Skip to content
Golden and blue Ancient Egyptian art with pharaoh, Eye of Horus, scarab, and "KEMETIC MIND" text.
Menu
  • Home
  • Breaking News
  • Live Trackers
    • Karmelo Anthony Case
    • Kohen Wiley Case
    • Nolan Wells Case
    • Global Conflict Tracker
    • Cyclospora Outbreak Map
    • Food Recall Tracker
    • Missing People in the United States
    • Bomb Threat Tracker
  • Tools
    • Numerology Calculator
    • Live Settlement Tracker
    • U.S. Voting Dates
    • Project 2025 Tracker
    • Frequently Asked Questions
  • Civil Rights
  • Kemetic Wisdom
  • Numerology
  • World News
  • About Kemetic Minds
    • Contact
  • Legal
    • Privacy Policy
    • Cookie Policy
    • Terms of Service
    • Disclaimer
Menu
Newsroom
Iran Denies Talks as Trump Says a Deal Is NearDaily Numerology: September 15, 2026 — Universal Day 7 (Spiritual Wisdom)Open Cosmos Raises $346M in European Space Funding BlitzSecond Judge Freezes Trump Mail Ballot Order as Justices Weigh In57 ICE Custody Deaths as Detained Population Jumps 70%Mount Etna Eruption Grounds Flights at Catania AirportDOJ Sues 24 States, D.C. Over Tuition for Undocumented StudentsFBI: Fake Delivery Texts Run Through 10,000 Look-Alike DomainsIran Denies Talks as Trump Says a Deal Is NearDaily Numerology: September 15, 2026 — Universal Day 7 (Spiritual Wisdom)Open Cosmos Raises $346M in European Space Funding BlitzSecond Judge Freezes Trump Mail Ballot Order as Justices Weigh In57 ICE Custody Deaths as Detained Population Jumps 70%Mount Etna Eruption Grounds Flights at Catania AirportDOJ Sues 24 States, D.C. Over Tuition for Undocumented StudentsFBI: Fake Delivery Texts Run Through 10,000 Look-Alike Domains
Cybersecurity & Scam Daily Briefing

Consumer Rights · Sep 14, 2026FBI: Delete Fake Delivery Texts Tied to 10,000 Domains

Posted on September 14, 2026 by Kemetic Mind
Listen to this article16:49
Your browser does not support audio playback.

KEMETIC MINDS
Cybersecurity & Scam Daily Briefing — September 14, 2026


Photo: Gustavo Fring via Pexels (source)

📢 SPREAD THE WORD — Share this report

Facebook Post on X WhatsApp LinkedIn Reddit
  • FBI: fake delivery texts now run through 10,000+ look-alike web addresses — delete them (Bing News, 2026a, 2026b).
  • Revolut leaked customer ID records after a fake request from a real government domain (Yahoo Finance, 2026).
  • Attackers now post that data daily until Revolut pays (CoinCentral, 2026).
  • Exposed files include passports, selfies, statements and Bitcoin history (Yahoo Finance, 2026).
  • Revolut says systems and funds were untouched; the exact customer count is undisclosed (Yahoo Finance, 2026).

1. Fake Package-Delivery Texts

SCAM WATCH: Fake Package Delivery Text
kemeticmind.com — Cybersecurity Scam Watch
Text Message • “USPS Delivery” (unknown number, spoofed)
USPS: Your package is being held at our facility due to an incomplete address. Reschedule delivery within 12 hours here: usps-redelivery-center.co/track
RED FLAG: Unsolicited delivery alert
RED FLAG: Look-alike domain
RED FLAG: Artificial 12-hour deadline
I’m not expecting anything. Why would a real carrier send me to a .co address instead of usps.com? I’ll just look up my tracking number myself.
Your parcel will be returned to sender today. To release it, confirm your name and full card details for the $1.99 redelivery fee at the link — we cannot hold it longer.
RED FLAG: Card details requested
RED FLAG: Fake small fee
RED FLAG: Escalating urgency
HOW TO RESPOND
Never click a tracking link in an unexpected delivery text — the 10,000+ look-alike domains in this wave exist only to harvest card numbers. Open your carrier’s official app or type the real domain yourself and paste the tracking number from your order confirmation; report the message by forwarding it to 7726.

Watch how a real fake package delivery text unfolds — and the red flags that give it away.

Federal investigators have flagged a wave of fraudulent text messages that pose as package delivery alerts — the FBI warning on look-alike delivery domains, as reported by MSN (Bing News, 2026a, 2026b).

The scheme runs through a network of more than 10,000 fake web addresses, described as “look-alike” domains built to pass for the real thing (Bing News, 2026a, 2026b).

The FBI’s guidance to anyone who receives one is blunt: delete the message (Bing News, 2026a, 2026b).

Why 10,000 domains changes the math

Blocking one bad link doesn’t help when a campaign can rotate through thousands of addresses. That scale is what separates this wave from the one-off fake text most people have learned to spot.

The same report surfaced on a second syndicated MSN page carrying the identical warning, with no additional details attached (Bing News, 2026b).

So the reader’s job shifts. You can no longer win by reading carefully — the message has to be treated as unverified no matter how normal it looks.

How to Avoid This Scam

  • Never tap a link in an unexpected delivery text. Track a parcel by typing the carrier’s or retailer’s own web address yourself.
  • Delete the message once you’ve confirmed you aren’t expecting that delivery — that is the FBI’s stated advice for this campaign (Bing News, 2026a, 2026b).
  • Watch the web address, not the message wording. The trick here is a fake address that looks close to a real one (Bing News, 2026a, 2026b).

Video: The Cheap Security Device Burglars Avoid & StubHub’s Customer Service Nightmare. Source: Clark Howard: Save More, Spend Less.

2. “Innocent-Looking” Texts Draw a Broadband Warning

SCAM WATCH: Fake Parcel Redelivery Text
kemeticmind.com — Cybersecurity Scam Watch
Text Message • “Royal Mail” (spoofed short code)
ROYAL MAIL: Your parcel (GB8842917) is held at our depot — an unpaid £1.45 redelivery fee is due. Reschedule within 24hrs or it returns to sender: rml-redelivery-help.info
RED FLAG: Lookalike web address
RED FLAG: Urgent 24-hour deadline
RED FLAG: Small fee to lower guard
I’m not clicking that. I’ll open the courier’s own app and check my tracking number there myself.
Payment failed — your card was declined by your bank. To avoid return, confirm your full card number, expiry and the 3-digit code, plus your billing address, at the same link.
RED FLAG: Asks for card security code
RED FLAG: Blames your bank
RED FLAG: Harvests billing address
HOW TO RESPOND
Never pay a redelivery fee from a link in a text — go to the courier’s official app or website and enter your tracking number yourself. If a genuine fee is owed, it will show there, and no courier ever needs your CVV or full card details over SMS.

Watch how a real fake parcel redelivery text unfolds — and the red flags that give it away.

A broadband provider is warning households that fake delivery texts, banking alerts and account warnings are getting harder to tell apart from genuine ones — Community Fibre’s warning about innocent-looking scam messages (Bing News, 2026c).

Community Fibre’s response was to urge households to strengthen their online security (Bing News, 2026c).

That advice points somewhere different from “spot the fake.” If the message itself is no longer a reliable clue, the protection has to sit on the account — not in the inbox (Bing News, 2026c).

What that means for a family

Delivery texts, bank alerts and account warnings are now the same style of attack wearing three different costumes (Bing News, 2026c).

The takeaway is not “read more carefully.” It’s that a convincing message should trigger a check somewhere other than your phone screen.

How to Avoid This Scam

  • Assume the message is fake until you confirm it inside the company’s own app or on a web address you type yourself (Bing News, 2026c).
  • Do the account-side work now — strengthen your online security settings before a convincing text arrives, which is what Community Fibre asked households to do (Bing News, 2026c).
  • Apply the same rule to banking alerts and account warnings that you’d apply to a delivery text: verify, don’t reply (Bing News, 2026c).

phishing email laptop warning
Photo: Markus Winkler via Pexels (source)

3. Revolut: A Fraudulent Request From a Real Government Domain

SCAM WATCH: Fake Package Delivery Text
kemeticmind.com — Cybersecurity Scam Watch
Text Message • Unknown Number
USPS: Your package #9405511 is on hold at our facility due to an incomplete address. Redeem within 12 hrs or it returns to sender: usps-redelivery-help[.]com/trk
RED FLAG: Look-alike domain
RED FLAG: False urgency deadline
RED FLAG: Delivery you didn’t order
I’m not expecting anything, and that tracking number isn’t a real USPS format. I’ll open usps.com myself and paste it in there rather than tapping a link in a text.
FINAL NOTICE: your parcel returns to sender today. Confirm your address and cover the $1.95 redelivery fee with any card here: usps-redelivery-help[.]com/pay – the small fee just verifies you’re the recipient.
RED FLAG: Small fee to harvest card
RED FLAG: Second deadline push
RED FLAG: Card details via link
HOW TO RESPOND
Never tap a delivery link in a text – open the carrier’s own site or app and paste the tracking number in yourself. Real carriers don’t collect a ‘redelivery fee’ through a texted link; that tiny charge exists only to capture your full card number, so if you already entered it, call your bank and freeze the card.

Watch how a real fake package delivery text unfolds — and the red flags that give it away.

Revolut disclosed sensitive customer records to an unauthorized party after fraudulent data requests arrived from an email address on a legitimate government agency’s domain — Revolut’s customer notification, reported by Yahoo Finance (Yahoo Finance, 2026).

The company confirmed the disclosure on Saturday, September 12 (Yahoo Finance, 2026).

Someone impersonated the agency using an address on that agency’s own domain, and the request cleared Revolut’s checks before it was identified as fraudulent (Yahoo Finance, 2026).

What was in the records

The notification Revolut emailed to affected customers listed birth dates, postal and email addresses, phone numbers, and copies of identity documents such as passports and driving licences (Yahoo Finance, 2026).

Verification selfies, account statements and transaction histories may also have been disclosed, the company said (Yahoo Finance, 2026).

Crypto investigator ZachXBT publicized the notice in a Telegram post and added items Revolut’s own notification did not list: IBANs, withdrawal records, occupations, and transaction history covering Bitcoin (Yahoo Finance, 2026).

What Revolut says so far

Revolut told TechCrunch that a limited number of customers were affected, and that its systems and customer funds remained unaffected (Yahoo Finance, 2026).

The company blocked the sender’s address after detecting the scheme, and alerted the government agency concerned, law enforcement, data protection authorities and financial regulators (Yahoo Finance, 2026).

A spokesperson called the episode an external impersonation scam, and Revolut has not disclosed an exact number of affected customers (Yahoo Finance, 2026).

How to Avoid This Scam

  • If you hold a Revolut account, expect phishing that quotes details only a real bank should know — leaked names, birth dates and phone numbers make a fake far more convincing (Yahoo Finance, 2026).
  • Ask Revolut directly whether your records were in the disclosed set; the company says affected customers were notified individually (Yahoo Finance, 2026).
  • Treat leaked ID documents as high-value: security experts quoted in today’s coverage say identity documents and facial-verification images raise the risk of identity theft for those affected (CoinCentral, 2026).

family online safety internet security
Photo: Ann H via Pexels (source)

4. Revolut Data Posted in an Extortion Campaign

SCAM WATCH: Fake Government Records Verification Email
kemeticmind.com — Cybersecurity Scam Watch
✉Email • “Government Records Office” (real agency domain, spoofed display name)
✉📧 New Email • Email
Dear Citizen, this is the Records Compliance Unit. Our file on you is incomplete and flagged for closure. To keep your account active, reply with a photo of your passport or driving licence plus a selfie holding it.
RED FLAG: Sender claims to be agency
RED FLAG: Asks for ID + selfie
RED FLAG: Vague ‘flagged’ threat
🖱️ Click — Wait — I’ve never had an account with you, and I’m not emailing photos of my passport to anyone. Can I get a reference number and a phone number to call you back on?
🔒 Ransomware Activates
Callback lines are closed for the audit period. Document requests expire in 24 hours or the file is escalated to enforcement. Attach your ID to this thread and include your date of birth, address and phone number to confirm identity.
RED FLAG: Callback refused
RED FLAG: 24-hour deadline
RED FLAG: Harvests DoB, address, phone
HOW TO RESPOND
A real government agency will never ask you to email a passport, licence or selfie, and the domain in the address bar proves nothing — display names are trivially spoofed. If a ‘records’ request arrives, don’t reply or attach anything: look up the agency’s number yourself, call it, and report the message as phishing.

Watch how a real fake government records verification email unfolds — and the red flags that give it away.

By Sunday night the incident had turned into an extortion campaign: attackers began posting sensitive customer information online and threatened to release more every day unless the company paid — CoinCentral’s report on the extortion threats (CoinCentral, 2026).

“We’re going to start releasing more and more data everyday until revolut pays for leaking their customers,” the attackers reportedly announced on Telegram (CoinCentral, 2026).

Who was named first

Among the first data published were identity documents and selfies linked to tennis player Alexander Shevchenko and Felix Römer, CEO of the online crypto casino Gamdom, according to a post on X from International Cyber Digest (CoinCentral, 2026).

The exposed information includes full names, dates of birth, occupations, contact details, account statements and full transaction histories, including Bitcoin transactions, plus passport copies and driver’s licences (CoinCentral, 2026).

The threat is still live

Revolut called the leak the result of a “sophisticated external impersonation scam,” said a “very limited” number of customers were affected, and said those customers were individually notified (CoinCentral, 2026).

Customers whose Bitcoin transaction histories were exposed could also face additional privacy concerns, the report notes (CoinCentral, 2026).

The daily-release threat means this story is unfinished — anyone named in the first drop becomes a target for follow-on fraud.

How to Avoid This Scam

  • Ignore anyone offering to delete your leaked files for a fee; the attackers are demanding payment from Revolut, not from you (CoinCentral, 2026).
  • Watch for second-wave phishing that quotes real details from the leak — your name, birth date or transaction history is exactly what makes a fake message land (CoinCentral, 2026; Yahoo Finance, 2026).
  • If you were notified, treat your passport or licence copy and your verification selfie as permanently exposed, and check your accounts for unfamiliar activity (CoinCentral, 2026).

What the Research Actually Says

Today’s briefing came with no peer-reviewed studies attached, and that gap is worth naming plainly: the guidance above rests on official warnings and company statements, not on controlled research (Bing News, 2026a; CoinCentral, 2026).

That limits what we can tell you. We can describe what happened today. We can’t tell you how well any single defense performs over time.

What the sources do support

The FBI’s instruction for this campaign is narrow and clear: delete the messages rather than engage with them (Bing News, 2026a, 2026b).

Community Fibre’s warning reaches the same conclusion from a different angle — because fake delivery texts, banking alerts and account warnings are getting harder to identify, households are being told to strengthen their online security rather than rely on spotting a fake by eye (Bing News, 2026c).

The Revolut case shows the ceiling on message-level defenses. The fraudulent requests arrived from an address on a legitimate government domain and cleared the company’s checks before anyone caught them (Yahoo Finance, 2026).

We’ll flag peer-reviewed findings here the moment they’re available — including any study measuring whether “delete and don’t click” actually reduces losses.


Today’s Family Safety Checklist

  • Verify, then act: check delivery, banking and account messages inside the company’s own app or on a web address you type yourself (Bing News, 2026c).
  • Delete instead of replying — the FBI’s stated guidance for this wave of fake delivery texts (Bing News, 2026a, 2026b).
  • Protect the account, not just the inbox: a leaked passport copy or selfie can’t be reset the way a password can, so tighten logins and watch your statements (CoinCentral, 2026; Yahoo Finance, 2026).
  • Treat a message that already knows your birth date or account details as a warning sign, not proof — the Revolut leak put exactly that kind of data into circulation (CoinCentral, 2026).

Figure 1
Who is covering this

Note. Built from the Scam Watch stories cited in this report.

Black Excellence This Week

The hard news is real, and so is this. Wins reported by the Black press in the last 14 days:

  • Another North Carolina HBCU shatters enrollment record as Black colleges surge
    miamiherald.com · 2026-09-11
  • 5 Things You May Not Know About XCEL Award Honoree Dr. Bernard Harris
    blackenterprise.com · 2026-09-10
  • Houston appoints first Black woman as executive assistant chief, names new fire marshal
    communityimpact.com · 2026-09-10
  • HBCUs Are Building New Support Systems for Black Male Students
    capitalbnews.org · 2026-09-08

What You Can Do This Week

Not just bad news — here is where to push.

  • Delete the fake delivery texts without clicking any link, then file a report with the FTC’s fraud database. — Report fraud (FTC)
  • Freeze your credit at Equifax, Experian, and TransUnion this week if you hold a Revolut account affected by the leak. — Freeze your credit (annualcreditreport.com)
  • Report the Revolut data-theft extortion and any suspicious account activity to the federal cybersecurity agency immediately. — CISA: report a cyber incident

SUPPORT KEMETIC MINDS

Enjoying this coverage? Back the work and find every way to connect with us in one place.

Support the Page →

Kemetic Minds Analysis

Today’s briefing pulled from 5 news sources and 0 peer-reviewed studies. No peer-reviewed source cleared today’s citation-count bar; treat today’s protection advice as news-grounded, not research-grounded. The pattern worth watching isn’t any single scam headline — it’s whether today’s news matches what the research already predicts about who gets targeted and what actually reduces risk, or whether it’s a genuinely new variant the literature hasn’t caught up to yet.


References

  1. Bing News. (2026, September 14). A fake delivery-text scam is running through more than 10,000 look-alike domains, and the FBI says to delete the messages. msn.com
  2. Bing News. (2026, September 13). Broadband provider warns of innocent-looking scam messages. msn.com
  3. Bing News. (2026, September 14). A fake delivery-text scam is running through more than 10,000 look-alike domains, and the FBI says to delete the messages. msn.com
  4. Bing News. (2026, September 14). Revolut Customer Records Exposed: Attackers Demand 10,000 BTC. finance.yahoo.com
  5. Bing News. (2026, September 13). Revolut Customer Data Leaked as Attackers Threaten Daily Releases Until Company Pays. coincentral.com

Investigative Methodology: This briefing is generated on a fixed daily schedule (6:00 AM, America/Chicago) from live news wires and the CrossRef scholarly database. Every news claim is grounded in fetched source text with an APA7 in-text citation. Every peer-reviewed source is a real, DOI-verifiable journal article — filtered to results with a named author list, a named journal, and at least 3 citations to screen out predatory or uncited entries — never a fabricated or paraphrased-from-memory study. Every video embed is verified to be a real, existing video via YouTube’s oEmbed endpoint before publication. The featured image is a real photograph sourced from Pexels, not an AI-generated image. No Wikipedia sources are used.

Stay Connected

Join @kemeticMinds on Telegram →

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

📩 Subscribe for New Posts

Get notified whenever Kemetic Minds publishes a new story.

📡 Subscribe via RSS

Get every new Kemetic Minds post delivered straight to your favorite RSS reader (Feedly, Inoreader, Apple News, etc.).

Subscribe to RSS Feed →
Live Alerts
Fetching verified headlines...
Real-time news • Updates every minute

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • September 14, 2026 by Kemetic Mind Iran Denies Talks as Trump Says a Deal Is Near
  • September 14, 2026 by Kemetic Mind Daily Numerology: September 15, 2026 — Universal Day 7 (Spiritual Wisdom)
  • September 14, 2026 by Kemetic Mind Open Cosmos Raises $346M in European Space Funding Blitz
  • September 14, 2026 by Kemetic Mind Second Judge Freezes Trump Mail Ballot Order as Justices Weigh In
  • September 14, 2026 by Kemetic Mind 57 ICE Custody Deaths as Detained Population Jumps 70%

Browse by Topic

Pages

  • About Kemetic Minds
  • Bomb Threat Tracker: Live U.S. Map
  • Contact
  • Cookie Policy
  • Cyclospora Outbreak Map: U.S. State-by-State Tracker (Live)
  • Cyclospora Tracker Subscribers (do not delete)
  • Disclaimer
  • Frequently Asked Questions
  • Home
  • Live Settlement Tracker: Open Class Action Claims
  • LIVE UPDATES: Justice for Kohen Wiley — Tracking the Senatobia Police Killing
  • LIVE UPDATES: Middle East Escalation & Global War Tensions
  • LIVE UPDATES: The Karmelo Anthony Case — Austin Metcalf Murder Trial & Appeal
  • LIVE UPDATES: The Nolan Wells Case — Horn Island, Mississippi
  • LIVE: Food Recall & Foodborne Illness Tracker — Search by State
  • Ma'at Feedback Log (Internal)
  • Missing People in the United States
  • Moved: About Kemetic Minds
  • Privacy Policy
  • Project 2025 Tracker: Timeline & Impact on the Black Community
  • Pythagorean Numerology Calculator — Words, Names, Dates & Historical Connections
  • Terms of Service
  • U.S. Voting Dates

Kemetic Mind Telegram

Click Here
© 2026 Kemetic Minds | Powered by Minimalist Blog WordPress Theme
Ask Ma’at
Ma’at is thinking…

Powered by
Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
None
Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
None
Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
None
Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
None
Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
None
Powered by