Nexora Groups Review 2026: Two Canadian Regulators, Four Domains, and a Phishing Warning on the Site Itself
Two Canadian regulators have named Nexora Groups: the BCSC on 14 July 2026 and the Ontario Securities Commission on 25 August 2026, between them listing four domains. As of 14 September 2026, Cloudflare serves a suspected phishing warning in place of the site. We score it 0.7 out of 10.
Quick facts
| Legal entity | "Nexora Groups Corp." per the OSC. Not published on the site |
|---|---|
| Regulator | Unlicensed |
| Licence number | None |
| Headquarters | 10 Upper Bank St, Canary Wharf Estate, London E14 5NP, per the OSC alert |
| Withdrawal time | Not published |
| Segregated funds | Not claimed |
| Website | nexoragroups.org,not linked: see our verdict |
You cannot currently read Nexora Groups’ website, and the reason is itself the most direct finding in this review. Type the address and the page that loads is not the broker’s. It is Cloudflare’s, and it is headed Suspected Phishing.
That is not a bot block or a regional restriction. It is the infrastructure provider in front of the site telling every visitor that the domain has been flagged as a phishing risk.
Two regulators, four domains
Nexora Groups has been named by two Canadian provincial regulators seven weeks apart, and between them they list four different domains.
| Regulator | Date | Domains named |
|---|---|---|
| British Columbia Securities Commission | 14 July 2026 | nexoragroups.org, nexoragroups.io |
| Ontario Securities Commission | 25 August 2026 | nexoragroups.net, nexoragroups.org |
The BCSC’s wording: “This company is not registered with the BC Securities Commission. If you have been approached by – or referred to – this entity, you should proceed with extreme caution and be aware of the risk before handing over any money.”
The OSC’s is more specific, and it names a corporate entity the site itself never does:
Nexora Markets (aka Nexora Groups Corp.) found at nexoragroups.net and nexoragroups.org is not registered in Ontario to engage in the business of trading in securities.
Only the .org appears on both lists. The BCSC saw a .io that Ontario did not; Ontario saw a .net that British Columbia did not. That is not two regulators disagreeing. It is a snapshot of an operation running several domains at once and rotating between them, caught at two different moments.
Why the extra domains matter more than they look
A regulator warning attaches to a string of text. Publish a warning about nexoragroups.org and it will rank in search for that domain, get picked up by warning aggregators, and become the first thing a cautious person finds.
Register the same brand on a different top-level domain, for about the price of a coffee, and none of that follows. The brand keeps every bit of its recognition. The warning stays behind on the old string.
Anybody checking this broker’s name needs to check which domain they were sent to. A person given the .net who searches the .org warning may reasonably conclude it is about somebody else.
The Canary Wharf address
The OSC alert records an address for the operation:
10 Upper Bank St, Canary Wharf Estate, London E14 5NP, UK
A Canary Wharf address has a specific job in this sector. It is among the most recognisable financial locations in Europe, and it is available from serviced-office and mail-forwarding providers to anyone with a card. It confers the appearance of a London institution at the cost of a monthly subscription.
The test is simple and it fails here: an address means something when a regulator’s register confirms it as a firm’s registered place of business. No register does. It appears in a warning, which is the opposite.
Note also what the geography implies. An operation using a London address, warned by regulators in British Columbia and Ontario, is not serving a local market. It is calling people in Canada from a business that presents itself as British.
What the phishing flag tells you
Cloudflare sits in front of an enormous share of the web and does not interstitial its own customers casually. A “Suspected Phishing” page means the domain has been flagged, through Cloudflare’s own detection or through abuse reports, as being used to harvest something from visitors.
For anyone who dealt with this firm, that has a practical consequence beyond the money. If you entered credentials on a Nexora domain, treat those credentials as compromised, and treat any password you reused elsewhere the same way. Change them now, starting with your email account and anything financial.
It also means the site’s own claims can no longer be read or quoted. This review does not attempt to describe what the pages said, because we could not read them, and we are not going to characterise content we have not seen.
What the score is made of
| Pillar | Weight | Score | Why |
|---|---|---|---|
| Regulation and licence tier | 30% | 0.2 | Two provincial regulators, seven weeks apart, four domains between them |
| Fund safety and withdrawals | 25% | 0.2 | No named entity on the site, no reachable operation, a phishing flag |
| Cost and execution | 15% | 2.0 | Nothing verifiable remains |
| Transparency | 15% | 0.3 | An accommodation address in a warning, and no entity the site admits to |
| Complaint record | 10% | 1.5 | Two regulator actions in seven weeks |
| Platform and support | 5% | 1.5 | No accessible site and no contact channel |
0.7 out of 10. The site being unreachable is not a neutral fact here: a firm nobody can contact is worse for somebody with money inside it than one that still answers the phone.
If you have already deposited
- Change your passwords first, before anything else. The phishing flag makes this the urgent step. Start with your email, then anything financial, and anywhere you reused the same password. Turn on two-factor authentication while you are there.
- Do not enter anything on any Nexora domain, including one that loads normally. Four are in circulation and at least three are flagged.
- Record which domain you actually used. Your bank will need it, and the four are treated separately by the two regulators.
- Card payments: chargeback for services not provided. Cite the BCSC listing of 14 July 2026 and the OSC alert of 25 August 2026 by date.
- Bank transfers: request a recall immediately and ask your bank to contact the beneficiary bank.
- Report it to the OSC, the BCSC, the Canadian Anti-Fraud Centre, and the FCA and Action Fraud in the UK given the London address.
- Refuse recovery offers. A collapsed operation leaves behind exactly the client list that gets resold to the next one.
The check worth learning
When you search a broker and find a regulator warning against a domain that is almost the one you are on, that is not a different company. Check the top-level domain, the hyphens and the spelling, character by character.
And if your browser or Cloudflare interrupts you with a security warning before a financial site loads, that is the whole answer. Close the tab.
Answered in detail
Safer alternatives
Rated Trusted or Neutral against the same six pillars. These link to our own reviews, not to the brokers, and no broker can pay to appear here.