KEMETIC MINDS
Cybersecurity & Scam Daily Briefing — August 02, 2026
Photo: Gustavo Fring via Pexels (source)
Update — August 3, 2026
HMRC scam scale confirmed. HMRC has now put a number on the problem: customers reported more than 170,000 scam referrals in the 12 months to July 31, 2025 — over 47,000 of them fake tax-refund claims, per HMRC’s official release. “Scammers target individuals when they know Self Assessment customers will be preparing to file their tax returns,” said Kelly Paterson, HMRC’s Chief Security Officer.
SplitVPN breach is worse than first reported. The full picture, confirmed via Have I Been Pwned and CyberSecurityNews: the breach struck July 21, 2026, and exposed not just email addresses but IP addresses, partial payment card numbers, device IDs, and nearly 58 million connection logs — directly contradicting SplitVPN’s “no logs” privacy promise. If you have ever used SplitVPN (formerly NotVPN), assume your payment card’s first six and last four digits, plus your approximate location and device, are exposed, and watch statements for unfamiliar charges.
- Scam emails claiming you are due a 2024-2025 Self Assessment tax refund are on the rise, HMRC warns (Express, 2026).
- The emails push urgency and demand personal and bank details — HMRC never sends urgent refund deadlines by email (Express, 2026).
- A SplitVPN data breach has exposed personal records of 865,000 users (CyberSecurityNews, 2026).
- Modern ransomware attackers keep changing methods; layered, budget-friendly defenses are the research-backed answer (Raj et al., 2024, Security and Privacy).
- Suspicious texts can be screened by examining the message content and the behavior of the links inside it (Mishra & Soni, 2020, Future Generation Computer Systems).
- Unsure about a tax message? Do not click links — report it to HMRC first (Express, 2026).
1. Today’s Key Headlines
On Sunday, August 2, HM Revenue & Customs (HMRC) posted an urgent scam alert on X, saying it is “receiving increased reports of customers receiving scam emails claiming they are due a Self Assessment tax refund for 2024 to 2025” (Express, 2026). Self Assessment is the UK system for filing your own tax return.
The fake emails tell recipients they need to claim their refund urgently and ask them to provide personal and bank details (Express, 2026).
HMRC says it will never send an email with an urgent deadline to claim a tax refund, and it urges people to stop and think about whether a request is genuine before sharing personal information or opening any links or attachments (Express, 2026).
To check whether you are actually due a refund, log in securely to your HMRC online account through GOV.UK or the HMRC app (Express, 2026).
HMRC also says it will never send a notification of a tax rebate or ask you to disclose personal or payment information by text message (Express, 2026).
If you are unsure about any message, do not click any links, and report it; the GOV.UK website lists genuine HMRC contacts so you can check whether an email, call, text, or letter is fraudulent (Express, 2026).
Report suspicious emails to phishing@hmrc.gov.uk, forward suspicious texts to 60599 (charged at your network rate), and use the online service to report a suspicious HMRC phone call (Express, 2026).
Video: 2026 Cost of a Data Breach Report: AI Is Changing Cybersecurity. Source: IBM Technology.
2. SplitVPN Data Breach Exposes 865,000 Users’ Personal Records
In separate news today, a report from CyberSecurityNews says a data breach at SplitVPN — a virtual private network service people use to protect their internet connection — exposed personal records belonging to 865,000 users (CyberSecurityNews, 2026).
Today’s report does not yet detail what types of records were exposed or when the breach occurred (CyberSecurityNews, 2026).
If you have ever used SplitVPN, the safe move is to act as if your personal records may be compromised (CyberSecurityNews, 2026).
Watch your bank and email accounts for unusual activity, and change any passwords you reused across other sites.
Video: N4T Investigators: FTC Issues Alert on Tech Support Scams. Source: News 4 Tucson KVOA-TV.
3. What the Research Actually Says
Ransomware changes fast — and defense can still be affordable. Raj et al. (2024, Security and Privacy) analyzed the most prevalent modern ransomware variants and identified the tactics, techniques, and procedures (TTPs) those attackers use most. TTPs are simply the specific methods attackers rely on.
The researchers mapped those methods using the MITRE ATT&CK framework, a widely used catalog of known attacker behaviors (Raj et al., 2024, Security and Privacy).
They also proposed a generic attack model for “modern ransomware” and, drawing on existing mitigation frameworks, put forward a simplified three-tier defensive model that is cost-effective and implementable even when resources and budgets are tight (Raj et al., 2024, Security and Privacy).
Plain-language takeaway: layered protection beats any single tool — and it does not have to be expensive (Raj et al., 2024, Security and Privacy).
Text-message scams (smishing) can be detected by studying the message and its links. Mishra and Soni (2020, Future Generation Computer Systems) propose a “Smishing Detector” security model that detects smishing — phishing carried out through text messages — by analyzing the SMS content and the behavior of the URLs in those messages.
In plain terms, two clues matter: what the text says, and where its link actually leads (Mishra & Soni, 2020, Future Generation Computer Systems).
That matters for today’s news because HMRC says it never notifies customers of rebates by text or asks them to disclose personal or payment information by text (Express, 2026).
Password-only logins have long been a research target. Yang and Shieh (1999, Computers & Security) examined password authentication schemes with smart cards — an early attempt to make simple password sign-ins more secure.
Even in 1999, researchers were working on ways to make password-based authentication stronger (Yang & Shieh, 1999, Computers & Security).

4. How to Protect Yourself and Your Family
- Stop before you click. Think about whether a request is genuine before sharing personal info or opening links; if unsure, don’t click (Express, 2026).
- Never trust an urgent refund email. HMRC never sends urgent deadlines to claim a tax refund; check your account through GOV.UK or the HMRC app (Express, 2026).
- Suspect every text. HMRC never asks for personal or payment details by text (Express, 2026), and the research-backed way to judge a message is to look at both the message and the link (Mishra & Soni, 2020, Future Generation Computer Systems).
- Forward, then delete. Send scam emails to phishing@hmrc.gov.uk and suspicious texts to 60599, then delete them so you don’t accidentally tap a dangerous link later (Express, 2026).
- If you used SplitVPN, act as if your records may be exposed. Monitor your accounts for unusual activity and change any passwords you reused elsewhere (CyberSecurityNews, 2026).
- Layer your defenses. Cost-effective, layered protection is the research-backed approach (Raj et al., 2024, Security and Privacy), and adding a second step to password logins is a defense researchers have worked on since at least 1999 (Yang & Shieh, 1999, Computers & Security).

Kemetic Minds Analysis
Today’s briefing pulled from 2 news sources and 3 peer-reviewed studies. Today’s strongest research signal comes from Computers & Security (1999), cited 230 times — the kind of study worth weighing more heavily than a single news anecdote. The pattern worth watching isn’t any single scam headline — it’s whether today’s news matches what the research already predicts about who gets targeted and what actually reduces risk, or whether it’s a genuinely new variant the literature hasn’t caught up to yet.
References
- Bing News. (2026, August 2). HMRC issues urgent new scam warning – ‘reports are increasing’. express.co.uk
- CyberSecurityNews. (2026, August 2). SplitVPN Data Breach Exposes 865k Users' Personal Records – CyberSecurityNews. news.google.com
- Yang, Shieh (1999). Password authentication schemes with smart cards. Computers & Security. doi.org/10.1016/s0167-4048(99)80136-9
- Raj, Narayan, Muskan et al. (2024). Modern ransomware: Evolution, methodology, attack model, prevention and mitigation using multi‐tiered approach. SECURITY AND PRIVACY. doi.org/10.1002/spy2.436
- Mishra, Soni (2020). Smishing Detector: A security model to detect smishing through SMS content analysis and URL behavior analysis. Future Generation Computer Systems. doi.org/10.1016/j.future.2020.03.021
Investigative Methodology: This briefing is generated on a fixed daily schedule (6:00 AM, America/Chicago) from live news wires and the CrossRef scholarly database. Every news claim is grounded in fetched source text with an APA7 in-text citation. Every peer-reviewed source is a real, DOI-verifiable journal article — filtered to results with a named author list, a named journal, and at least 3 citations to screen out predatory or uncited entries — never a fabricated or paraphrased-from-memory study. Every video embed is verified to be a real, existing video via YouTube’s oEmbed endpoint before publication. The featured image is a real photograph sourced from Pexels, not an AI-generated image. No Wikipedia sources are used.
Stay Connected

