KEMETIC MINDS
Cybersecurity & Scam Daily Briefing — September 01, 2026
Photo: Gustavo Fring via Pexels (source)
- Hasbro’s data breach exposed employee Social Security numbers and driver’s license data (Safestate, 2026).
- A Chrome extension with 70,000 users was weaponized to push fake update warnings (Bing News, 2026).
- Baptist Health warns patients about a widespread MyChart phishing campaign (Bing News, 2026).
- Scammers are sending “MyChart Medicare Kit” reward offers to patient portal users (Daily American, 2026).
- Research on online identity theft examines risk factors and protective factors (Holt & Turner, 2012, Deviant Behavior).
1. Weaponized Chrome Extension Pushes Fake Update Warnings
Watch how a real fake browser update alert unfolds — and the red flags that give it away.
A Chrome extension with 70,000 users and a 4.7-star rating began injecting fake update warnings after a threat actor acquired and weaponized it (Bing News, 2026).
According to the report, clicking the fake warnings can infect your computer (Bing News, 2026).
The case shows how a popular, trusted tool can become a danger after it changes hands (Bing News, 2026).
How to Avoid This Scam
- Never click an “update” pop-up that appears inside a website or extension; real Chrome updates run through Chrome’s own menus.
- Open your browser’s extensions page and remove anything you don’t recognize or didn’t intentionally install.
- If a page insists you update Chrome, close the tab and start the update from Chrome’s settings instead.

2. Baptist Health Warns Patients About MyChart Phishing
Watch how a real fake mychart login alert unfolds — and the red flags that give it away.
Baptist Health is warning patients about a widespread phishing scam targeting users of the MyChart medical portal (Bing News, 2026).
Phishing is the term for fake emails, texts, or websites that pretend to be a trusted service and try to steal your login information — the tactic behind this warning (Bing News, 2026).
The hospital system issued the alert so patients know the campaign exists (Bing News, 2026).
How to Avoid This Scam
- If you get a message about your MyChart account, don’t click its links — open your MyChart app or type your hospital’s web address yourself.
- No legitimate medical portal will ask for your password by email or text, so treat any such request as a phishing attempt.
- When in doubt, check your portal’s official website or app for security notices.

3. ‘MyChart Medicare Kit’ Reward Offers Are a Phishing Scam
Watch how a real fake medical rewards phish unfolds — and the red flags that give it away.
Scammers are sending emails or text messages that offer patients a chance to claim a reward in the form of a “MyChart Medicare Kit” (Daily American, 2026).
The messages are a phishing scam aimed at users of the MyChart patient portal (Daily American, 2026).
As with most phishing lures, the promise of a reward exists to pull you in; the bait itself is not real (Daily American, 2026).
How to Avoid This Scam
- Delete any email or text about a “MyChart Medicare Kit” — the reward offer is the scam (Daily American, 2026).
- Don’t click links or reply; instead, sign into your patient portal the way you always do and check for real notifications there.
- Treat “claim it now” urgency as a warning sign, not a reason to hurry.
4. Hasbro Breach Exposes Employee Social Security Numbers and Driver’s Licenses
Watch how a real breach-related phishing with fake id monitoring unfolds — and the red flags that give it away.
Hasbro has suffered a data breach that exposed employee Social Security numbers and driver’s license data (Safestate’s report on the Hasbro breach (Safestate, 2026).
The report does not say when the breach happened or how many employees were affected (Safestate, 2026).
Social Security numbers and driver’s license numbers are permanent pieces of personal identity, which is why this type of leak demands a fast response (Safestate, 2026).
How to Avoid This Scam
- If your employer reports a breach, don’t click links in related email; verify by calling HR or the company using a number you already have.
- When Social Security numbers have leaked, a credit freeze at the three major credit bureaus blocks criminals from opening new accounts in your name.
- Monitor bank and credit card statements closely for charges you don’t recognize.
What the Research Actually Says
One peer-reviewed study anchors the research side of today’s briefing: “Examining Risks and Protective Factors of On-Line Identity Theft,” published in the journal Deviant Behavior (Holt & Turner, 2012, Deviant Behavior).
As the title states, the study’s subject is the risk factors that make online identity theft more likely and the protective factors that make it less likely (Holt & Turner, 2012, Deviant Behavior).
In plain language, that means researchers study identity theft as a problem with identifiable causes and defenses, not pure luck (Holt & Turner, 2012, Deviant Behavior).
The abstract for this study was not available in today’s research feed, so we’re not quoting a statistic from it. We can accurately report its scope: an examination of the risks and protective factors of online identity theft (Holt & Turner, 2012, Deviant Behavior).
That framing connects directly to today’s news: phishing lures like the fake Chrome update and MyChart reward messages are attempts to gather the login and identity information that makes identity theft possible (Bing News, 2026; Daily American, 2026).
Today’s Family Safety Checklist
- Adopt the research-backed mindset: identity theft has risk factors and protective factors, so build your defenses before a scam message arrives (Holt & Turner, 2012, Deviant Behavior).
- Apply the pause-and-verify rule to every urgent message — fake Chrome updates, MyChart reward offers, breach notices — by using a channel you trust (Bing News, 2026; Daily American, 2026).
- If you use MyChart or any patient portal, never let an unsolicited message be your only route to “help”; go to the official app or website directly (Daily American, 2026; Bing News, 2026).
- When sensitive data like Social Security numbers is exposed, freeze your credit and watch your accounts carefully (Safestate, 2026).
SUPPORT KEMETIC MINDS
Enjoying this coverage? Back the work and find every way to connect with us in one place.
Support the Page →Kemetic Minds Analysis
Today’s briefing pulled from 5 news sources and 1 peer-reviewed study. Today’s strongest research signal comes from Deviant Behavior (2012), cited 65 times — the kind of study worth weighing more heavily than a single news anecdote. The pattern worth watching isn’t any single scam headline — it’s whether today’s news matches what the research already predicts about who gets targeted and what actually reduces risk, or whether it’s a genuinely new variant the literature hasn’t caught up to yet.
References
- Bing News. (2026, August 31). Fake Chrome update scam could infect your computer. msn.com
- Bing News. (2026, September 1). Baptist Health warns patients of MyChart phishing scam. msn.com
- Bing News. (2026, August 31). Phishing scam is targeting 'MyChart' patient portal users. dailyamerican.com
- Safestate. (2026, August 31). Hasbro Data Breach Exposed Employee SSNs and Driver's License Data – Safestate. news.google.com
- Daily American. (2026, August 31). Phishing scam is targeting 'MyChart' patient portal users – Daily American. news.google.com
- Holt, Turner (2012). Examining Risks and Protective Factors of On-Line Identity Theft. Deviant Behavior. doi.org/10.1080/01639625.2011.584050
Investigative Methodology: This briefing is generated on a fixed daily schedule (6:00 AM, America/Chicago) from live news wires and the CrossRef scholarly database. Every news claim is grounded in fetched source text with an APA7 in-text citation. Every peer-reviewed source is a real, DOI-verifiable journal article — filtered to results with a named author list, a named journal, and at least 3 citations to screen out predatory or uncited entries — never a fabricated or paraphrased-from-memory study. Every video embed is verified to be a real, existing video via YouTube’s oEmbed endpoint before publication. The featured image is a real photograph sourced from Pexels, not an AI-generated image. No Wikipedia sources are used.
Stay Connected

