September 2026: 47 SRA impersonation alerts
Our September register links 47 SRA scam alerts and explains what the count measures, the patterns it reveals and how firms can test client verification.
The brief
Our review of the SRA’s September scam-alert index found 47 distinct alerts dated 1–30 September 2026, checked at 19:23 BST on 30 September. The month had not yet closed. The full record links every alert, including impersonating emails, websites, calls, documents, social accounts and messaging profiles.
This is a count of warnings published by one regulator, not all scams, affected people or financial losses. The final seven-day period represented here, 22–28 September, contains 16 alerts. Our practical conclusion is to test how a client verifies a specific request through an independently established route. A genuine professional name, registration number or logo cannot by itself establish who sent an instruction or whether it is authorised.
The full record
The Solicitors Regulation Authority’s September index contained 47 distinct scam alerts when we reviewed it at 19:23 BST on 30 September 2026. Each entry is linked below. The reporting window is 1–30 September, with an explicit cutoff before the month’s end; later publications or corrections may change the total. Open the SRA’s filtered register.
The unit matters. One alert can describe several messages, websites or people. Several alerts can misuse the same genuine firm’s name. Our 47 is therefore a publication count, not 47 proven separate perpetrators, 47 victims or the number of scam attempts. It covers this SRA register, not every impersonation alert issued in the UK or elsewhere.
The count by publication period
- 1–7 September: 6 alerts.
- 8–14 September: 9 alerts.
- 15–21 September: 10 alerts.
- 22–28 September: 16 alerts.
- 29–30 September: 6 alerts.
The five periods sum to 47. The last period contains only two calendar days and should not be compared directly with a full week. No alert in this snapshot is dated 1 September. Dates are the regulator’s publication dates, not necessarily the dates on which the underlying communications were sent.
Correction to our earlier article: a complete reconciliation identifies 16 alerts dated 22–25 September, rather than the 14 in our original report. We had omitted the Georgina Crowhurst email alert and the Ahmed Ali telephone-call alert, both dated 22 September. The earlier article and its method have been corrected. The preceding 15–21 September period contains 10 alerts in this register. These corrected totals do not support the earlier briefing’s claim that warnings doubled.
Impersonation reaches beyond an inbox
The register includes TikTok accounts and WhatsApp messages misusing Clifford Chance’s name, a call and WhatsApp message misusing Ward & Rider’s name, and a profile misusing Tessa Manisty’s identity. A communication channel’s familiarity does not establish the sender’s authority.
The practical takeaway is to give clients an independent route to check the particular request. That route must be established before an unexpected message arrives. A client should not have to rely on the telephone number or link supplied in the questionable communication to decide whether it is genuine.
Routine documents can carry the false authority
Several alerts concern documents that resemble ordinary business administration: invoice-related emails, a tenancy-change letter sent to an energy company, and acquisition and non-disclosure documents. The issue is not confined to a dramatic demand for emergency funds.
Our proposed exercise is to use a fictional change to an existing instruction. Ask the receiving colleague to identify the originator, their authority, the exact change and the required confirmation. Record whether the process depends on an assumption such as recognising a logo or recalling a similar email.
A recovery offer needs the same independent check
The register also includes purported assistance with recovering investment or cryptocurrency funds, including Cyber Law Solution and communications misusing CG Law’s details. These alerts illustrate why a request framed as help should still be checked. They do not establish how often a previously affected person is targeted again.
In the Cross Border Legal alert, the SRA advises verifying suspect correspondence through reliable, established contact with the genuine firm. Our analysis is that the firm’s response should confirm the precise instruction and leave a record of who supplied the answer. Confirmation that a solicitor exists is not confirmation that the solicitor sent this request.
What this first register can become
This is a reproducible starting series for The Formal Record. Future monthly reports can use the same source, date rule and deduplication method. That would support comparisons of publication activity. Claims about fraud prevalence, losses or control effectiveness would still require other evidence.
Our immediate benchmark proposal concerns the reader’s experience: can an unfamiliar client reach the approved verification route and obtain an attributable answer without relying on the suspicious message? Record completion, mistaken assumptions and unresolved handoffs. We have not yet run that benchmark, and these alert counts are not its results.
Complete September alert register
Each link leads to the SRA’s own alert. The names below identify identities or purported entities discussed in the warnings; inclusion is not an allegation of wrongdoing by the genuine professionals or firms whose details were misused.
30 September
- Leeds Family Law: invoices
- Andrew Kidd: email and website
- Masood Haider: tenancy letter
- SM Solicitors: emails and letterhead
- Ashraf Legal: website
29 September
25 September
24 September
- Andrew Hamilton: inheritance emails
- Hausfeld: compensation emails
- Hamilton Law: correspondence
- Cyber Law Solution: recovery offer
- Al-Taawon Law: recovery document
- Clarke Willmott: tenancy letter
23 September
- Longfords: lease letter
- Hilton Law: website
- Ward & Rider: WhatsApp and call
- Atlee Chung: website
- Mark Shillito: email
22 September
21 September
18 September
16 September
- Raj Law: calls and website
- Kate Andrews: property emails
- Amandeep Kaur Matharu: profile
- Complex Law: telephone calls
- Saunders & Partners: correspondence and calls
- Manak Lawyers: website
15 September
14 September
11 September
- Billy Tee: inheritance emails
- CG Law: crypto-recovery communications
- Samuel Ashford: profile
- Carlos Hernandez Pardo: recovery email
10 September
9 September
8 September
7 September
4 September
3 September
2 September
We selected September 2026 as both the start and end month in the live SRA scam-alert search, reviewed all three result pages and recorded each unique September alert URL once. All 47 individual links were opened and checked. Publication dates determine inclusion. The snapshot cutoff is 19:23 BST (18:23 UTC), 30 September 2026. We did not count messages, victims, losses or perpetrators, infer incident dates, or estimate unreported fraud. The five publication-period totals are 6, 9, 10, 16 and 6. Short register labels are editorial descriptions. Examples are qualitative; no channel-frequency estimate or comparison with other months is claimed. The operational exercises are proposals and have not been run as benchmarks.