KEMETIC MINDS
Cybersecurity & Scam Daily Briefing — August 13, 2026
Photo: Gustavo Fring via Pexels (source)
- WhatsApp unveils new scam alert feature (CyberSecurityNews, 2026)
- Surfshark launches Scam Text Protection (Bing News, 2026)
- Fake Amazon refund text steals phone users’ data (FTC, 2026)
- Akira ransomware affiliate uses Safe Mode to disable endpoint security (Huntress, 2026)
- SM-Detector model detects smishing messages with 99.63% accuracy (Ghourabi, 2021, Concurrency and Computation: Practice and Experience)
- AI-based cybersecurity awareness training reduces risk scores (Ansari, 2022, International Journal of Smart Sensor and Adhoc Network)
1. The WhatsApp “Wrong Code” Account-Takeover Scam
Meta began a limited beta of a new WhatsApp feature called Scam Alert on August 12, 2026 — an optional, on-device machine-learning check that flags likely scam messages from people outside your contacts, without sending any message content off your phone (Meta Engineering, 2026).
The feature is aimed squarely at the kind of social-engineering scam WhatsApp users have actually been hit with this month: attackers trigger WhatsApp’s real account-verification code to be sent to a victim’s phone, then pose as a friend or “WhatsApp support” and ask the victim to read the code back to them — handing over full control of the account (Forbes, 2026).
Watch how a real the whatsapp “wrong code” takeover unfolds — and the red flags that give it away.
How to Avoid This Scam
- Never read a WhatsApp verification code to anyone, even someone who sounds like a friend in a panic — that code is the only thing standing between an attacker and your account.
- Turn on Two-Step Verification under Settings > Account so a stolen code alone isn’t enough to take over your account.
- If you’re eligible, opt in to the new Scam Alert beta feature, which flags likely-scam messages from non-contacts directly in the chat.
- If a “friend” asks for a code, verify by calling them on a number you already have saved — never the number that just messaged you.

2. The Fake Delivery-Fee Text Surfshark’s New Feature Targets
Surfshark launched a real-time Scam Text Protection feature this month that scans incoming text messages for known scam sender numbers, scam-pattern language, and malicious links before you ever tap them — available to Surfshark One and One+ subscribers on iOS and Android (Surfshark, 2026; TechRadar, 2026).
The feature is built for exactly the kind of “smishing” (SMS phishing) text that’s been flooding phones this year: a fake delivery notice asking for a small “customs fee” or “redelivery fee,” with a link to a lookalike site built to steal payment details.
Watch how a real the fake delivery-fee text unfolds — and the red flags that give it away.
How to Avoid This Scam
- Never tap a payment link in an unexpected delivery text — go to the carrier’s real app or website directly instead.
- Real carriers (USPS, UPS, FedEx) do not text you a link to pay a small release fee for a package.
- Turn on a scam-text filtering feature if your carrier or security app offers one; on iPhone, suspected scam texts can be automatically routed to a separate spam folder.
- If you weren’t expecting a package, that’s the first red flag — verify directly with the retailer or carrier before doing anything else.
3. The Fake Amazon “No Return Needed” Refund Text
The FTC is warning shoppers about a text message impersonating Amazon that claims a “routine quality inspection” found a problem with a recent order, and offers a full refund — no return required (FTC, 2026).
The catch: the link in the text doesn’t go to Amazon at all. It leads to a fake site built to steal your Amazon login credentials and payment information, according to the FTC.
Watch how a real the fake amazon “refund” text unfolds — and the red flags that give it away.
How to Avoid This Scam
- A refund that doesn’t require you to return the item is not how Amazon refunds actually work — treat that offer itself as the red flag.
- Check your real order status only inside the official Amazon app or by typing amazon.com directly into your browser — never through a link in a text.
- Report the text as spam by forwarding it to 7726, or use your phone’s built-in “report junk” option (FTC, 2026).
- If you already clicked and entered information, change your Amazon password immediately and check your account’s order history and saved payment methods for anything unfamiliar.

4. How the Akira Ransomware Safe Mode Attack Actually Broke In
Huntress researchers documented the first known Akira ransomware attack to abuse Windows Safe Mode to disable endpoint security — and it started with something far more ordinary than malware: a SonicWall SSL VPN account with no multi-factor authentication (Huntress, 2026).
The attacker credential-sprayed that account and got in after seven minutes of failed login attempts, then rebooted the target server into Safe Mode with Networking — which loads only core Windows drivers, disabling Microsoft Defender and third-party endpoint tools by design (Huntress, 2026).
The ransomware itself actually failed to encrypt the victim’s files, running into memory errors in Safe Mode’s stripped-down environment. But the attacker had already stolen credentials and file contents beforehand, so the extortion threat landed regardless of whether encryption worked (Huntress, 2026).
Watch how a real how the akira safe mode attack actually broke in unfolds — and the red flags that give it away.
How to Avoid This Scam
- Require multi-factor authentication on every VPN account, not just administrator accounts — this attack succeeded specifically because MFA was missing.
- Monitor for bursts of failed VPN logins that suddenly resolve into a successful one — that pattern is a credential-spray attack in progress.
- Alert on unexpected Safe Mode reboots: watch for msconfig.exe or bcdedit activity, Kernel-Boot event 27 with SAFEBOOT options, and new Safe Boot registry keys (Huntress, 2026).
- Assume data was stolen even if encryption fails or is blocked — attackers increasingly exfiltrate first and encrypt second (or not at all), so a failed encryption attempt is not the same as a defeated attack.
What the Research Actually Says
A study by Ghourabi (2021, Concurrency and Computation: Practice and Experience) found that the SM-Detector model can detect smishing messages with 99.63% accuracy.
Research by Ansari (2022, International Journal of Smart Sensor and Adhoc Network) showed that AI-based cybersecurity awareness training can reduce risk scores.
Today’s Family Safety Checklist
- Never share a verification code, one-time password, or your card number in response to a text or chat message — no legitimate company or contact needs it that way.
- Go directly to the app or official website for any account, delivery, or order question instead of tapping a link in a message.
- Turn on two-factor or two-step verification everywhere it’s offered, and use a scam-text filtering feature if your phone or security app has one.
- Cybersecurity awareness training measurably lowers risk scores (Ansari, 2022) — the pattern above repeats across scams: urgency, an unfamiliar link, and a request for something you’d never normally hand over.
SUPPORT KEMETIC MINDS
Enjoying this coverage? Back the work and find every way to connect with us in one place.
Support the Page →Kemetic Minds Analysis
Today’s briefing pulled from 4 news sources and 3 peer-reviewed studies. Today’s strongest research signal comes from Concurrency and Computation: Practice and Experience (2021), cited 25 times — the kind of study worth weighing more heavily than a single news anecdote. The pattern worth watching isn’t any single scam headline — it’s whether today’s news matches what the research already predicts about who gets targeted and what actually reduces risk, or whether it’s a genuinely new variant the literature hasn’t caught up to yet.
References
- CyberSecurityNews. (2026, August 12). WhatsApp Unveils New Scam Alert Feature to Protect Users from Social Engineering Attacks – CyberSecurityNews. news.google.com
- Bing News. (2026, August 12). Surfshark launches Scam Text Protection for suspicious SMS. cybernews.com
- Bing News. (2026, August 12). The FTC says a fake Amazon refund text is quietly stealing phone users’ data. msn.com
- Bing News. (2026, August 12). First Akira Safe Mode attack disables endpoint detection and response but fails to encrypt, Huntress says. siliconangle.com
- Ghourabi (2021). SM‐Detector: A security model based on BERT to detect SMiShing messages in mobile environments. Concurrency and Computation: Practice and Experience. doi.org/10.1002/cpe.6452
- Parti (2022). “Elder Scam” Risk Profiles: Individual and Situational Factors of Younger and Older Age Groups’ Fraud Victimization. International Journal of Cybersecurity Intelligence & Cybercrime. doi.org/10.52306/2578-3289.1117
- Ansari (2022). A Quantitative Study of Risk Scores and the Effectiveness of AI-Based Cybersecurity Awareness Training Programs. International Journal of Smart Sensor and Adhoc Network.. doi.org/10.47893/ijssan.2022.1212
Investigative Methodology: This briefing is generated on a fixed daily schedule (6:00 AM, America/Chicago) from live news wires and the CrossRef scholarly database. Every news claim is grounded in fetched source text with an APA7 in-text citation. Every peer-reviewed source is a real, DOI-verifiable journal article — filtered to results with a named author list, a named journal, and at least 3 citations to screen out predatory or uncited entries — never a fabricated or paraphrased-from-memory study. Every video embed is verified to be a real, existing video via YouTube’s oEmbed endpoint before publication. The featured image is a real photograph sourced from Pexels, not an AI-generated image. No Wikipedia sources are used.
Stay Connected

