An investment account can be emptied without a criminal ever signing in to the victim’s existing brokerage profile. That uncomfortable fact sits at the center of ACATS brokerage fraud.
The scheme abuses a legitimate system designed to move investments efficiently between financial firms. Understanding that distinction matters because the best defenses are different from the usual advice about suspicious emails and strong passwords.

Overview
The ACATS brokerage scam is a form of identity theft in which a criminal attempts to transfer investments from a victim’s brokerage account into another account controlled by the criminal.
ACATS stands for Automated Customer Account Transfer Service. It is operated by the National Securities Clearing Corporation and is widely used by brokerage firms to automate account transfers.
A normal transfer begins when an investor opens an account at a new brokerage and asks that firm to bring over assets held at the old brokerage. The receiving firm submits the transfer request, and the delivering firm reviews the identifying information before releasing eligible assets.
The fraud version begins with stolen personal data. A criminal may already have the victim’s name, address, Social Security number, date of birth, brokerage name, and account number from a data breach, stolen statement, compromised mailbox, phishing attack, or identity-theft marketplace.
Using that information, the criminal opens an account in the victim’s name at a different financial firm. The criminal then submits an apparently ordinary request to transfer the real victim’s investments into the newly opened account.
FINRA Regulatory Notice 23-06 describes this exact pattern. FINRA says bad actors may use stolen personally identifiable information to open a new brokerage account and then request the transfer of a legitimate customer’s assets through ACATS.
The system is not fraudulent. The transfer request is. ACATS processes millions of legitimate instructions, and speed is one of its benefits. Unfortunately, speed also creates a narrow window in which a victim or financial institution must recognize an unauthorized request.
Why an account password may not stop the transfer
Many people assume that a criminal must know the password to the existing brokerage account. That is not always true in an ACATS identity-theft case.
The request is initiated through the receiving firm, not by signing in to the victim’s old brokerage profile. A thief who has enough identity and account information may try to make the receiving account and transfer instruction appear to belong to the same person.
Two-factor authentication still protects the existing online account and should remain enabled. It can prevent other forms of theft, unauthorized trades, changed contact details, and direct withdrawals. It simply is not a complete answer to a transfer request created outside that login session.
What an unexpected transfer alert may look like
Account Transfer Request Received
We received instructions from another financial institution to transfer the assets in your brokerage account.
If you did not authorize this request, contact our fraud department immediately. Do not reply to this message.
Transfer status: Pending validation
A real brokerage may send an email, app notification, secure message, letter, or phone call when it receives a transfer request. Criminals also send fake versions, so the alert itself must be verified through the brokerage app, a bookmarked website, or the number printed on a statement.
Common variations of the transfer message
- “Your full account transfer has been initiated”
- “We received a request from another broker to transfer your assets”
- “Certain securities are restricted while your transfer is processing”
- “Your account will be closed after the residual balance is transferred”
- “Action required to verify an outgoing ACATS request”
- “A new external financial institution was added to your profile”
- “Your transfer request has been validated”
- “Your investment account is moving to a new custodian”
Some fraudulent messages are phishing bait rather than evidence of a real transfer. They direct the recipient to a fake brokerage login page. The safe response is the same: do not use the message link and verify independently.
Warning signs that deserve immediate attention
- An alert mentions a brokerage firm where you never opened an account.
- Your existing broker says a full or partial transfer is pending.
- You receive a welcome letter, tax form, or identity-verification request from an unfamiliar broker.
- Positions in your portfolio become temporarily restricted without an explanation you recognize.
- Your mailing address, email address, phone number, or trusted contact changes unexpectedly.
- A statement or account document disappears from your mailbox.
- Your credit report shows a new inquiry or financial account you did not request.
- A fraudster calls and tells you to ignore genuine alerts because they are “system errors.”
Do not wait for money to disappear. A notice that a request is pending is the moment to act, even if the representative says the transfer has not yet completed.
Full transfers, partial transfers and residual sweeps
A full ACATS request attempts to move the entire eligible account. Depending on the process, the delivering account may later be closed. A partial request names specific assets or amounts and may be harder for a victim to notice.
Some assets cannot move automatically. Cash, stocks, bonds, listed options, and many common funds are generally transferable, while certain proprietary products or other holdings may require special handling.
Residual sweeps can move dividends, interest, or cash that arrives after the main transfer. This means monitoring should continue even after the first suspicious request is stopped or reversed.
How The Operation Works
1. The criminal builds an identity profile
The operation starts long before the victim sees an alert. Stolen identity data may come from an unrelated breach, phishing form, malware infection, mail theft, insider abuse, or a document discarded without shredding.
A brokerage statement is especially valuable because it can reveal the financial institution, account title, partial or complete account number, holdings, address, and approximate balance.
Criminals combine records from several sources. One leak may provide a Social Security number, another an old address, and a stolen statement the account number needed to make a transfer request look plausible.
2. A fraudulent receiving account is opened
The thief applies for an account at another brokerage using the victim’s identity. The contact email, phone number, device, or funding relationship may remain under the thief’s control even though the legal name and identity fields match the victim.
Financial firms use identity-verification controls, but criminals test multiple firms, use forged documents, exploit compromised accounts, or recruit money mules until one application succeeds.
3. The transfer instruction is submitted through ACATS
The receiving firm enters the transfer information. According to Investor.gov’s explanation of brokerage transfers, the new firm starts the transfer process and communicates with the old firm through ACATS.
The request includes identifying details intended to match the existing account. In a legitimate transfer, the customer provided them. In the scam, the thief obtained them without permission.
4. The delivering brokerage validates or rejects the request
The old brokerage reviews whether account information matches and whether an exception applies. FINRA rules impose short operational timeframes, which help legitimate investors but make prompt fraud detection essential.
Automated matching alone cannot understand that a correct Social Security number was stolen. Strong firms use additional signals such as recent contact changes, unusual devices, inconsistent addresses, high-risk receiving accounts, customer alerts, or out-of-pattern transfer behavior.
5. Assets are moved and may be liquidated
If the request passes review, eligible securities and cash move to the receiving account. The criminal may sell investments, convert the balance to cash, or try to transfer proceeds to another bank, brokerage, cryptocurrency service, or mule account.
Each additional movement complicates recovery. That is why the victim should contact both the delivering and receiving firms as soon as either is identified.
6. The criminal tries to delay discovery
The thief may change contact details, redirect mail, flood the victim’s inbox, impersonate the brokerage, or claim a real security warning is routine. Some criminals time the request before a weekend or while the victim is traveling.
They may also send a fake support call after the transfer begins. The caller asks for a security code under the pretense of stopping the transaction, while actually using that code to approve another account change.
7. Proceeds are moved beyond the first destination
Once the assets are under the criminal’s control, the receiving account may be only a temporary waypoint. Funds can be divided, wired, withdrawn, or converted to make tracing more difficult.
A fast report gives fraud teams a better chance to freeze the receiving account and preserve records before the chain expands.
How to reduce the risk before anything happens
- Ask about an account-transfer lock. Some brokers offer a restriction that blocks outbound ACATS requests until the customer completes additional verification.
- Enable every alert available. Turn on notifications for transfers, profile changes, new linked accounts, address changes, trades, withdrawals, and logins.
- Protect statements. Use secure electronic delivery, lock your mailbox, and shred documents containing account identifiers.
- Use unique credentials. A password manager and multi-factor authentication reduce the damage from credential theft.
- Freeze your credit when appropriate. A security freeze can make it harder to open accounts in your identity, though financial-account systems and policies vary.
- Keep contact information current. Alerts cannot help if they go to an abandoned email address or old phone number.
- Name a trusted contact. This can give the brokerage another way to address concerns without granting that person authority over the account.
- Review accounts frequently. Do not rely only on monthly statements, especially after an identity-theft incident.
What To Do If You Detect an Unauthorized Transfer
- Call the delivering brokerage immediately. Use the number in the official app, on a statement, or on the firm’s verified website. Say clearly that the ACATS request is unauthorized identity theft and ask for the fraud or account-transfer team.
- Ask for an immediate stop, reject, freeze, or recall. The exact action depends on the transfer stage. Request a case number and write down the representative’s name, time, and instructions.
- Identify and contact the receiving firm. Ask your broker for the receiving institution and transfer reference. Tell the receiving firm’s fraud department that an account may have been opened in your identity.
- Secure the real brokerage account. Change the password from a trusted device, sign out other sessions, enable stronger authentication, verify contact details, and add any transfer or withdrawal lock offered.
- Do not share a one-time code with an inbound caller. A real investigator can work through the firm’s authenticated process. If someone calls, hang up and call the official number yourself.
- Preserve every record. Save alerts, secure messages, statements, transfer references, caller numbers, envelopes, screenshots, and notes. Do not rely on links remaining active.
- Report identity theft. Create a recovery plan through IdentityTheft.gov. File a police report if the brokerage or identity-recovery process requests one.
- Freeze credit reports. Contact Equifax, Experian, and TransUnion directly. Review reports for unfamiliar inquiries, addresses, and accounts.
- Check other financial institutions. The same identity package may be used against bank accounts, retirement plans, credit cards, tax accounts, or additional brokerages.
- Escalate unresolved brokerage problems. If a firm does not respond appropriately, consider a complaint through FINRA, the SEC, or the relevant state securities regulator after documenting your efforts.
- Continue monitoring after the main transfer is stopped. Watch for residual cash movements, new applications, changed tax documents, and follow-up social-engineering calls.
Stay calm but move quickly. An unauthorized transfer request does not automatically mean the assets are gone, and even a completed transfer may be recoverable when both firms receive a prompt, well-documented fraud report.
The Bottom Line
ACATS is a legitimate transfer system, but identity thieves can abuse it by opening another brokerage account in a victim’s name and requesting the victim’s investments.
Strong passwords and two-factor authentication remain important, yet they are not the whole defense because the fraudulent request may start at another firm. Transfer locks, account alerts, protected statements, credit freezes, and frequent review add the missing layers.
If an unfamiliar transfer appears, contact both firms through verified channels immediately. Do not use a link or number supplied by an unexpected message, and do not let an inbound caller talk you into sharing a security code.