhere to protect it. Please note that we would not make such a request. Interactive Brokers is an FCA regulated broker and custodian of your assets, and as such would maintain them securely in accordance with FCA requirements.
Use trusted contact details. If you are unsure whether a communication is genuine, do not reply to the message. Instead, contact your usual UCapital or TPP representative using an email address you already know to be genuine.
Remember: we will never ask you by email to provide your Interactive Brokers login credentials, your email password, or one-time authentication codes.
If you receive a suspicious communication
- Do not click any links or open attachments — even if the message appears within an existing conversation, quotes genuine previous correspondence, or refers to real people and real account details. Attackers copy authentic material to appear credible.
- Do not provide personal or account information.
- Forward the message to security@ucapital.com as an attachment rather than as a standard forward, so that the technical detail we need in order to investigate is preserved. In most email applications you can do this by selecting the message and choosing “Forward as attachment”. If that option is not available, a normal forward is still helpful.
- Contact your usual UCapital or TPP representative using verified contact details so the communication can be reviewed.
Please report suspected impersonation attempts
If you believe you have received or responded to a communication that impersonates UCapital, TPP, Interactive Brokers or another trusted organisation in an attempt to extract personal information, obtain account access, persuade you to move money, or carry out any other fraudulent activity, please contact UCapital immediately using your usual verified contact details. Prompt reporting allows us to help protect you and other clients from ongoing fraud attempts.
There is no disadvantage to you in telling us. Early notice is what allows us to act.
If you have already replied to something like this
Please act now, in this order, and then contact us.
- Change the password on the affected account directly at the provider — by typing the address into your browser rather than following any link.
- Enable two-factor authentication on that account if it is not already enabled.
- Contact the provider. For brokerage accounts, ask Interactive Brokers to review recent access and any pending instructions.
- Update passwords on any other financial application where funds or assets can be accessed or moved.
Verifying this notice
This notice is published at https://ucapital.com/security-advisory. If you have received an email referring you here and you have any doubt that it is genuine, this page is the authoritative copy.
Protecting your assets and personal information is a shared responsibility. Thank you for your continued trust.
Operations Team — UCapital Asset Management