KEMETIC MINDS
Cybersecurity & Scam Daily Briefing — September 11, 2026
Photo: Gustavo Fring via Pexels (source)
- ShinyHunters published stolen American Tower data, including plaintext physical access codes for cell tower sites (Rojas, 2026).
- Macquarrie Corporation was hit by Storm ransomware through an outside technology provider, not its own network (Insurance Business Mag, 2026).
- Delhi Police issued a cyber advisory ahead of the BRICS Summit, warning of phishing, malware and fake information campaigns (Dynamite News, 2026).
- iPhone 18 Pro pre-orders open September 12, and fraud experts say scammers are already trying to take buyers’ money (Winder, 2026).
- A Conti ransomware developer was sentenced to four years in US federal prison (Bitdefender, 2026).
1. iPhone 18 Pro Pre-Order Scams
Watch how a real fake iphone pre-order payment phish unfolds — and the red flags that give it away.
Pre-orders for the Apple iPhone 18 Pro and Pro Max open Saturday, September 12. Fraud experts say scammers are already trying to take buyers’ money before the phones even ship (Winder, 2026).
That timing is the whole trick. When demand is high and stock is unclear, a fake “reserve yours now” offer feels urgent instead of suspicious.
What we know — and what we don’t
The Forbes report does not name a specific tactic, only that fraud attempts are already underway around the launch (Winder, 2026). The safe assumption for any hot product launch is that the pressure to buy fast is exactly what gets exploited.
How to Avoid This Scam
- Type Apple’s or your carrier’s web address yourself. Don’t click a pre-order link that arrived by text, email or social media message.
- Treat any request to “pay now to hold your place in line” as a red flag. A real pre-order charges you through the retailer’s own checkout.
- Expect below-retail “deals” on marketplaces and social posts to be bait. If the price beats Apple by a lot, walk away.
- Never share your Apple ID password or a one-time verification code with anyone who contacts you first.

2. BRICS Summit Phishing Advisory
Watch how a real fake summit it phishing email unfolds — and the red flags that give it away.
Delhi Police issued a cybersecurity advisory to government officials and contract IT staff ahead of the BRICS Summit 2026 (Dynamite News, 2026).
The warning names four threats: phishing attacks, malware infections, remote-access threats and fake information campaigns (Dynamite News, 2026).
Why a summit attracts attackers
Summits bring together some of the world’s largest economies, which means a heavy flow of information between government departments, security agencies and diplomatic teams (Dynamite News, 2026).
Attackers use that moment to send fake emails, build misleading websites, steal login details and push false information meant to cause confusion (Dynamite News, 2026).
The Intelligence Fusion and Strategic Operations unit of Delhi Police issued guidelines focused on blocking unauthorized access, protecting sensitive files and keeping official networks secure (Dynamite News, 2026).
The same playbook reaches your inbox
You are not at a summit. But big news events are when lookalike login pages and urgent “official notice” emails spike for everyone else too.
How to Avoid This Scam
- Never log in to a work or government account through a link in an email. Open the site the way you normally do.
- Check the sender’s full address, not just the display name. Lookalike domains are the standard tool in event-themed phishing.
- Verify any “official summit update” or press document against an official government site before forwarding it.
- Report suspicious messages to your IT or security team instead of deleting them quietly — one report can protect your whole office.

3. ShinyHunters Cell Tower Breach
Watch how a real fake breach-notification verification text unfolds — and the red flags that give it away.
ShinyHunters says it stole more than 5.2 million records from American Tower Corporation, one of the largest cell tower operators in the United States (Rojas, 2026).
The group claimed responsibility on June 12, 2026, in a “pay or leak” extortion campaign (Rojas, 2026).
Gate codes in plain text
The stolen set included customer and landowner personal information, tower asset records, GPS coordinates, physical access codes and internal corporate documents (Rojas, 2026).
The physical access codes for tower compounds were stored in plain text — not scrambled — which is what makes this breach unusual (Rojas, 2026).
ShinyHunters also claimed the documents touched records tied to T-Mobile, Verizon and DHS (Rojas, 2026).
What was actually published
The group published about 574,000 unique email addresses with names, phone numbers, physical addresses and geographic data (Rojas, 2026).
Breach notification service Have I Been Pwned added 216,601 accounts from the incident on June 26, 2026, covering more than 200,000 unique email addresses belonging to employees, contractors, customers and business leads (Rojas, 2026).
If your name was in that file, the risk is not just embarrassment. It is a caller who already knows your address and your phone number.
How to Avoid This Scam
- Search your email address on Have I Been Pwned to see if you were in the American Tower dataset (Rojas, 2026).
- If you get a call that opens with your correct address and phone number, don’t treat it as proof of legitimacy. That data is now public.
- Landowners, contractors and site managers: ask American Tower whether gate and compound access codes tied to your site have been changed.
- Watch for invoices or shipping notices that use your real details — breached data is what makes fake paperwork convincing.
4. Storm Ransomware Hits a Company Through Its Tech Vendor
Watch how a real fake breach-notification phishing (third-party vendor impersonation) unfolds — and the red flags that give it away.
A 20-person engineering company in Port Melbourne was listed on the Storm ransomware group’s leak site on September 1, 2026 (Insurance Business Mag, 2026).
Macquarrie Corporation provides diesel engine and machinery management services across Australia and New Zealand. The attack did not start inside its own network (Insurance Business Mag, 2026).
The door was a supplier
“Macquarrie Corporation is aware of a cyber security incident involving one of its external technology providers, resulting in unauthorised access to certain systems used by the business,” a company spokesperson said (Insurance Business Mag, 2026).
Storm set a September 16 publication deadline — the standard pressure tactic used before stolen data goes public (Insurance Business Mag, 2026).
What leaked as proof
Storm posted an employee passport scan, a death certificate, company correspondence, customer data and credit listings (Insurance Business Mag, 2026). The group does not disclose total volume and routinely publishes samples to establish credibility with victims (Insurance Business Mag, 2026).
Macquarrie said it secured affected systems, brought in outside specialists and restored operations through arrangements independent of the provider (Insurance Business Mag, 2026). It is notifying affected people and working with the Australian Cyber Security Centre and the Office of the Australian Information Commissioner (Insurance Business Mag, 2026).
Storm only emerged in August 2026 and has listed 49 alleged victims since (Insurance Business Mag, 2026). Two weeks of existence, 49 names.
How to Avoid This Scam
- Ask your IT provider and any outside software vendor what access they hold to your systems, and whether it is still needed.
- Put a notification deadline in vendor contracts. You cannot respond to a breach you learn about from a leak site.
- Keep backups that the vendor cannot reach — offline or isolated copies.
- If a supplier is breached, assume your customer data is exposed even if your own network looks clean, and notify early.
5. Conti Developer Sentenced to Four Years
Watch how a real fake invoice attachment that drops a ransomware loader unfolds — and the red flags that give it away.
Oleksii Oleksiyovych Lytvynenko, 44, a Ukrainian national, has been sentenced to four years in US federal prison for his role in the Conti ransomware operation (Bitdefender, 2026).
He pleaded guilty in June to conspiracy to commit wire fraud after his extradition from Ireland in October last year (Bitdefender, 2026).
What he admitted to
Prosecutors said Lytvynenko joined the Conti conspiracy around September 2021. He admitted possessing data stolen from eight US victims and four victims overseas, and working on code for a malware “loader” — software built to launch other malicious components during an attack (Bitdefender, 2026).
Conti infected more than 1,000 victims worldwide between 2020 and 2022, hitting networks in 47 US states and 31 foreign countries (Bitdefender, 2026).
The money is the point
The FBI estimated that Conti-linked victims had paid more than $150 million in ransoms by January 2022 (Bitdefender, 2026).
Prosecutors tied the conspiracy to more than $500,000 in cryptocurrency extorted from two victims in Tennessee, plus the publication of data stolen from a third (Bitdefender, 2026). Four other alleged conspirators were indicted in the same federal district in 2023 (Bitdefender, 2026).
Lytvynenko was arrested in County Cork, Ireland, in July 2023. Forensic evidence recovered then showed continued involvement in ransomware activity even after the original Conti operation ended (Bitdefender, 2026).
Sentences like this close one case. They do not close the model — which is why the practical advice below still matters for households.
How to Avoid This Scam
- Keep operating systems and applications patched. Unpatched software is how most ransomware gets its first foothold (Bitdefender, 2026).
- Maintain offline or isolated backups so a ransom demand is an inconvenience, not a decision (Bitdefender, 2026).
- Don’t open unexpected attachments or links — including files that look like invoices, shipping notices or résumés.
- If your files suddenly won’t open, unplug the device from the network and your backup drive before you do anything else.
What the Research Actually Says
No peer-reviewed studies were retrieved for today’s briefing, so nothing here is presented as a research finding.
What we can say, and whose words they are
Every defensive step in this briefing comes from the reporting itself, not from a study. Where research would normally sit, the sourced guidance stands in.
The Conti sentencing coverage states the consumer-side basics directly: patch systems, keep offline or isolated backups, and avoid unexpected attachments and links (Bitdefender, 2026).
The American Tower coverage documents why a breach matters long after it drops off the news: 216,601 accounts were added to Have I Been Pwned, with names, addresses and phone numbers included (Rojas, 2026).
The Macquarrie case shows a pattern worth remembering on its own evidence — the entry point was an external technology provider, not the company’s own network (Insurance Business Mag, 2026).
What to do with that
When no study tells you what works, the reported facts still point one direction: check your exposure, treat your data as already circulating, and mind the suppliers you trust with access.
Today’s Family Safety Checklist
- Check your email address on Have I Been Pwned today — 216,601 accounts from the American Tower breach are listed there (Rojas, 2026).
- Treat a caller or email that knows your name, address and phone number as unverified, not as proof. That data comes from breach files (Rojas, 2026).
- Ask every outside company with access to your accounts or devices what they hold — Macquarrie was breached through a technology provider, not its own network (Insurance Business Mag, 2026).
- Patch your devices and keep one backup that is not connected to the internet, so a ransomware demand doesn’t decide your week (Bitdefender, 2026).
- During big news events — a phone launch, a global summit — slow down before clicking anything that says “official” (Winder, 2026; Dynamite News, 2026).
Figure 1
Who is covering this
Note. Built from the Scam Watch stories cited in this report.
Black Excellence This Week
The hard news is real, and so is this. Wins reported by the Black press in the last 14 days:
- ‘I made those!’: 11-year-old designer Brooke Sumpter makes history with American Girl collaboration
thegrio.com · 2026-09-10 - 5 Things You May Not Know About XCEL Award Honoree Dr. Bernard Harris
blackenterprise.com · 2026-09-10 - By Us Beauty: The Best Black-Owned Beauty Launches From August 2026
essence.com · 2026-09-09 - HBCUs Are Building New Support Systems for Black Male Students
capitalbnews.org · 2026-09-08
What You Can Do This Week
Not just bad news — here is where to push.
- Freeze your credit at all three bureaus to block identity thieves using personal data exposed in the American Tower cell tower breach. — Freeze your credit (annualcreditreport.com)
- File a complaint about fake iPhone 18 Pro pre-order sites that took your money and vanished. — File a consumer complaint (CFPB)
- Report a cyber incident to federal authorities if ransomware hit your workplace through an outside technology provider. — CISA: report a cyber incident
SUPPORT KEMETIC MINDS
Enjoying this coverage? Back the work and find every way to connect with us in one place.
Support the Page →Kemetic Minds Analysis
Today’s briefing pulled from 5 news sources and 0 peer-reviewed studies. No peer-reviewed source cleared today’s citation-count bar; treat today’s protection advice as news-grounded, not research-grounded. The pattern worth watching isn’t any single scam headline — it’s whether today’s news matches what the research already predicts about who gets targeted and what actually reduces risk, or whether it’s a genuinely new variant the literature hasn’t caught up to yet.
References
- Bing News. (2026, September 11). Apple iPhone 18 Pro Scam Warning As Pre-Orders Go Live September 12. forbes.com
- Bing News. (2026, September 11). BRICS Summit 2026 Cyber Alert: Hackers Target Global Meet, Delhi Builds Digital Shield. dynamitenews.com
- Bing News. (2026, September 11). ShinyHunters publishes physical access codes for US cell towers in American Tower breach. gcn.com
- Bing News. (2026, September 10). Ransomware attack reaches Victorian business through external technology provider. insurancebusinessmag.com
- Bing News. (2026, September 11). Conti ransomware developer sentenced to four years in US prison. bitdefender.com
Investigative Methodology: This briefing is generated on a fixed daily schedule (6:00 AM, America/Chicago) from live news wires and the CrossRef scholarly database. Every news claim is grounded in fetched source text with an APA7 in-text citation. Every peer-reviewed source is a real, DOI-verifiable journal article — filtered to results with a named author list, a named journal, and at least 3 citations to screen out predatory or uncited entries — never a fabricated or paraphrased-from-memory study. Every video embed is verified to be a real, existing video via YouTube’s oEmbed endpoint before publication. The featured image is a real photograph sourced from Pexels, not an AI-generated image. No Wikipedia sources are used.
Stay Connected

