KEMETIC MINDS
Cybersecurity Scam Watch — Weekly Report — September 14, 2026
Photo: Gustavo Fring via Pexels (source)
Two federal warnings landed in the same week, and both depend on you trusting a message that looks official. The FBI says a delivery-text scam is now running through more than 10,000 look-alike web addresses — and the right move is to delete the text. The FTC, meanwhile, says scammers have started pasting their own QR codes over the real ones on parking meters.
- Scammers are covering the legitimate QR codes on parking meters with fake codes, sending anyone who scans them to a lookalike payment page (FTC, 2026).
- Car buyers who pay a “clone” dealership website can send the money, arrive at the real dealership, and find the dealer has no record of the order or the payment (FTC, 2026).
- The FBI’s Internet Crime Complaint Center has updated its warning about scammers who pose as the bureau’s own fraud-reporting staff, targeting people who have already lost money once (FBI, 2026).
- A wave of fake package-delivery texts now runs through a network of more than 10,000 fake web addresses, and the FBI says to delete the messages (FBI, 2026).
- The NSA, CISA and the FBI accused DeepSeek, Moonshot and other Chinese AI companies of “distilling” American frontier AI models (NSA et al., 2026).
- That accusation came in a joint cybersecurity advisory released September 8, 2026 (NSA, CISA, & FBI, 2026).
1. QR Codes Pasted Over Parking Meters
Watch how a real fake parking-meter qr code unfolds — and the red flags that give it away.
Scammers have started covering the real QR codes on parking meters with fake codes of their own, per a Federal Trade Commission warning dated September 9, 2026 (FTC, 2026).
Scanning one of the swapped stickers sends the driver to a lookalike payment page rather than the meter’s own payment system (FTC, 2026). The scan works. The page loads. That is the trap.
What makes this one hard to catch is the setting. There is no email to check, no sender name to question — just a sticker on a meter you are standing next to with a car you need to leave.
The FTC’s alert flags the tactic itself rather than a count of tampered meters, so drivers have no way to know which streets have been hit.
How to Avoid This Scam
- Look at the sticker, not just the code. The giveaway described by the FTC is a code applied over the meter’s original one (FTC, 2026).
- Pay through the meter’s own card reader or the official parking app on your phone instead of scanning a code posted on the street.
- If a scanned code takes you to a payment page, stop and check whether that page is the city’s or the meter operator’s — the FTC’s warning is that the lookalike replaces the real one (FTC, 2026).
Video: Buying a car online? How to spot fake vehicle ads. Source: KSDK News.
2. Clone Car Dealership Websites
Watch how a real clone car-dealership website unfolds — and the red flags that give it away.
Fake car dealership websites — built to look like the real thing — are catching buyers who send money before ever setting foot on a lot (FTC, 2026).
The sequence the FTC describes is brutal in its simplicity. An unwitting buyer finds the clone site, sends the money, then shows up at the actual dealership.
That is when they learn the legitimate dealer has no record of the order or the payment at all (FTC, 2026).
The sums at stake are large — the coverage frames this as a way to lose thousands in cash. And because the buyer paid a website, not a dealership, there is no order number for the real dealer to trace.
How to Avoid This Scam
- Confirm you are on the real dealership’s site before sending anything. A clone is a copy, so a near-match web address is the warning sign (FTC, 2026).
- Call the dealership directly using a number you looked up yourself — not one listed on the site you are about to pay.
- Never wire money or pay a deposit for a vehicle before the dealer confirms the order on their end. The FTC’s warning is that the real dealer will have no record of either the order or the payment (FTC, 2026).
Video: FBI Scams. Source: WBFF FOX45 Baltimore.
3. Scammers Posing as the FBI’s Own Fraud Staff
Watch how a real fake fbi fraud-recovery callback unfolds — and the red flags that give it away.
The FBI’s Internet Crime Complaint Center has updated its warning about a particular kind of cruelty: scammers posing as the bureau’s own fraud-reporting staff (FBI, 2026).
Their targets are people who have already lost money once (FBI, 2026).
That is the design. A person who has just been scammed is looking for someone official to fix it — and the impersonator arrives wearing the badge of the agency people are told to report to.
The FBI says scammers pose as the bureau’s own fraud-reporting staff; the update to the IC3 warning is dated September 9, 2026 (FBI, 2026).
For anyone still waiting on a recovery promise from a supposed federal fraud investigator, that call is the story to watch.
How to Avoid This Scam
- Treat any inbound contact from someone claiming to be FBI fraud-reporting staff as suspect — that is the exact impersonation the IC3 has now warned about twice (FBI, 2026).
- If you have already lost money once, slow down before acting on any “help” that reaches out to you. The FBI says these scammers specifically prey on people who have lost money already (FBI, 2026).
- Start your own report through a channel you find yourself rather than replying to a message, call or email that came to you first.
Video: FTC warns of new scam. Source: ABC 10 News.
4. Fake Delivery Texts Across 10,000-Plus Domains
Watch how a real fake package delivery text unfolds — and the red flags that give it away.
Federal investigators have flagged a wave of fraudulent text messages posing as package delivery alerts (FBI, 2026).
The scale is what separates this one from a typical phishing blast: the scheme runs through a network of more than 10,000 fake web addresses built to mimic real ones (FBI, 2026).
The FBI’s instruction is unusually direct
Delete the messages (FBI, 2026). No link to check, no number to call — just remove it.
Why the domain count matters
A single fake address gets blocked by filters. Ten thousand of them built to look alike means the network keeps working even as individual links get shut down (FBI, 2026).
The alert was published September 14, 2026 — meaning packages you are actually expecting are moving through the same week the fake notices are (FBI, 2026).
How to Avoid This Scam
- Delete the text rather than tapping it. That is the FBI’s own guidance on this campaign (FBI, 2026).
- If you are expecting a package, open the carrier’s app or type the carrier’s address yourself — never through a link in a text.
- Do not assume a “delivery problem” text is real because you did order something. The FBI describes these as fraudulent alerts built on a domain network of 10,000-plus fake addresses (FBI, 2026).

5. US Authorities Accuse Chinese AI Firms of Copying US Models
Watch how a real fake ai lab “distillation” compliance threat unfolds — and the red flags that give it away.
The NSA, CISA and the FBI have accused DeepSeek, Moonshot and other Chinese AI companies of “distilling” American frontier AI models (NSA et al., 2026).
“Distilling” is the term at the center of the accusation — the claim is that American models were used as the raw material for building competing ones (NSA et al., 2026).
The framing from US authorities is “industrial-scale campaigns,” which signals this is described as an organized effort rather than isolated copying (NSA et al., 2026).
Why the three agencies moved together
When the NSA, CISA and the FBI put their names on the same accusation, it shifts from a tech-industry complaint to a national-security position (NSA et al., 2026).
For everyday users, the practical question is not the model weights — it is which AI tools your workplace has already wired into its systems, and whether anyone checked whose model is underneath.
How to Avoid This Scam
- Ask which AI services your organization uses and whether any are the China-based firms named in the accusation (NSA et al., 2026).
- Read the accusation for what it is: a claim about how competing models were trained, “distilling” American frontier models (NSA et al., 2026).
- If you buy or deploy AI tools at work, route this to your security lead before your next vendor decision rather than deciding alone.

6. The Joint Advisory Behind the Accusation
Watch how a real fake api-key re-verification phish unfolds — and the red flags that give it away.
The accusation came with a document. The NSA, CISA and the FBI released a joint cybersecurity advisory on September 8, 2026, warning that China-based AI firms distill US frontier models (NSA, CISA, & FBI, 2026).
A joint cybersecurity advisory is the format these agencies use when they want the warning to be actionable, not just rhetorical (NSA, CISA, & FBI, 2026).
The date matters for tracking. The advisory is dated September 8, 2026, and it was framed as a warning — the language of something to prepare for, not just something that happened (NSA, CISA, & FBI, 2026).
What is still missing from the public picture
The advisory names the practice and the three issuing agencies. What it does not yet tell the public is what companies, universities or agencies should do differently, or who is expected to act first.
That gap is the one to watch — when three agencies title a warning a “cybersecurity advisory,” organizations tend to ask their vendors what changed.
How to Avoid This Scam
- Note who issued the warning — the NSA, CISA and the FBI together — and weigh an advisory from all three differently from a single-agency blog post (NSA, CISA, & FBI, 2026).
- If your team builds or licenses AI, learn what “distilling” means before your next vendor review so the advisory’s warning makes sense in context (NSA, CISA, & FBI, 2026).
- Treat the September 8, 2026 release date as the starting point: any follow-up guidance will build on this advisory, not replace it (NSA, CISA, & FBI, 2026).
This Week’s Family Safety Checklist
- Slow down when a message creates urgency. A package, a parking payment, a car deposit — this week’s scams all lean on you acting before you check (FBI, 2026).
- Verify a business through a channel you found yourself. A cloned dealership site and a pasted-over meter code both work because the contact method came from the scammer (FTC, 2026).
- Warn the person who has already been hit. Someone who has lost money once is now a specific target, with scammers impersonating the FBI’s own fraud-reporting staff to reach them (FBI, 2026).
- Pass work-related advisories up the chain. If AI tools are in use at your job, the joint advisory from the NSA, CISA and the FBI is a question for your security lead, not a decision to make alone (NSA, CISA, & FBI, 2026).
Figure 1
Who is covering this
Note. Built from the Scam Watch stories cited in this roundup.
Black Excellence This Week
The hard news is real, and so is this. Wins reported by the Black press in the last 14 days:
- Another North Carolina HBCU shatters enrollment record as Black colleges surge
miamiherald.com · 2026-09-11 - 5 Things You May Not Know About XCEL Award Honoree Dr. Bernard Harris
blackenterprise.com · 2026-09-10 - Houston appoints first Black woman as executive assistant chief, names new fire marshal
communityimpact.com · 2026-09-10 - HBCUs Are Building New Support Systems for Black Male Students
capitalbnews.org · 2026-09-08
What You Can Do This Week
Not just bad news — here is where to push.
- Photograph and report any QR sticker pasted over a parking meter’s printed payment code, then file a complaint online — Report fraud (FTC)
- Delete unrequested package-delivery texts without tapping links, then report the spoofed look-alike domain to federal cyber authorities — CISA: report a cyber incident
- Verify a used-car dealer’s real address and license before wiring cash, and file a complaint if the clone site vanishes — File a consumer complaint (CFPB)
SUPPORT KEMETIC MINDS
Enjoying this coverage? Back the work and find every way to connect with us in one place.
Support the Page →Kemetic Minds Analysis
The scams that spread fastest each week are rarely brand new — they’re small variations on the same playbook (urgency, spoofed authority, a link that looks almost right) recycled against whichever payment rail, app, or headline event is trending. Tracking the official warnings alongside the scams themselves is the fastest way to see which variant is live right now, not just which ones were common last year.
References
- Bing News. (2026, September 9). The FTC says scammers are pasting their own QR codes over parking meters. msn.com
- Bing News. (2026, September 10). How to spot ‘clone’ car websites to avoid losing thousands in cash. celticswire.usatoday.com
- Bing News. (2026, September 9). The FBI says scammers are now impersonating its own fraud-reporting centre. msn.com
- Bing News. (2026, September 14). A fake delivery-text scam is running through more than 10,000 look-alike domains, and the FBI says to delete the messages. msn.com
- Bing News. (2026, September 9). US Authorities Accuse Chinese AI Companies Of Industrial-Scale Campaigns To Copy American Models. msn.com
- Bing News. (2026, September 8). NSA, CISA, FBI Warn China-Based AI Firms Distill US Frontier Models. unite.ai
Investigative Methodology: This roundup is generated on a fixed weekly schedule (Monday morning, America/Chicago) from live wire sources. Every claim is grounded in fetched source text with an APA7 in-text citation. Every video embed is verified to be a real, existing video via YouTube’s oEmbed endpoint before publication — none are written by the drafting model. The featured image is a real photograph sourced from Pexels, not an AI-generated image. No Wikipedia sources are used.
Stay Connected

