KEMETIC MINDS
Cybersecurity & Scam Daily Briefing — September 06, 2026
Photo: Gustavo Fring via Pexels (source)
- The FBI warns that a password reset no longer stops attackers who get into your email through an OAuth consent phishing scam (Hoodline, 2026).
- The Washington Post reports credit card scammers are using a tactic that buries the bank fraud alerts meant to catch them (Washington Post, 2026).
- The Philippines’ SSS has put members and Uplift beneficiaries on alert for email and text scams (SunStar, 2026).
- Trezor’s breach now touches roughly 80,689 customers after old ShipMonk shipping logs surfaced despite repeated deletion assurances (CryptoSlate, 2026).
- Leaked shipping addresses tie people to hardware-wallet purchases, raising phishing and physical security risks (Daily Hodl, 2026).
1. The OAuth Consent Scam a Password Reset Can’t Stop
Watch how a real oauth ‘review my draft’ phish unfolds — and the red flags that give it away.
The FBI says the old fix for a hacked email — change your password — no longer works. It’s warning about a technique called OAuth consent phishing, which lets criminals keep reading, writing, and sending your email long after a fresh password is set (Hoodline, 2026).
Here’s how it works. A cyber actor registers an app with a legitimate OAuth provider, then poses as a government official, a media organization, or a well-known public figure. The scammer sends a link, often asking the target to “review a document”; clicking it produces an OAuth permission request, and approving it instantly gives the app access to the email account (Hoodline, 2026).
OAuth itself isn’t the problem — it’s the legitimate permission screen used by Google and Microsoft to let apps access data without a password. The damage happens when a malicious app asks to read and write your files and emails, and you click approve without realizing what you’ve granted (Hoodline, 2026). The Internet Crime Complaint Center has tracked this campaign since late 2025 and issued an alert on September 1 (Hoodline, 2026).
Once an app is approved, its access token bypasses your password and multi-factor authentication entirely. It stays valid until it is specifically revoked, which is why a password reset won’t save you (Hoodline, 2026).
How to Avoid This Scam
- Treat any permission screen that appears after you click a link in an email or direct message as a red flag, especially when the message pretends to be from a government official or known public figure (Hoodline, 2026).
- Read the full permission request before clicking allow, and refuse any app asking to read, write, or manage your email or files unless you deliberately sought it out (Hoodline, 2026).
- If you already approved a suspicious app, revoke its access in your account’s third-party app settings — a password change alone won’t remove it (Hoodline, 2026).
- Learn what a normal OAuth permission screen from Google or Microsoft looks like, so an unusual request stands out (Hoodline, 2026).

2. Credit Card Scammers Bury Bank Fraud Alerts
Watch how a real sms flood code phish unfolds — and the red flags that give it away.
The Washington Post reports that credit card scammers are using a tactic designed to bury the bank fraud alerts that would normally warn victims (Washington Post, 2026). A fraud alert is only useful if it actually reaches you in a form the scammer can’t hide.
The column was published September 5; full details of the tactic were not included in today’s briefing feed (Washington Post, 2026). The working takeaway: don’t let an alert you never see be your only line of defense.
How to Avoid This Scam
- Open your card issuer’s app or website and scan recent transactions yourself — don’t wait for an alert to be pushed to you.
- Verify your bank has your current phone number and email on file; buried alerts are far worse when they’re sent to an outdated address.
- If a fraud alert does arrive, confirm it independently by calling the number on the back of your card rather than replying to the message.

3. SSS Warns Members and Uplift Beneficiaries of Email and Text Scams
Watch how a real fake uplift benefit link unfolds — and the red flags that give it away.
The Philippines’ Social Security System has warned its members and Uplift beneficiaries to watch for email and text scams (SunStar, 2026). SunStar reported the warning on September 6 (SunStar, 2026).
Specific scam details from the warning were not included in today’s briefing feed (SunStar, 2026). An official alert like this is worth acting on before a message arrives: unsolicited emails and texts claiming to be from SSS or Uplift deserve immediate suspicion.
How to Avoid This Scam
- If an email or text claims to come from SSS or Uplift, don’t click its links or attachments (SunStar, 2026).
- Reach the agency through its official website or phone number rather than using contact details inside the message (SunStar, 2026).
- Never send ID numbers, bank details, or passwords in reply to an unsolicited message.
4. Trezor Breach Expands Sixfold as Old ShipMonk Logs Surface
Watch how a real fake wallet security alert unfolds — and the red flags that give it away.
Hardware wallet maker Trezor disclosed on September 4 that logistics vendor ShipMonk exposed contact and order data for roughly another 67,000 U.S. customers (CryptoSlate, 2026). Combined with the original August disclosure, the breach implies about 80,689 affected people, though Trezor hasn’t published a single combined figure or checked overlap between the groups (CryptoSlate, 2026).
The newly exposed records cover U.S. orders from November 2019 through August 2021 and include names, email addresses, phone numbers, shipping addresses, and order numbers. That data can connect an identifiable person and physical location to a hardware-wallet purchase, creating risks well beyond a normal email leak (CryptoSlate, 2026).
Trezor’s August 13 disclosure counted 11,742 customers fully exposed and 1,947 partially exposed, and said older order data had already been deleted. The September 4 update reverses that: records from 2019 to 2021 remained despite Trezor’s 90-day deletion policy and repeated written assurances from ShipMonk confirming deletion (CryptoSlate, 2026). The assurance letters and their dates have not been made public, and BleepingComputer reported the original access was tied to a vulnerability in analytics platform Metabase (CryptoSlate, 2026).
How to Avoid This Scam
- If you might have ordered from Trezor between November 2019 and August 2021, expect targeted scams built from your real name, address, phone number, and order details (CryptoSlate, 2026).
- Don’t assume the risk is over because Trezor says it requested deletion — treat the leaked data as permanently exposed (CryptoSlate, 2026).
- Apply extra skepticism to any unsolicited call, text, or mail about a “Trezor order,” since criminals now have exactly the details a convincing message needs (CryptoSlate, 2026).
5. Trezor Warns Customers of Higher Phishing and Physical Risks
Watch how a real phishy ‘wallet verification’ email unfolds — and the red flags that give it away.
On September 2, ShipMonk told Trezor that order records from November 2019 through August 2021 had remained in its systems and were swept up in the same August incident (Daily Hodl, 2026). About 67,000 U.S. customers’ full names, email addresses, phone numbers, shipping addresses, and order numbers were exposed (Daily Hodl, 2026).
Trezor said that “throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data,” and expressed disappointment that the deletion never actually happened (Daily Hodl, 2026). All affected customers received direct email notices from support@trezor.io; those who didn’t get a notice are not part of the expanded breach (Daily Hodl, 2026).
Trezor’s own systems and hardware wallets were not compromised — the incident originated entirely within ShipMonk’s infrastructure. Trezor nonetheless warned customers of heightened phishing and physical security risks because the leaked records tie identifiable people to wallet purchases (Daily Hodl, 2026).
How to Avoid This Scam
- Expect a second wave of phishing that quotes your real order history to look convincing; legitimate notices came from support@trezor.io (Daily Hodl, 2026).
- Don’t click links in unsolicited messages about your hardware wallet — open Trezor’s official website yourself if you need help (Daily Hodl, 2026).
- Watch for physical-world risks too: shipping addresses tied to wallet purchases can invite suspicious mail, fake delivery notices, or unexpected visitors, so verify anyone claiming to represent a delivery or crypto service (Daily Hodl, 2026).
What the Research Actually Says
No peer-reviewed studies were available in today’s briefing source set, so this section draws on what the official reports and alerts themselves document — not on academic journal findings.
Access tokens outlive passwords
The FBI and IC3 case shows that an approved app’s access token works independently of your password and multi-factor authentication, and lasts until it is specifically revoked. That is exactly why “change your password” is no longer a complete fix after an OAuth consent grant (Hoodline, 2026).
Deletion promises are not proof
Trezor requested and received written assurances from ShipMonk that customer data was deleted, yet records spanning 2019–2021 stayed in the vendor’s systems and were later exposed (CryptoSlate, 2026; Daily Hodl, 2026). A company’s confirmation that data is gone should never be treated as verification.
Attackers ride legitimate infrastructure
Both the OAuth scam and the Trezor supply-chain incident moved through trusted systems — a legitimate OAuth provider in the first case (Hoodline, 2026) and a real logistics vendor in the second (CryptoSlate, 2026). Trusting the platform itself isn’t enough; the specific request and the party making it still have to be checked (Hoodline, 2026).
Today’s Family Safety Checklist
- Audit third-party app access on your main email account this week — revoke anything you don’t recognize or actively use (Hoodline, 2026).
- Check card and bank transactions by opening the app or website directly at least weekly, rather than relying on alerts that scammers may be able to bury (Washington Post, 2026).
- Treat every breach notice as the start of a phishing wave, and expect messages that quote your real name, address, or order number (CryptoSlate, 2026; Daily Hodl, 2026).
- Slow down on anything urgent — a document to review, a benefit deadline, or a delivery problem — and reach the organization through its published official channel (Hoodline, 2026; SunStar, 2026).
Figure 1
Who is covering this
Note. Built from the Scam Watch stories cited in this report.
Black Excellence This Week
The hard news is real, and so is this. Wins reported by the Black press in the last 14 days:
- ATL Labor Day Classic Kicks Off With HBCU Football Rivalry
blackenterprise.com · 2026-09-03 - Florida HBCU Announces Historic Enrollment
miamiherald.com · 2026-09-02 - Winston-Salem State enrollment climbs as HBCU welcomes 5,200 – plus
hbcugameday.com · 2026-09-02
What You Can Do This Week
Not just bad news — here is where to push.
- Freeze your credit to block accounts compromised by the Trezor breach and follow email scam warnings. — Freeze your credit (annualcreditreport.com)
- Report phishing texts mimicking password resets or wire alerts directly to the FTC. — Report fraud (FTC)
- File a complaint against your bank for burying fraud alerts under credit card notification tactics. — File a consumer complaint (CFPB)
SUPPORT KEMETIC MINDS
Enjoying this coverage? Back the work and find every way to connect with us in one place.
Support the Page →Kemetic Minds Analysis
Today’s briefing pulled from 5 news sources and 0 peer-reviewed studies. No peer-reviewed source cleared today’s citation-count bar; treat today’s protection advice as news-grounded, not research-grounded. The pattern worth watching isn’t any single scam headline — it’s whether today’s news matches what the research already predicts about who gets targeted and what actually reduces risk, or whether it’s a genuinely new variant the literature hasn’t caught up to yet.
References
- Bing News. (2026, September 6). FBI Warns a Password Reset Won’t Save Your Hacked Email in New Scam. hoodline.com
- The Washington Post. (2026, September 5). Column | Credit card scammers are using this tactic to bury bank fraud alerts – The Washington Post. news.google.com
- SunStar Publishing Inc.. (2026, September 6). SSS warns members, Uplift beneficiaries vs email, text scams – SunStar Publishing Inc.. news.google.com
- Bing News. (2026, September 5). Users exposed by Trezor breach grows sixfold after supposedly deleted shipping logs are found. cryptoslate.com
- Bing News. (2026, September 5). Trezor Warns 67,000 U.S. Customers As Data Breach Discovery Expands. dailyhodl.com
Investigative Methodology: This briefing is generated on a fixed daily schedule (6:00 AM, America/Chicago) from live news wires and the CrossRef scholarly database. Every news claim is grounded in fetched source text with an APA7 in-text citation. Every peer-reviewed source is a real, DOI-verifiable journal article — filtered to results with a named author list, a named journal, and at least 3 citations to screen out predatory or uncited entries — never a fabricated or paraphrased-from-memory study. Every video embed is verified to be a real, existing video via YouTube’s oEmbed endpoint before publication. The featured image is a real photograph sourced from Pexels, not an AI-generated image. No Wikipedia sources are used.
Stay Connected

