KEMETIC MINDS
Cybersecurity & Scam Daily Briefing — September 13, 2026
Photo: Gustavo Fring via Pexels (source)
- Hackers tricked Revolut into handing over customers’ passports and Bitcoin histories (CryptoSlate, 2026).
- A second outlet calls the same event a data leak exposing Bitcoin and identity info (The Cryptonomist, 2026).
- Fake iPhone Duo sites spiked around Apple’s launch, using AI-copied storefronts (NewsBytes, 2026).
- One Conti malware developer received a four-year sentence (Security Affairs, 2026).
- Today’s source packet included no peer-reviewed studies.
1. Revolut Tricked Into Handing Over Customer Passports
Watch how a real breach follow-on “fraud team” text unfolds — and the red flags that give it away.
Hackers tricked Revolut into handing them the passports and Bitcoin transaction histories of wealthy customers, according to CryptoSlate (CryptoSlate, 2026).
Those are two of the most sensitive records a financial app holds: a government ID document and a record of how much cryptocurrency a person owns and moves (CryptoSlate, 2026).
The report does not say how the trick worked, how many customers were affected, or when it happened (CryptoSlate, 2026).
What is not yet answered
If you hold a Revolut account, the open question tonight is whether you will be told you were affected — and how fast (CryptoSlate, 2026).
CryptoSlate’s report gives no detail on notifications, no timeline for customers, and no company statement (CryptoSlate, 2026).
How to Avoid This Scam
- Treat unexpected calls, texts, or emails mentioning your Revolut account as a possible follow-up to this leak — hang up and call the number printed on your own card.
- Never send a fresh photo of your passport or driver’s licence to anyone who contacted you first.
- You cannot take back an ID copy that has already leaked, so watch your account logins for anything you did not do.
- Be suspicious of any message quoting your exact Bitcoin balance or pushing you to move funds to a “safe wallet.”
Video: Pawpads Daily 09/13 OpenAI Delays IPO, Inflation Outpaces Wages, Revolut Data Leak. Source: 肉球日報 PawpadsNews.
2. Same Breach, Two Different Words: “Leak” vs. “Tricked”
Watch how a real breach follow-on wallet phishing unfolds — and the red flags that give it away.
The Cryptonomist reported the same Revolut incident, describing it as a data leak that exposed sensitive Bitcoin and identity information (The Cryptonomist, 2026).
So two outlets describe one event two ways: one says hackers tricked the company, the other says data leaked (CryptoSlate, 2026; The Cryptonomist, 2026).
Why the wording matters to you
A leak can mean someone made a mistake. A trick means a person was deliberately targeted — and a method that worked once can be pointed at other companies (CryptoSlate, 2026; The Cryptonomist, 2026).
Neither report names a number of affected customers, and neither says whether Revolut has contacted them (CryptoSlate, 2026; The Cryptonomist, 2026).
How to Avoid This Scam
- Read any breach notice you receive from a financial app all the way through — the useful part is the list of what was exposed, not the apology.
- If your ID document is in a leaked batch, keep a dated record of when you were told and what the company said was taken.
- Reuse of the same password across crypto and banking apps turns one leak into several — change the reused ones now.
- Expect the attacker’s next move to be a message that sounds like customer service, because they already know your details.

3. Fake iPhone Duo Sites Target Launch-Day Buyers
Watch how a real fake iphone preorder storefront unfolds — and the red flags that give it away.
Scam websites promising discounted new iPhones spiked around Apple’s launch, including the first-ever foldable, the iPhone Duo (NewsBytes, 2026).
Researchers found a surge of scam domains registered with keywords like “Apple” and “iPhone” in the name, and some appeared days before Apple’s official announcement (NewsBytes, 2026).
Alexandre Francois, a scam investigator at WhoisXML API, said the fake stores look convincingly real because scammers use AI to copy genuine retailers (NewsBytes, 2026).
One example he gave: a fake page advertising “all-day battery” for an iPhone Pro Max in three different colors (NewsBytes, 2026).
Two red flags worth memorizing
Francois warned that fraudulent sites often accept payment only by bank transfer, which does not carry the protections that debit and credit card payments do (NewsBytes, 2026).
They also push a limited-time window to buy, so shoppers hurry past the warning signs (NewsBytes, 2026).
Apple has issued a warning about these scams as well (NewsBytes, 2026).
How to Avoid This Scam
- Pay with a credit or debit card, never a bank transfer — if a phone store offers transfer as its only option, close the tab.
- Shop the launch through Apple’s own site or a retailer you have used before, and type the address yourself instead of clicking an ad.
- Treat any countdown timer or “only 3 left” banner on a phone deal as a pressure tactic, not information.
- A discount that beats every official price on a brand-new model is the scam, not the deal — check the price on Apple’s site first.

4. Conti Malware Developer Sentenced to Four Years
Watch how a real fake breach-data extortion email unfolds — and the red flags that give it away.
A hacker who the report says built malware for the Conti ransomware operation and attacked victims has been sentenced to four years (Security Affairs, 2026).
The headline ties the case directly to malware development — writing the code that locks up other people’s computers and data (Security Affairs, 2026).
The report does not name the defendant, the court, or the country where the sentence was handed down (Security Affairs, 2026).
Why a four-year sentence is news at your kitchen table
Ransomware reaches families through hospitals, schools, and small businesses that cannot open their files (Security Affairs, 2026).
One conviction does not switch off that risk, and the report gives no word on whether other Conti members are still being pursued (Security Affairs, 2026).
How to Avoid This Scam
- Ransomware counts on you having no copy of your files — keep an offline backup of photos and documents you could not replace.
- Do not pay a ransom demand; there is no guarantee in this report or any other that paying returns your files.
- If your workplace or your child’s school is hit, expect operations to stop for days — ask now how they would reach you.
5. Second Outlet Confirms the Conti Sentence
Watch how a real fake ransomware extortion email unfolds — and the red flags that give it away.
A second outlet reported the same outcome, putting the Conti ransomware hacker’s sentence at four years (Tech Insider, 2026).
Two independent write-ups landing on the same number is a useful cross-check — it means the duration is not a single outlet’s misreading (Security Affairs, 2026; Tech Insider, 2026).
Neither report names the defendant or describes which victims were attacked (Security Affairs, 2026; Tech Insider, 2026).
What is still missing
Arrests and sentences are the visible part of ransomware; the crews themselves are the part families actually meet (Tech Insider, 2026).
Watch for the details that usually follow: the defendant’s name, the court, and whether more charges are coming (Security Affairs, 2026; Tech Insider, 2026).
How to Avoid This Scam
- Treat news of a ransomware arrest as good news, not as an all-clear — the tools and the tactics outlive the people who wrote them.
- Keep your devices updated on a schedule you set, not when a warning appears on screen.
- If a pop-up or email claims your files are encrypted and demands payment, do not follow its links — report it to your IT contact or the platform first.
What the Research Actually Says
No peer-reviewed studies were included in today’s source packet, so this briefing has no new academic finding to report. That absence is a gap in the day’s evidence, not a result.
What today’s reporting does offer is named expert guidance. Alexandre Francois, a scam investigator at WhoisXML API, told NewsBytes that fake retail sites look convincing because scammers use AI to copy real storefronts (NewsBytes, 2026).
His two specific indicators were payment method and time pressure: sites that only take bank transfers, and sites that give shoppers a limited window to buy (NewsBytes, 2026).
Those are the closest thing to tested guidance in today’s material, and they come from an investigator’s observation — not from a controlled study (NewsBytes, 2026).
Revolut customers get no equivalent guidance yet. Both crypto outlets are silent on what the company is telling the people whose passports and Bitcoin histories were handed over (CryptoSlate, 2026; The Cryptonomist, 2026).
Today’s Family Safety Checklist
- Pay by card, never bank transfer. The one concrete rule in today’s reporting comes from a scam investigator: fraudulent sites push transfers because that money is harder to claw back (NewsBytes, 2026).
- Countdown timers are a warning, not a deal. Limited-time pressure was flagged as a marker of fake stores — so a clock on a checkout page is a reason to slow down (NewsBytes, 2026).
- Assume a leaked ID copy stays leaked. Passports are among the data handed over in the Revolut incident, so anyone in that batch should watch their own accounts rather than wait for a fix (CryptoSlate, 2026; The Cryptonomist, 2026).
- One sentencing is not the end of ransomware. A four-year sentence for a Conti malware developer does not remove the risk from the schools, hospitals, and businesses families depend on (Security Affairs, 2026; Tech Insider, 2026).
Black Excellence This Week
The hard news is real, and so is this. Wins reported by the Black press in the last 14 days:
- Wendy Williams’s producer opens up, but not about everything
rollingout.com · 2026-09-13 - Another North Carolina HBCU shatters enrollment record as Black colleges surge
miamiherald.com · 2026-09-11 - 5 Things You May Not Know About XCEL Award Honoree Dr. Bernard Harris
blackenterprise.com · 2026-09-10 - HBCUs Are Building New Support Systems for Black Male Students
capitalbnews.org · 2026-09-08
What You Can Do This Week
Not just bad news — here is where to push.
- Freeze your credit with Equifax, Experian and TransUnion this week if Revolut ever held your passport or Bitcoin data — Freeze your credit (annualcreditreport.com)
- Verify any unsolicited iPhone pre-order text against Apple’s official store before paying, then report the sender as fraud — Report fraud (FTC)
- Report the Revolut breach to CISA if your passport or crypto account data was exposed, then keep the confirmation for identity-theft records — CISA: report a cyber incident
SUPPORT KEMETIC MINDS
Enjoying this coverage? Back the work and find every way to connect with us in one place.
Support the Page →Kemetic Minds Analysis
Today’s briefing pulled from 5 news sources and 0 peer-reviewed studies. No peer-reviewed source cleared today’s citation-count bar; treat today’s protection advice as news-grounded, not research-grounded. The pattern worth watching isn’t any single scam headline — it’s whether today’s news matches what the research already predicts about who gets targeted and what actually reduces risk, or whether it’s a genuinely new variant the literature hasn’t caught up to yet.
References
- CryptoSlate. (2026, September 12). Revolut tricked into handing hackers the passports and Bitcoin histories of wealthy customers – CryptoSlate. news.google.com
- The Cryptonomist. (2026, September 12). Revolut Data Leak Exposes Sensitive Bitcoin and Identity Info – The Cryptonomist. news.google.com
- Bing News. (2026, September 12). Beware! Scammers are targeting users eager to buy latest iPhones. newsbytesapp.com
- securityaffairs.com. (2026, September 13). Conti Hacker Who Built Malware and Attacked Victims Gets Four-Year Sentence – securityaffairs.com. news.google.com
- tech-insider.org. (2026, September 12). Conti Ransomware Hacker Sentenced to 4 Years [2026] – tech-insider.org. news.google.com
Investigative Methodology: This briefing is generated on a fixed daily schedule (6:00 AM, America/Chicago) from live news wires and the CrossRef scholarly database. Every news claim is grounded in fetched source text with an APA7 in-text citation. Every peer-reviewed source is a real, DOI-verifiable journal article — filtered to results with a named author list, a named journal, and at least 3 citations to screen out predatory or uncited entries — never a fabricated or paraphrased-from-memory study. Every video embed is verified to be a real, existing video via YouTube’s oEmbed endpoint before publication. The featured image is a real photograph sourced from Pexels, not an AI-generated image. No Wikipedia sources are used.
Stay Connected

