KEMETIC MINDS
Cybersecurity & Scam Daily Briefing — August 21, 2026
Photo: Gustavo Fring via Pexels (source)
- FTC: an unexpected package with a QR code is a “brushing scam” warning sign (FTC, 2026).
- 27% of veterans have lost money to scams; 86% have seen military-themed scam hooks (Plummer, 2026).
- Global cyber fraud and cybercrime were on track to cost $10.5 trillion in 2025 and $12.2 trillion by 2031 (Irish Times, 2026).
- NSA, CISA, and FBI flag an active threat to hospital building-control systems (Becker’s Hospital Review, 2026).
- A Missouri school district warns parents about a phishing scam circulating by text (MSN, 2026).
1. The ‘Brushing’ Package: An Unexpected Box Carries a Risky QR Code
Watch how a real qr-code brushing scam unfolds — and the red flags that give it away.
The FTC is warning about a “brushing scam” that begins with an out-of-the-blue package arriving at your door (FTC, 2026). A nefarious QR code might be involved (FTC, 2026).
The trap is in the next step: a curious scan could lead you somewhere harmful (FTC, 2026).
How to Avoid This Scam
- Don’t scan QR codes on packages you never ordered — the code may be the trap (FTC, 2026).
- Check your recent orders before opening anything unexpected; the surprise box is the scam’s opening move (FTC, 2026).
- If you already scanned and entered details, change that password and watch your accounts for strange activity.
- Tell family members about the warning so the trick doesn’t work twice in one household (FTC, 2026).
Video: 🔴 Aug 20's Top Cyber News NOW! – Ep 1199. Source: Simply Cyber – Gerald Auger, PhD.
2. Fake Benefits: 27% of Veterans Have Lost Money
Watch how a real fake va benefit update unfolds — and the red flags that give it away.
Scammers are working the military community at scale. Some 27% of veterans have lost money to scams at some point in their lives, according to Military.com’s new report (Plummer, 2026). About 86% of veterans have met scams crafted to target veterans by mentioning benefits or other military-related themes (Plummer, 2026).
These operators typically use technology to do the heavy lifting and avoid meeting in person (Plummer, 2026). That means the “benefits” pitch can arrive by call, text, or email with no human check.
How to Avoid This Scam
- Treat any unsolicited message about veterans’ benefits or military themes as a possible scam (Plummer, 2026).
- Never share banking, Social Security, or benefit details with someone who contacted you first (Plummer, 2026).
- Verify benefit information through official channels you already know, not links inside the message (Plummer, 2026).
- Spread the word: with 86% of veterans seeing these hooks, every veteran household should expect them (Plummer, 2026).

3. AI-Powered Fraud: A $10.5 Trillion Crime Problem
Watch how a real supplier invoice bank detail change unfolds — and the red flags that give it away.
Cyber fraud is big business. Research firm Cybersecurity Ventures said global cyber fraud and cybercrime were on track to cost $10.5 trillion in 2025 and to grow to $12.2 trillion by 2031 (Irish Times, 2026). The World Economic Forum’s Global Cybersecurity Outlook 2026 lists cyber-enabled fraud among the most prominent cyber risks facing organizations (Irish Times, 2026).
Experts describe the new wave as “a highly organized criminal enterprise, increasingly powered by artificial intelligence,” designed to exploit human behavior as well as technology (Irish Times, 2026). PwC’s Shomo Das calls it “old-fashioned deception supercharged by technology” — and warns it “often looks routine and legitimate until the money or data has gone” (Irish Times, 2026).
How to Avoid This Scam
- Slow down when a message demands speed — urgent “bank,” “supplier,” or “executive” requests are classic hooks (Irish Times, 2026).
- Verify through channels you already have, never the phone number or website in the suspicious message (Irish Times, 2026).
- Assume AI makes fakes realistic: convincing emails, voices, and images are now cheap to produce (Irish Times, 2026).
- For families and small businesses, set clear payment controls and a second approval step for large transfers (Irish Times, 2026).

4. Hospitals on Alert: Threats Hit Building-Control Systems
Watch how a real fake plc security advisory unfolds — and the red flags that give it away.
The American Hospital Association is warning hospitals about an active cyber threat to building-control systems (Becker’s Hospital Review, 2026). The alert follows the NSA, CISA, and FBI flagging risks to Siemens S7 Series PLCs, the devices used in building-control systems (Becker’s Hospital Review, 2026).
For families, the takeaway is simple: hospitals are active targets right now, so treat any unexpected message claiming to be from one with extra suspicion (Becker’s Hospital Review, 2026).
How to Avoid This Scam
- Treat unexpected emails or texts about hospital bills, appointments, or patient portals as suspicious (Becker’s Hospital Review, 2026).
- Call the hospital’s published phone number to verify any message — never a number inside the message (Becker’s Hospital Review, 2026).
- If you work with building or industrial control systems, follow your organization’s patching and access rules without shortcuts (Becker’s Hospital Review, 2026).
- Report odd system behavior — strange login prompts, unusual messages, sluggish controls — to security teams right away (Becker’s Hospital Review, 2026).
5. Morrisville Schools: Phishing Texts Target Parents
Watch how a real fake school text phish unfolds — and the red flags that give it away.
The Marion C. Early School District in Morrisville is warning parents about a phishing scam circulating via text message (MSN, 2026). The district’s alert puts the school community on notice that scam texts are making the rounds (MSN, 2026).
How to Avoid This Scam
- Don’t click links in unexpected text messages related to your child’s school (MSN, 2026).
- Verify school messages by calling the district office at a number you already have (MSN, 2026).
- Never reply to a suspicious text with student or family information (MSN, 2026).
- Let the school know if you receive one so administrators can warn other parents (MSN, 2026).
What the Research Actually Says
Scam texts can be filtered automatically. A 2025 study in Computers & Security explored malicious SMS detection using ensemble learning and a data-balancing technique called SMOTE, with the goal of improving mobile cybersecurity (Xu et al., 2025, Computers & Security). In plain terms: researchers are building software that flags scam texts for you — a useful safety net, not a reason to drop your guard.
Login security has deep roots. A 2006 study in Computers & Security performed cryptanalysis — a systematic security review — of two password-based authentication schemes that use smart cards (Phan, 2006, Computers & Security). That work was an early reminder that the systems that “prove” who you are can carry hidden weaknesses (Phan, 2006, Computers & Security).
Repeat victimization follows routine. A study of 541 college women found that behavioral routines — everyday online habits — had the most explanatory power for repeated online victimization, including unwanted sexual advances, harassment, and unsolicited contacts (Reyns & Fissel, 2019, Violence & Victims). Individual characteristics and situational factors explained less than those routines (Reyns & Fissel, 2019).
The researchers say the findings provide guidance for prevention, policy, and research (Reyns & Fissel, 2019). For families, the lesson is practical: the online habits we repeat are part of our safety picture, not an afterthought.
Today’s Family Safety Checklist
- Make “verify before you act” a family rule — it’s the single action repeated across every scam in today’s briefing (FTC, 2026; Plummer, 2026; Irish Times, 2026).
- Stop using “it looks real” as your test — AI now makes fakes look routine and legitimate (Irish Times, 2026).
- Use automation as backup: research shows software can be trained to flag malicious SMS messages (Xu et al., 2025, Computers & Security).
- Review your family’s online routines — repeated-victimization research found everyday behaviors predicted who was targeted again (Reyns & Fissel, 2019, Violence & Victims).
SUPPORT KEMETIC MINDS
Enjoying this coverage? Back the work and find every way to connect with us in one place.
Support the Page →Kemetic Minds Analysis
Today’s briefing pulled from 5 news sources and 3 peer-reviewed studies. Today’s strongest research signal comes from Computers & Security (2006), cited 3 times — the kind of study worth weighing more heavily than a single news anecdote. The pattern worth watching isn’t any single scam headline — it’s whether today’s news matches what the research already predicts about who gets targeted and what actually reduces risk, or whether it’s a genuinely new variant the literature hasn’t caught up to yet.
References
- Bing News. (2026, August 20). The FTC is warning about a 'brushing scam.' Here's what to look out for. msn.com
- Bing News. (2026, August 21). 27% of Veterans Have Lost Money To Cyber Scams Offering Fake Benefits. military.com
- Bing News. (2026, August 20). Old-fashioned deception supercharged by technology. irishtimes.com
- Bing News. (2026, August 20). AHA warns hospitals of cyber threats on building-control systems. beckershospitalreview.com
- Bing News. (2026, August 20). On your side: Possible phishing text scam making the rounds in Morrisville schools. msn.com
- Phan (2006). Cryptanalysis of two password-based authentication schemes using smart cards. Computers & Security. doi.org/10.1016/j.cose.2005.11.005
- Xu, Qadir, Sadiq (2025). Malicious SMS detection using ensemble learning and SMOTE to improve mobile cybersecurity. Computers & Security. doi.org/10.1016/j.cose.2025.104443
- Reyns, Fissel (2019). Recurring Online Victimization Among College Women: Risk Factors From Within the Hookup Culture. Violence and Victims. doi.org/10.1891/0886-6708.vv-d-18-00186
Investigative Methodology: This briefing is generated on a fixed daily schedule (6:00 AM, America/Chicago) from live news wires and the CrossRef scholarly database. Every news claim is grounded in fetched source text with an APA7 in-text citation. Every peer-reviewed source is a real, DOI-verifiable journal article — filtered to results with a named author list, a named journal, and at least 3 citations to screen out predatory or uncited entries — never a fabricated or paraphrased-from-memory study. Every video embed is verified to be a real, existing video via YouTube’s oEmbed endpoint before publication. The featured image is a real photograph sourced from Pexels, not an AI-generated image. No Wikipedia sources are used.
Stay Connected

