KEMETIC MINDS
Cybersecurity & Scam Daily Briefing — August 18, 2026
Photo: Gustavo Fring via Pexels (source)
- Pokémon Center UK/Germany customers’ names, addresses, phones, emails, and order details were stolen via logistics partner CEVA (BleepingComputer, 2026).
- Valve told European Steam hardware customers the same types of data were exposed in the CEVA attack (BleepingComputer, 2026).
- Three-quarters of ransomware attacks now target mid-market firms, putting smaller businesses on the front line (Infosecurity Magazine, 2026).
- A new Akira ransomware attack disabled security tools — then its own encryptor crashed (Bing News, 2026).
- Overconfidence — thinking “it won’t happen to me” — was a predictor of online fraud victimization in a 2025 study (Balakrishnan et al., 2025, PLOS ONE).
- Fake rental listings are a known scam track, and Bitdefender published a guide on spotting them (Bitdefender, 2026).
1. Quick Signs That Reveal a Scam
Watch how a real fake bank fraud / one-time passcode scam unfolds — and the red flags that give it away.
A new video briefing from Bing News shows that a few simple checks can reveal a scam before you respond or share information (Bing News, 2026).
The clip walks through quick indicators to watch for and invites viewers to add their own warning signs (Bing News, 2026).
How to Avoid This Scam
- Before replying to any unexpected message, stop and run a simple check — quick checks catch most scams (Bing News, 2026).
- If someone pressures you to share information immediately, treat the pressure itself as a warning sign.
- Build a family list of warning signs so every household member spots the same patterns faster.
Video: My Parents Replaced My Wedding Cake With My Sister’s Gender Reveal Cake—So I Took Back the Mic. Source: Revenge Served Cold.
2. Fake Rental Listings
Watch how a real fake rental listing deposit unfolds — and the red flags that give it away.
Security firm Bitdefender published a guide on how to spot and avoid fake rental listings (Bitdefender, 2026).
The guide is aimed at anyone searching for housing online, where fraudulent ads are common (Bitdefender, 2026).
How to Avoid This Scam
- Read Bitdefender’s rental-scam guide before you hunt for an apartment, and share it with anyone in your household who is searching (Bitdefender, 2026).
- See the property yourself — in person or on a live video call — before sending money or personal documents.
- Paste the listing’s photos and text into a search engine to check whether the same ad reappears under a different name or owner.
- Never pay a deposit until you have a written lease and can confirm the person is the actual owner.

3. Pokémon Center Data Breach
Watch how a real fake order cancellation refund phish unfolds — and the red flags that give it away.
Pokémon Center is notifying customers in the United Kingdom and Germany that their personal and order information was stolen — but the breach happened at third-party shipping partner CEVA Logistics, not at Pokémon Center itself (BleepingComputer, 2026).
Attackers broke into CEVA’s systems between July 29 and August 1, and the exposed records included names, addresses, phone numbers, email addresses, and information about ordered products for PokemonCenter.com customers (BleepingComputer, 2026).
CEVA is a subsidiary of the CMA CGM Group, the world’s third-largest shipping company, with 1,000 warehouses and $18.3 billion in revenue in 2025 (BleepingComputer, 2026). The same attack also hit Valve, which notified European Steam hardware customers that their names, addresses, phone numbers, emails, and product order information were stolen (BleepingComputer, 2026).
Eight European warehouses were disrupted, causing shipping delays, and Pokémon Center canceled some orders, telling customers: “We’re sorry to inform you that we have had to cancel your recent order [order number] due to an unforeseen fulfilment issue” (BleepingComputer, 2026).
How to Avoid This Scam
- If you ordered from PokemonCenter.com in the UK or Germany, check your inbox for a data breach notification from Pokémon Center (BleepingComputer, 2026).
- Go to the retailer’s official website directly — don’t click links in emails claiming to be about the breach.
- Be extra suspicious of calls or texts that reference your recent order: names, addresses, and phone numbers were exposed, so criminals can make such messages look convincing (BleepingComputer, 2026).
- Expect some legitimate delays: the attack disrupted eight European warehouses, so real logistics emails will be mixed in with scam attempts (BleepingComputer, 2026).

4. Akira Ransomware’s Self-Own Goal
Watch how a real fake edr "fix" lure unfolds — and the red flags that give it away.
In a new attack, the Akira ransomware gang disabled EDR tools at a victim’s systems — but then its own encryptor crashed, and researchers described the gang as crashing its own attack (Bing News, 2026).
EDR (endpoint detection and response) is security software that watches computers for signs of an attack; ransomware gangs commonly try to disable it first (Bing News, 2026).
Researchers still warn that this “worrying practice” — shutting down security tools before encryption — continues, even though this particular attempt failed (Bing News, 2026).
How to Avoid This Scam
- If you run a business, keep EDR running and make sure its alerts actually reach a human — attackers try to kill this software first (Bing News, 2026).
- Don’t rely on attackers making mistakes: this encryptor crashed, but ransomware gangs learn and adjust (Bing News, 2026).
- If your security software suddenly disappears or turns itself off, disconnect the device from the network and get help immediately.
5. Ransomware Hits Mid-Market Firms Hard
Watch how a real fake supplier invoice ransomware unfolds — and the red flags that give it away.
Three-quarters of ransomware attacks target mid-market firms, according to reporting from Infosecurity Magazine (Infosecurity Magazine, 2026).
Mid-market firms are businesses bigger than a local shop but smaller than a global corporation — exactly the organizations that often lack a full security team (Infosecurity Magazine, 2026).
How to Avoid This Scam
- If you own or make IT decisions for a midsize company, treat ransomware as a “when,” not an “if” (Infosecurity Magazine, 2026).
- Keep at least one backup disconnected from your network so an attacker can’t encrypt it.
- Ask your employer or your company’s IT decision-maker where backups live and whether they’ve been tested — before an attack, not after.
What the Research Actually Says
A two-part 2025 study of Malaysian adults (820 people in the first survey, 629 in the validation survey) found that overconfidence predicted online fraud victimization, with an odds ratio of 1.453 (95% CI [1.119, 1.887], p = 0.005) (Balakrishnan et al., 2025, PLOS ONE). In plain terms: people who were most sure they could never be scammed were about 45% more likely to become victims, even though most respondents said they were aware of digital privacy (Balakrishnan et al., 2025, PLOS ONE).
The same study found that social influence — being swayed by others — also predicted victimization, and it identified five survey factors: self-awareness, safe practice, bank trust, overconfidence, and social influence (Balakrishnan et al., 2025, PLOS ONE).
On identity theft, a 2011 study in the Journal of Financial Crime examined consumer identity theft prevention and identity fraud detection behaviours — what actions consumers can take to prevent theft and catch fraud early (Archer, 2011, Journal of Financial Crime).
A 2023 study in SN Computer Science — “Engineering the Human Mind: Social Engineering Attack Using Kali Linux” — examined how attackers use the Kali Linux toolkit to run social engineering attacks, meaning they trick people instead of hacking the computer directly (James, 2023, SN Computer Science).
Today’s Family Safety Checklist
- Drop the “it won’t happen to me” mindset: overconfidence predicted victimization in the 2025 PLOS ONE study, so walk through real scam scripts with your family instead (Balakrishnan et al., 2025, PLOS ONE).
- Run the quick check before every reply: pause, verify the sender, and never share information on demand (Bing News, 2026).
- If you ordered from Pokémon Center or another CEVA-shipped retailer, assume your name, address, and phone number are exposed, and treat any call or text referencing your order with suspicion (BleepingComputer, 2026).
- If you own or work for a midsize company, push for tested offline backups and security monitoring: three-quarters of ransomware attacks target mid-market firms (Infosecurity Magazine, 2026).
SUPPORT KEMETIC MINDS
Enjoying this coverage? Back the work and find every way to connect with us in one place.
Support the Page →Kemetic Minds Analysis
Today’s briefing pulled from 5 news sources and 3 peer-reviewed studies. Today’s strongest research signal comes from PLOS ONE (2025), cited 13 times — the kind of study worth weighing more heavily than a single news anecdote. The pattern worth watching isn’t any single scam headline — it’s whether today’s news matches what the research already predicts about who gets targeted and what actually reduces risk, or whether it’s a genuinely new variant the literature hasn’t caught up to yet.
References
- Bing News. (2026, August 18). Quick signs that can reveal a scam. msn.com
- bitdefender.com. (2026, August 18). Rental scams: How to spot and avoid fake rental listings – bitdefender.com. news.google.com
- Bing News. (2026, August 17). Pokémon Center data breach exposes customer info, cancels some orders. bleepingcomputer.com
- Bing News. (2026, August 17). Ransomware gang crashes own attack — with no one to blame but themselves. msn.com
- Bing News. (2026, August 18). Three-quarters of Ransomware Attacks Target Mid-Market Firms. infosecurity-magazine.com
- Balakrishnan, Ahhmed, Basheer (2025). Personal, environmental and behavioral predictors associated with online fraud victimization among adults. PLOS ONE. doi.org/10.1371/journal.pone.0317232
- James (2023). Engineering the Human Mind: Social Engineering Attack Using Kali Linux. SN Computer Science. doi.org/10.1007/s42979-023-02321-y
- Archer (2011). Consumer identity theft prevention and identity fraud detection behaviours. Journal of Financial Crime. doi.org/10.1108/13590791211190704
Investigative Methodology: This briefing is generated on a fixed daily schedule (6:00 AM, America/Chicago) from live news wires and the CrossRef scholarly database. Every news claim is grounded in fetched source text with an APA7 in-text citation. Every peer-reviewed source is a real, DOI-verifiable journal article — filtered to results with a named author list, a named journal, and at least 3 citations to screen out predatory or uncited entries — never a fabricated or paraphrased-from-memory study. Every video embed is verified to be a real, existing video via YouTube’s oEmbed endpoint before publication. The featured image is a real photograph sourced from Pexels, not an AI-generated image. No Wikipedia sources are used.
Stay Connected

