Home / Brokers / Scam / Nexora Groups Review 2026: Two Canadian Regulators, Four Domains, and a Phishing Warning on the Site Itself
Scam

Nexora Groups Review 2026: Two Canadian Regulators, Four Domains, and a Phishing Warning on the Site Itself

Two Canadian regulators have named Nexora Groups: the BCSC on 14 July 2026 and the Ontario Securities Commission on 25 August 2026, between them listing four domains. As of 14 September 2026, Cloudflare serves a suspected phishing warning in place of the site. We score it 0.7 out of 10.

Quick facts

Legal entity"Nexora Groups Corp." per the OSC. Not published on the site
RegulatorUnlicensed
Licence numberNone
Headquarters10 Upper Bank St, Canary Wharf Estate, London E14 5NP, per the OSC alert
Withdrawal timeNot published
Segregated fundsNot claimed
Websitenexoragroups.org,not linked: see our verdict

You cannot currently read Nexora Groups’ website, and the reason is itself the most direct finding in this review. Type the address and the page that loads is not the broker’s. It is Cloudflare’s, and it is headed Suspected Phishing.

That is not a bot block or a regional restriction. It is the infrastructure provider in front of the site telling every visitor that the domain has been flagged as a phishing risk.

Two regulators, four domains

Nexora Groups has been named by two Canadian provincial regulators seven weeks apart, and between them they list four different domains.

Regulator Date Domains named
British Columbia Securities Commission 14 July 2026 nexoragroups.org, nexoragroups.io
Ontario Securities Commission 25 August 2026 nexoragroups.net, nexoragroups.org

The BCSC’s wording: “This company is not registered with the BC Securities Commission. If you have been approached by – or referred to – this entity, you should proceed with extreme caution and be aware of the risk before handing over any money.”

The OSC’s is more specific, and it names a corporate entity the site itself never does:

Nexora Markets (aka Nexora Groups Corp.) found at nexoragroups.net and nexoragroups.org is not registered in Ontario to engage in the business of trading in securities.

Only the .org appears on both lists. The BCSC saw a .io that Ontario did not; Ontario saw a .net that British Columbia did not. That is not two regulators disagreeing. It is a snapshot of an operation running several domains at once and rotating between them, caught at two different moments.

Why the extra domains matter more than they look

A regulator warning attaches to a string of text. Publish a warning about nexoragroups.org and it will rank in search for that domain, get picked up by warning aggregators, and become the first thing a cautious person finds.

Register the same brand on a different top-level domain, for about the price of a coffee, and none of that follows. The brand keeps every bit of its recognition. The warning stays behind on the old string.

Anybody checking this broker’s name needs to check which domain they were sent to. A person given the .net who searches the .org warning may reasonably conclude it is about somebody else.

The Canary Wharf address

The OSC alert records an address for the operation:

10 Upper Bank St, Canary Wharf Estate, London E14 5NP, UK

A Canary Wharf address has a specific job in this sector. It is among the most recognisable financial locations in Europe, and it is available from serviced-office and mail-forwarding providers to anyone with a card. It confers the appearance of a London institution at the cost of a monthly subscription.

The test is simple and it fails here: an address means something when a regulator’s register confirms it as a firm’s registered place of business. No register does. It appears in a warning, which is the opposite.

Note also what the geography implies. An operation using a London address, warned by regulators in British Columbia and Ontario, is not serving a local market. It is calling people in Canada from a business that presents itself as British.

What the phishing flag tells you

Cloudflare sits in front of an enormous share of the web and does not interstitial its own customers casually. A “Suspected Phishing” page means the domain has been flagged, through Cloudflare’s own detection or through abuse reports, as being used to harvest something from visitors.

For anyone who dealt with this firm, that has a practical consequence beyond the money. If you entered credentials on a Nexora domain, treat those credentials as compromised, and treat any password you reused elsewhere the same way. Change them now, starting with your email account and anything financial.

It also means the site’s own claims can no longer be read or quoted. This review does not attempt to describe what the pages said, because we could not read them, and we are not going to characterise content we have not seen.

What the score is made of

Pillar Weight Score Why
Regulation and licence tier 30% 0.2 Two provincial regulators, seven weeks apart, four domains between them
Fund safety and withdrawals 25% 0.2 No named entity on the site, no reachable operation, a phishing flag
Cost and execution 15% 2.0 Nothing verifiable remains
Transparency 15% 0.3 An accommodation address in a warning, and no entity the site admits to
Complaint record 10% 1.5 Two regulator actions in seven weeks
Platform and support 5% 1.5 No accessible site and no contact channel

0.7 out of 10. The site being unreachable is not a neutral fact here: a firm nobody can contact is worse for somebody with money inside it than one that still answers the phone.

If you have already deposited

  1. Change your passwords first, before anything else. The phishing flag makes this the urgent step. Start with your email, then anything financial, and anywhere you reused the same password. Turn on two-factor authentication while you are there.
  2. Do not enter anything on any Nexora domain, including one that loads normally. Four are in circulation and at least three are flagged.
  3. Record which domain you actually used. Your bank will need it, and the four are treated separately by the two regulators.
  4. Card payments: chargeback for services not provided. Cite the BCSC listing of 14 July 2026 and the OSC alert of 25 August 2026 by date.
  5. Bank transfers: request a recall immediately and ask your bank to contact the beneficiary bank.
  6. Report it to the OSC, the BCSC, the Canadian Anti-Fraud Centre, and the FCA and Action Fraud in the UK given the London address.
  7. Refuse recovery offers. A collapsed operation leaves behind exactly the client list that gets resold to the next one.

The check worth learning

When you search a broker and find a regulator warning against a domain that is almost the one you are on, that is not a different company. Check the top-level domain, the hyphens and the spelling, character by character.

And if your browser or Cloudflare interrupts you with a security warning before a financial site loads, that is the whole answer. Close the tab.

Answered in detail

Safer alternatives

Rated Trusted or Neutral against the same six pillars. These link to our own reviews, not to the brokers, and no broker can pay to appear here.

Verdict changelog

14 Sep 2026 Scam First rating. BCSC Investment Caution List 14 July 2026 naming nexoragroups.org and nexoragroups.io; OSC investor alert 25 August 2026 naming nexoragroups.net and nexoragroups.org and the entity Nexora Groups Corp. at 10 Upper Bank St, Canary Wharf, London. Checked 14 September 2026: .org, .io and .net all serve a Cloudflare "Suspected Phishing" interstitial, so the site's own content could not be read and is not characterised in the review.