More than a million people in the UK now buy shares, funds and crypto from an app on their phone. That is mostly a good thing: investing has never been more accessible. But every pound that flows into these apps makes them a more attractive target, and the security habits that protect your email account are not quite enough when your life savings sit behind a four-digit PIN.
The phishing problem has a new face
The classic attack on investors is no longer a dodgy email from a fake prince. It is a pixel-perfect clone of a genuine trading app or login page, often advertised through search engines and social media. You search for your platform’s name, tap the first result, enter your credentials, and hand them straight to an attacker. The FCA’s warning list gains hundreds of entries a year, many of them clones of legitimate, authorised firms, complete with copied branding and even cloned firm reference numbers.
The defence is boring and effective: never log in through an advert or a search result. Bookmark the genuine site, use the official app store listing linked from the company’s own website, and if an ‘account manager’ contacts you first, assume it is a scam until proven otherwise.
Check what FCA authorisation actually covers
Most people know to look for the phrase ‘FCA regulated’. Fewer know what it does and does not mean. Authorisation means the firm meets conduct and capital standards, and that cash and investments are typically protected up to 85,000 pounds by the FSCS if the firm itself fails. It does not mean the regulator will refund you if you are tricked into sending money to a fraudster, and it does not apply to most crypto holdings at all. Checking a firm on the FCA register takes two minutes: match the firm reference number on the register against the one on the website, because clone firms quote real numbers with fake contact details.
Five settings worth ten minutes of your time
First, turn on two-factor authentication, and prefer an authenticator app over SMS, since SIM-swap attacks remain a favourite way into financial accounts. Second, set a unique password for your trading account; credential-stuffing from old breaches is still how most accounts fall. Third, enable withdrawal confirmations and, where offered, whitelisted bank accounts, so money can only leave to an account in your name. Fourth, review linked devices and active sessions occasionally and remove anything you do not recognise. Fifth, keep the app updated, because trading platforms patch security issues just as often as any other software.
Security is now a comparison point, not a given
Security features vary between platforms far more than the glossy adverts suggest. Some offer biometric login, withdrawal locks and instant device management; others still rely on a password and hope. Independent reviewers have started to treat this as a ranking factor, which is long overdue. A comparison of the best trading apps in the UK now weighs security and FCA protections alongside fees and usability, which is a sensible way to shortlist before you trust an app with real money.
Research sites such as The Investors Centre open live accounts with their own deposits to test these platforms in practice, including how deposits, withdrawals and account protections behave in the real world rather than in the marketing copy.
The takeaway
You would not leave your front door unlocked because the neighbourhood seems nice. Treat your trading app the same way. Ten minutes spent on two-factor authentication, register checks and withdrawal controls is the cheapest insurance available to any investor, and choosing a platform that takes security as seriously as you do is the step most people skip. The markets carry enough risk on their own; your login should not add to it.


