Skip to content
Golden and blue Ancient Egyptian art with pharaoh, Eye of Horus, scarab, and "KEMETIC MIND" text.
Menu
  • Home
  • Breaking News
  • Live Trackers
    • Karmelo Anthony Case
    • Kohen Wiley Case
    • Nolan Wells Case
    • Global Conflict Tracker
    • Cyclospora Outbreak Map
    • Food Recall Tracker
    • Missing People in the United States
    • Bomb Threat Tracker
    • White Nationalist Activity
  • Tools
    • Numerology Calculator
    • Live Settlement Tracker
    • U.S. Voting Dates
    • Project 2025 Tracker
    • Frequently Asked Questions
  • Civil Rights
    • AT&T and Black America
  • Kemetic Wisdom
  • Numerology
  • World News
  • About Kemetic Minds
    • Contact
    • Telegram
  • Legal
    • Privacy Policy
    • Cookie Policy
    • Terms of Service
    • Disclaimer
Menu
Newsroom
Ethiopia Expels Egyptian Diplomatic Staff Member as Regional Tensions EscalateWorld War 3 Watch: Third US aircraft carrier heads for Mideast as Trump keeps Iran strikes on tableCraven County sheriff warns of scam calls posing as deputiesAfrican Union urges de-escalation amid tension between Ethiopia, Eritrea, EgyptWorld War 3 Watch: Talks End, a Third Carrier Heads to the Middle East, and What the Footage ShowsNicodemus KS Farmer’s Family Still Awaits Pigford PayoutFuel Price Watch — Evening, October 01, 2026: Diesel $6.39, Regular $4.41Third U.S. Carrier and About 9,000 Troops Head to the Middle East; What Iran’s Own Outlets Are SayingEthiopia Expels Egyptian Diplomatic Staff Member as Regional Tensions EscalateWorld War 3 Watch: Third US aircraft carrier heads for Mideast as Trump keeps Iran strikes on tableCraven County sheriff warns of scam calls posing as deputiesAfrican Union urges de-escalation amid tension between Ethiopia, Eritrea, EgyptWorld War 3 Watch: Talks End, a Third Carrier Heads to the Middle East, and What the Footage ShowsNicodemus KS Farmer’s Family Still Awaits Pigford PayoutFuel Price Watch — Evening, October 01, 2026: Diesel $6.39, Regular $4.41Third U.S. Carrier and About 9,000 Troops Head to the Middle East; What Iran’s Own Outlets Are Saying
Cybersecurity & Scam Daily Briefing

Consumer Rights · Sep 2, 2026Fake MyChart Portal Alerts Hit Patients as County Pays $128K Ransom

Posted on September 2, 2026, 8:05 AM CDT by Kemetic Mind

KEMETIC MINDS
Cybersecurity & Scam Daily Briefing — September 02, 2026


Photo: Gustavo Fring via Pexels (source)

📢 SPREAD THE WORD — Share this report

Facebook Post on X WhatsApp LinkedIn Reddit

Key Takeaways

  • Philadelphia health systems warn of a phishing scam mimicking MyChart patient portals (Bing News, 2026a).
  • Paradise Valley parents got texts claiming their child’s meal account was overdue (Bing News, 2026b).
  • Leaked Pocket Bitcoin files tie 291 customers’ names and addresses to public wallet activity (CryptoSlate, 2026).
  • The Keystone Newsroom independently flags MyChart portal phishing (The Keystone Newsroom, 2026).
  • Winona County paid $128k after a ransomware attack; experts warn other agencies (KAAL TV, 2026).

1. Fake MyChart Medicare Portal Scam — Philadelphia

SCAM WATCH: Fake Patient Portal Login
kemeticmind.com — Cybersecurity Scam Watch
✉Email • "MyChart Portal" (spoofed)
✉📧 New Email • Email
Your MyChart Medicare statement is ready. Confirm your coverage now: mychart-medicare-verify[.]com. Failure to verify will interrupt your benefits.
RED FLAG: Urgent tone
RED FLAG: Unknown link
RED FLAG: Medicare bait
🖱️ Click — I didn't request this. Why does the link ask for my Social Security number before showing my statement?
🔒 Ransomware Activates
This is our FINAL notice. Enter your full SSN and DOB within 24 hours or your Medicare coverage will be suspended indefinitely.
RED FLAG: Threat of suspension
RED FLAG: Requests full SSN
RED FLAG: Artificial deadline
HOW TO RESPOND
Never click a MyChart link inside an unexpected email. Instead, open your real hospital's app or type the official portal URL directly, then check the message center. Real health systems never demand your full SSN or threaten to suspend Medicare via email.

Watch how a real fake patient portal login unfolds — and the red flags that give it away.

Philadelphia-area health systems are warning residents to watch for an online phishing scam that mimics MyChart, the secure online patient portal used by most leading health systems (Bing News, 2026a). The campaign is described in a Bing News report as a MyChart Medicare phishing scam that has raised concern across the region (Bing News, 2026a).

The danger is that patients receive messages that look like they come from their hospital’s secure portal, built to steal login details or personal information (Bing News, 2026a). The published alert text does not spell out the exact wording of the lure yet, so the safest assumption is that any unsolicited MyChart or Medicare message is hostile until verified (Bing News, 2026a).

How to Avoid This Scam

  • Never click a login link inside an email or text about MyChart or Medicare — open your browser, type the official portal address yourself, and sign in there (Bing News, 2026a).
  • If a message demands payment, card numbers, or a Medicare ID, call the hospital using the phone number published on its official website — never the number inside the message (Bing News, 2026a).
  • Check the sender address and URL closely; portal-themed fakes often use addresses that look right at a glance but are slightly misspelled.
  • Report suspicious messages to your health system’s help desk or security team so it can confirm whether it is part of the active campaign (Bing News, 2026a).

Video: Parents beware: New phishing scam targeting school lunch accounts. Source: Arizona’s Family (3TV / CBS 5) .

2. Paradise Valley School Lunch ‘Overdue Balance’ Text Scam

SCAM WATCH: Fake Overdue Lunch Balance Text
kemeticmind.com — Cybersecurity Scam Watch
Text Message • "School Meal Services" (spoofed number)
School Meal Services: Your student's lunch account shows an overdue balance of $4.75. Pay now to avoid meal suspension. [link]
RED FLAG: unexpected balance alert
RED FLAG: payment link in text
RED FLAG: threatened meal suspension
I don't see that charge in our parent portal. Which school is this for, and what's the invoice or student ID number?
This is the final notice before suspension. Pay the $4.75 with a card at the secure link today or your child will be blocked from lunch tomorrow. [link]
RED FLAG: fake final notice
RED FLAG: card payment demanded
RED FLAG: short deadline
HOW TO RESPOND
Never tap meal-account links in unsolicited texts. Log in to the school district's official parent portal (typed in yourself) or call the food services office on the district's real website to verify any balance.

Watch how a real fake overdue lunch balance text unfolds — and the red flags that give it away.

School officials in the Paradise Valley School District warned parents after a text-message phishing scam claimed a student’s school meal account had an overdue balance (Bing News, 2026b). The warning, covered by Bing News, tells families the texts are not from the district.

These “smishing” text scams create money urgency around a believable hook like a school lunch account, which can push parents to tap a link or share payment details quickly (Bing News, 2026b). The district’s public warning is the official response, so families who verify any account balance through real district channels have a safe path (Bing News, 2026b).

How to Avoid This Scam

  • Do not tap links in unexpected texts about lunch money; open the meal account through the official app or the district’s website.
  • If the text threatens a late fee, a frozen account, or says your child “can’t eat,” slow down and call the school office — manufactured urgency is the tell.
  • Never enter a debit card, credit card, or bank number into a page you reached from an SMS link (Bing News, 2026b).
  • Report the text to the district and delete it, so other families can be alerted (Bing News, 2026b).

Video: Scottsboro Electric Power Board warns customers of phishing email scam. Source: 48 News.

3. Pocket Bitcoin Leak Reveals 291 Users’ Names and Wallets

SCAM WATCH: Breach Follow-Up Phishing
kemeticmind.com — Cybersecurity Scam Watch
✉Email • "Bitcoin Wallet Alert" (spoofed)
✉📧 New Email • Email
We detected a new device login to your Bitcoin wallet. Since your records were in a recent support breach, verify your recovery phrase at [link] within 24 hours or your funds may be frozen.
RED FLAG: Creates false urgency
RED FLAG: Requests recovery phrase
RED FLAG: Unfamiliar link
🖱️ Click — Why would support ask for my recovery phrase? I'll go to the official site and contact them directly instead.
🔒 Ransomware Activates
Final notice: the leaked files show your name, home address, and last Bitcoin payment. Click the verification link now to prevent your account being locked.
RED FLAG: Uses leaked personal data
RED FLAG: Final notice pressure
RED FLAG: Repeats link request
HOW TO RESPOND
If an unsolicited email mentions leaked personal details or recent Bitcoin activity, do not click its link or share a recovery phrase. Open the official website yourself and contact support through the verified channel.

Watch how a real breach follow-up phishing unfolds — and the red flags that give it away.

Pocket Bitcoin, a Swiss non-custodial Bitcoin service — meaning it never held customers’ private keys — said copied support records exposed identity and compliance data for 291 customers, sometimes matching real names directly to public Bitcoin activity (CryptoSlate, 2026). An August 31 update expanding its August 21 disclosure says the files contained varying combinations of names, postal addresses, Bitcoin addresses, identity-document copies, and source-of-funds records (CryptoSlate, 2026).

The money itself is safe: spending Bitcoin requires a valid signature made with the corresponding private key, the secret code that unlocks it, and the company reported no risk to customer funds (CryptoSlate, 2026). The real dangers are privacy and deception — anyone can inspect the balance and history of a public Bitcoin address, and Swiss authorities have documented scams that use a victim’s real home address to increase pressure (CryptoSlate, 2026).

How to Avoid This Scam

  • Assume any Bitcoin address tied to your name is public forever; the leaked data just removed the separation between your offline identity and blockchain activity (CryptoSlate, 2026).
  • Treat any email, call, or text that mentions Pocket Bitcoin or this breach as a possible scam, and reach the company only through its official website (CryptoSlate, 2026).
  • If a message quotes your real home address to “prove” it is legitimate, that matches a documented pressure tactic — delete it or hang up (CryptoSlate, 2026).
  • Change the password on any email tied to the affected accounts and turn on two-factor authentication wherever it is available.

phishing email laptop warning
Photo: Markus Winkler via Pexels (source)

4. Keystone Newsroom Confirms MyChart Portal Phishing

SCAM WATCH: Fake Patient Portal Login Alert
kemeticmind.com — Cybersecurity Scam Watch
✉Email • Patient Portal (spoofed)
✉📧 New Email • Email
Alert: You have a new secure message in your patient portal. Review and respond within 24 hours to avoid account suspension. Sign in at https://health-portal-security.update
RED FLAG: Urgency/lockout
RED FLAG: Look-alike link
RED FLAG: Unsolicited link
🖱️ Click — I don't see any new message when I open the app. Why send me a link? I’ll just log in directly like I always do.
🔒 Ransomware Activates
This is a mandatory security verification. If you don't click the link and confirm your identity, your medical records will be locked and you may miss upcoming appointments.
RED FLAG: Threatens lockout
RED FLAG: False deadline
RED FLAG: Spoofed sender
HOW TO RESPOND
Never tap email links to log in to your patient portal. Open your healthcare provider's official app or website directly and check messages there. If in doubt, call your provider using the number on your insurance card—not the one in the email.

Watch how a real fake patient portal login alert unfolds — and the red flags that give it away.

A separate report from The Keystone Newsroom, published Tuesday, warns that a phishing scam is targeting MyChart patient portal users (The Keystone Newsroom, 2026). It independently echoes the Philadelphia-area health system alerts, meaning two credible sources are flagging the same campaign (The Keystone Newsroom, 2026; Bing News, 2026a).

For patients who use MyChart, the takeaway is straightforward: do not let a familiar hospital logo lower your guard, and verify any portal-related message through the secure app or a web address you typed yourself (The Keystone Newsroom, 2026).

How to Avoid This Scam

  • Before answering any MyChart message, open your health system’s portal the way you always do and look for the same alert inside the secure app.
  • Legitimate portals do not ask for your full password, Medicare number, or card details through email or text.
  • If you already clicked a suspicious link and entered your login, change your MyChart password immediately and tell your health system’s security team.

family online safety internet security
Photo: Ann H via Pexels (source)

5. Winona County’s $128k Ransomware Payment

SCAM WATCH: Ransomware Negotiation Email
kemeticmind.com — Cybersecurity Scam Watch
✉Email • "Security Alert" (spoofed)
✉📧 New Email • Email
Your network has been breached and files encrypted. Send 0.9 bitcoin to [wallet] within 48 hours to receive the decryption key. Contact us after payment.
RED FLAG: Claims files encrypted
RED FLAG: Cryptocurrency-only payment
RED FLAG: Fixed 48-hour deadline
🖱️ Click — I'm not sending crypto until you prove my files are actually encrypted. How do I know this isn't a scam?
🔒 Ransomware Activates
Check your desktop for “SECURE-test.xlsx” — that’s proof. If you notify authorities, the ransom doubles and we leak your client records. We’ll know if you do.
RED FLAG: Mentions planted file
RED FLAG: Threatens ransom hike
RED FLAG: Claims to monitor victim
HOW TO RESPOND
Real ransomware groups don’t negotiate over a casual email thread before you’ve confirmed the infection on your own machine. If you see a ransom demand, disconnect the device right away, contact your IT/security team or a trusted incident-response firm, and never reply to the scammers — replying confirms your address is active and can invite more attacks.

Watch how a real ransomware negotiation email unfolds — and the red flags that give it away.

Winona County paid $128k following a ransomware attack, and cybersecurity experts are using the case to issue a warning (KAAL TV, 2026). The KAAL TV report, published September 1, does not describe how the attack began or which county systems were affected (KAAL TV, 2026).

Ransomware attacks hold an organization’s systems hostage until money is paid, and a county payout of this size is exactly the outcome experts are warning others to try to prevent (KAAL TV, 2026). For residents, the practical lesson is about preparedness: strong household backups reduce the damage any future attack can do to your own files (KAAL TV, 2026).

How to Avoid This Scam

  • If your county or city reports a ransomware attack, expect follow-up scams pretending to be from county offices, and verify every contact through official channels (KAAL TV, 2026).
  • Keep backups of important photos, documents, and tax files on a separate drive or service so no one can hold your data hostage.
  • Follow the county’s official website and local news for real updates instead of relying on forwarded messages or screen-shotted alerts.

What the Research Actually Says

No peer-reviewed studies were included in today’s research feed, and this briefing does not invent findings that are not there. Every fact above comes from the named news reports and is cited inline (Bing News, 2026a, 2026b; CryptoSlate, 2026; KAAL TV, 2026; The Keystone Newsroom, 2026).

When peer-reviewed research is available in a future briefing, this section will explain in plain language what a study actually found, who was studied, and what it means for how your family should react to the day’s scams.


Today’s Family Safety Checklist

  • Treat every urgent money message — an overdue lunch bill, a Medicare portal warning, a wallet “verification” — as a script designed to rush you (Bing News, 2026a, 2026b; CryptoSlate, 2026).
  • Reach official services only through addresses you type yourself or save as bookmarks, never through links inside texts or emails.
  • Assume data that leaks once — a school account, a patient portal, a crypto compliance file — can surface again in future scams, so use unique passwords for each account (CryptoSlate, 2026; The Keystone Newsroom, 2026).
  • Take one protective action tonight: back up your files, turn on two-factor login for email, or show someone in your family what today’s scam texts look like (Bing News, 2026b; KAAL TV, 2026).

SUPPORT KEMETIC MINDS

Enjoying this coverage? Back the work and find every way to connect with us in one place.

Support the Page →

Kemetic Minds Analysis

Today’s briefing pulled from 5 news sources and 0 peer-reviewed studies. No peer-reviewed source cleared today’s citation-count bar; treat today’s protection advice as news-grounded, not research-grounded. The pattern worth watching isn’t any single scam headline — it’s whether today’s news matches what the research already predicts about who gets targeted and what actually reduces risk, or whether it’s a genuinely new variant the literature hasn’t caught up to yet.


References

  1. Bing News. (2026, September 2). MyChart Medicare phishing scam raises concern among Philadelphia health systems. msn.com
  2. Bing News. (2026, September 1). Paradise Valley School District warns parents of text message phishing scam. msn.com
  3. Bing News. (2026, September 1). Leaked compliance records shatter anonymity of 291 crypto users by matching names directly to wallet activity. cryptoslate.com
  4. The Keystone Newsroom. (2026, September 1). Phishing scam is targeting ‘MyChart’ patient portal users – The Keystone Newsroom. news.google.com
  5. kaaltv.com. (2026, September 1). Cybersecurity experts issue warning after Winona County pays $128k following ransomware attack – kaaltv.com. news.google.com

Investigative Methodology: This briefing is generated on a fixed daily schedule (6:00 AM, America/Chicago) from live news wires and the CrossRef scholarly database. Every news claim is grounded in fetched source text with an APA7 in-text citation. Every peer-reviewed source is a real, DOI-verifiable journal article — filtered to results with a named author list, a named journal, and at least 3 citations to screen out predatory or uncited entries — never a fabricated or paraphrased-from-memory study. Every video embed is verified to be a real, existing video via YouTube’s oEmbed endpoint before publication. The featured image is a real photograph sourced from Pexels, not an AI-generated image. No Wikipedia sources are used.

Stay Connected

Join @kemeticMinds on Telegram →

Kemetic Minds Editorial Desk

Kemetic Minds Editorial Desk

Verified Newsroom

Primary-sourced investigative intelligence on civil rights, voting rights, federal policy, and consumer protection. Sourced from primary legal filings, government statistics, and direct field reporting.

Editorial Standards & Policy → Join Telegram Alerts

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

📩 Subscribe for New Posts

Get Kemetic Minds stories in your inbox: weekly, monthly or quarterly. No account needed.

How often?

📡 Subscribe via RSS

Get every new Kemetic Minds post delivered straight to your favorite RSS reader (Feedly, Inoreader, Apple News, etc.).

Subscribe to RSS Feed →

📨 Get Terror Watch alerts by email

An email when a terror attack is reported by several independent outlets or an official source. Rare, factual, and you can stop any time.

Live Alerts
Fetching verified headlines...
Real-time news • Updates every minute

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • October 2, 2026, 5:41 AM CDT by Kemetic Mind Ethiopia Expels Egyptian Diplomatic Staff Member as Regional Tensions Escalate
  • October 2, 2026, 3:22 AM CDT by Kemetic Mind World War 3 Watch: Third US aircraft carrier heads for Mideast as Trump keeps Iran strikes on table
  • October 2, 2026, 1:10 AM CDT by Kemetic Mind Craven County sheriff warns of scam calls posing as deputies
  • October 2, 2026, 12:41 AM CDT by Kemetic Mind African Union urges de-escalation amid tension between Ethiopia, Eritrea, Egypt
  • October 1, 2026, 9:21 PM CDT by Kemetic Mind World War 3 Watch: Talks End, a Third Carrier Heads to the Middle East, and What the Footage Shows

Browse by Topic

Pages

  • About Kemetic Minds
  • Bomb Threat Tracker: Live U.S. Map
  • Contact
  • Cookie Policy
  • Cyclospora Outbreak Map: U.S. State-by-State Tracker (Live)
  • Cyclospora Tracker Subscribers (do not delete)
  • Disclaimer
  • Frequently Asked Questions
  • Home
  • Kemetic Minds on Telegram
  • Live Settlement Tracker: Open Class Action Claims
  • LIVE UPDATES: Justice for Kohen Wiley — Tracking the Senatobia Police Killing
  • LIVE UPDATES: Middle East Escalation & Global War Tensions
  • LIVE UPDATES: The Karmelo Anthony Case — Austin Metcalf Murder Trial & Appeal
  • LIVE UPDATES: The Nolan Wells Case — Horn Island, Mississippi
  • LIVE: Food Recall & Foodborne Illness Tracker — Search by State
  • Ma'at Feedback Log (Internal)
  • Missing People in the United States
  • Moved: About Kemetic Minds
  • Nolan Wells: Data & Timeline Dashboard
  • Privacy Policy
  • Project 2025 Tracker: Timeline & Impact on the Black Community
  • Pythagorean Numerology Calculator — Words, Names, Dates & Historical Connections
  • Terms of Service
  • U.S. Voting Dates
  • US Power Outage Tracker
  • White Nationalist Activity Tracker

Kemetic Mind Telegram

Click Here
© 2026 Kemetic Minds | Powered by Minimalist Blog WordPress Theme
Ask Ma’at
Ma’at is thinking…

Powered by
Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
None
Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
None
Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
None
Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
None
Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
None
Powered by