Skip to content
Golden and blue Ancient Egyptian art with pharaoh, Eye of Horus, scarab, and "KEMETIC MIND" text.
Menu
  • Home
  • Breaking News
  • Live Trackers
    • Karmelo Anthony Case
    • Kohen Wiley Case
    • Nolan Wells Case
    • Global Conflict Tracker
    • Cyclospora Outbreak Map
    • Food Recall Tracker
    • Missing People in the United States
    • Bomb Threat Tracker
  • Tools
    • Numerology Calculator
    • Live Settlement Tracker
    • U.S. Voting Dates
    • Project 2025 Tracker
    • Frequently Asked Questions
  • Civil Rights
  • Kemetic Wisdom
  • Numerology
  • World News
  • About Kemetic Minds
    • Contact
  • Legal
    • Privacy Policy
    • Cookie Policy
    • Terms of Service
    • Disclaimer
Menu
Newsroom
4th Circuit Blocks ICE No-Bond Rule, Teeing up Supreme CourtOil Jumps 8% as Houthis Near Control of Bab al-Mandeb StraitAnak Krakatau Ash Reaches 50,000 Feet and Grounds FlightsFirstEnergy: Tens of Thousands of Attacks Blocked Each MonthRaul Morales Indicted on Hate Crime Charges in N.Y. StabbingsShinyHunters Leaks Cell Tower Gate Codes for 5.2M RecordsCyclospora Outbreak Ends Without the Answers Officials WantedUS Blockade Cuts Iran’s Oil Exports by More Than 80%4th Circuit Blocks ICE No-Bond Rule, Teeing up Supreme CourtOil Jumps 8% as Houthis Near Control of Bab al-Mandeb StraitAnak Krakatau Ash Reaches 50,000 Feet and Grounds FlightsFirstEnergy: Tens of Thousands of Attacks Blocked Each MonthRaul Morales Indicted on Hate Crime Charges in N.Y. StabbingsShinyHunters Leaks Cell Tower Gate Codes for 5.2M RecordsCyclospora Outbreak Ends Without the Answers Officials WantedUS Blockade Cuts Iran’s Oil Exports by More Than 80%
Cybersecurity & Scam Daily Briefing

Consumer Rights · Sep 11, 2026ShinyHunters Leaks Cell Tower Gate Codes for 5.2M Records

Posted on September 11, 2026 by Kemetic Mind
Listen to this article19:55
Your browser does not support audio playback.

KEMETIC MINDS
Cybersecurity & Scam Daily Briefing — September 11, 2026


Photo: Gustavo Fring via Pexels (source)

📢 SPREAD THE WORD — Share this report

Facebook Post on X WhatsApp LinkedIn Reddit
  • ShinyHunters published stolen American Tower data, including plaintext physical access codes for cell tower sites (Rojas, 2026).
  • Macquarrie Corporation was hit by Storm ransomware through an outside technology provider, not its own network (Insurance Business Mag, 2026).
  • Delhi Police issued a cyber advisory ahead of the BRICS Summit, warning of phishing, malware and fake information campaigns (Dynamite News, 2026).
  • iPhone 18 Pro pre-orders open September 12, and fraud experts say scammers are already trying to take buyers’ money (Winder, 2026).
  • A Conti ransomware developer was sentenced to four years in US federal prison (Bitdefender, 2026).

1. iPhone 18 Pro Pre-Order Scams

SCAM WATCH: Fake iPhone Pre-Order Payment Phish
kemeticmind.com — Cybersecurity Scam Watch
✉Email • "iPhone Pre-Order Desk" (spoofed)
✉📧 New Email • Email
Your iPhone 18 Pro pre-order is reserved! Confirm your payment method within 2 hours to keep your Sept 12 delivery slot: hxxps://iphone-reserve-now[.]com
RED FLAG: Urgent 2-hour deadline
RED FLAG: Unexpected pre-order claim
RED FLAG: Suspicious payment link
🖱️ Click — I never pre-ordered an iPhone 18 Pro. I'll go straight to the official store app and check my account there.
🔒 Ransomware Activates
Your reservation will be cancelled unless you pay a $1.00 verification fee now. Reply CONFIRM and we'll text you a secure payment link.
RED FLAG: Small fee to bait card details
RED FLAG: Threat of cancellation
RED FLAG: Asks for reply to continue
HOW TO RESPOND
Never click pre-order links in unsolicited emails or texts. Open the official retailer's app or type its web address yourself, check your order history there, and remember: legitimate pre-orders never require a 'verification fee' via a message link.

Watch how a real fake iphone pre-order payment phish unfolds — and the red flags that give it away.

Pre-orders for the Apple iPhone 18 Pro and Pro Max open Saturday, September 12. Fraud experts say scammers are already trying to take buyers’ money before the phones even ship (Winder, 2026).

That timing is the whole trick. When demand is high and stock is unclear, a fake “reserve yours now” offer feels urgent instead of suspicious.

What we know — and what we don’t

The Forbes report does not name a specific tactic, only that fraud attempts are already underway around the launch (Winder, 2026). The safe assumption for any hot product launch is that the pressure to buy fast is exactly what gets exploited.

How to Avoid This Scam

  • Type Apple’s or your carrier’s web address yourself. Don’t click a pre-order link that arrived by text, email or social media message.
  • Treat any request to “pay now to hold your place in line” as a red flag. A real pre-order charges you through the retailer’s own checkout.
  • Expect below-retail “deals” on marketplaces and social posts to be bait. If the price beats Apple by a lot, walk away.
  • Never share your Apple ID password or a one-time verification code with anyone who contacts you first.

phishing email laptop warning
Photo: Markus Winkler via Pexels (source)

2. BRICS Summit Phishing Advisory

SCAM WATCH: Fake Summit IT Phishing Email
kemeticmind.com — Cybersecurity Scam Watch
✉Email • "Summit IT Support" (spoofed)
✉📧 New Email • Email
URGENT: BRICS Summit 2026 staff must re-verify credentials within 2 hours. Click the secure link to avoid account suspension: hxxp://bit[.]ly/xxxx
RED FLAG: Urgency/deadline
RED FLAG: Shortened URL
RED FLAG: Credential request
🖱️ Click — Why would summit IT email from a public Gmail address? I'll check the official advisory portal and call the help desk.
🔒 Ransomware Activates
Verification is mandatory. Reply with your official username, password and OTP, or your access will be blocked before the leaders arrive.
RED FLAG: Password/OTP request
RED FLAG: Threat of blocked access
RED FLAG: Impersonates event security
HOW TO RESPOND
Never click summit-themed links or enter credentials/OTP from an email, especially shortened URLs. Navigate to the official government/IT portal directly and report the message to your security team or Delhi Police IFSO.

Watch how a real fake summit it phishing email unfolds — and the red flags that give it away.

Delhi Police issued a cybersecurity advisory to government officials and contract IT staff ahead of the BRICS Summit 2026 (Dynamite News, 2026).

The warning names four threats: phishing attacks, malware infections, remote-access threats and fake information campaigns (Dynamite News, 2026).

Why a summit attracts attackers

Summits bring together some of the world’s largest economies, which means a heavy flow of information between government departments, security agencies and diplomatic teams (Dynamite News, 2026).

Attackers use that moment to send fake emails, build misleading websites, steal login details and push false information meant to cause confusion (Dynamite News, 2026).

The Intelligence Fusion and Strategic Operations unit of Delhi Police issued guidelines focused on blocking unauthorized access, protecting sensitive files and keeping official networks secure (Dynamite News, 2026).

The same playbook reaches your inbox

You are not at a summit. But big news events are when lookalike login pages and urgent “official notice” emails spike for everyone else too.

How to Avoid This Scam

  • Never log in to a work or government account through a link in an email. Open the site the way you normally do.
  • Check the sender’s full address, not just the display name. Lookalike domains are the standard tool in event-themed phishing.
  • Verify any “official summit update” or press document against an official government site before forwarding it.
  • Report suspicious messages to your IT or security team instead of deleting them quietly — one report can protect your whole office.

family online safety internet security
Photo: Ann H via Pexels (source)

3. ShinyHunters Cell Tower Breach

SCAM WATCH: Fake Breach-Notification Verification Text
kemeticmind.com — Cybersecurity Scam Watch
Text Message • "Security Response Team" (spoofed breach notice)
Security Response Team: your details were found in the recent tower data breach, including your site access ID. Reply YES with your name and employee ID to receive your replacement gate code.
RED FLAG: Fake breach notice
RED FLAG: Uses real leak details
RED FLAG: Asks you to reply
I'm not confirming anything by text. I'll call the company's main line myself and check with my own supervisor.
Codes lock at midnight. Enter the 6-digit code we just texted plus your gate PIN to keep site access. Ignoring this cancels your credentials permanently.
RED FLAG: Artificial deadline
RED FLAG: Wants one-time code
RED FLAG: Threatens lost access
HOW TO RESPOND
Real breach notifications never arrive by text or DM asking you to confirm IDs, gate PINs, or one-time passcodes — if someone references details from a leak, that's the bait, not proof. Hang up or stop replying, then contact the company through the phone number on your badge, contract, or its official website, and never read a verification code to anyone who contacted you first.

Watch how a real fake breach-notification verification text unfolds — and the red flags that give it away.

ShinyHunters says it stole more than 5.2 million records from American Tower Corporation, one of the largest cell tower operators in the United States (Rojas, 2026).

The group claimed responsibility on June 12, 2026, in a “pay or leak” extortion campaign (Rojas, 2026).

Gate codes in plain text

The stolen set included customer and landowner personal information, tower asset records, GPS coordinates, physical access codes and internal corporate documents (Rojas, 2026).

The physical access codes for tower compounds were stored in plain text — not scrambled — which is what makes this breach unusual (Rojas, 2026).

ShinyHunters also claimed the documents touched records tied to T-Mobile, Verizon and DHS (Rojas, 2026).

What was actually published

The group published about 574,000 unique email addresses with names, phone numbers, physical addresses and geographic data (Rojas, 2026).

Breach notification service Have I Been Pwned added 216,601 accounts from the incident on June 26, 2026, covering more than 200,000 unique email addresses belonging to employees, contractors, customers and business leads (Rojas, 2026).

If your name was in that file, the risk is not just embarrassment. It is a caller who already knows your address and your phone number.

How to Avoid This Scam

  • Search your email address on Have I Been Pwned to see if you were in the American Tower dataset (Rojas, 2026).
  • If you get a call that opens with your correct address and phone number, don’t treat it as proof of legitimacy. That data is now public.
  • Landowners, contractors and site managers: ask American Tower whether gate and compound access codes tied to your site have been changed.
  • Watch for invoices or shipping notices that use your real details — breached data is what makes fake paperwork convincing.

4. Storm Ransomware Hits a Company Through Its Tech Vendor

SCAM WATCH: Fake Breach-Notification Phishing (Third-Party Vendor Impersonation)
kemeticmind.com — Cybersecurity Scam Watch
✉Email • "IT Provider – Breach Support" (spoofed)
✉📧 New Email • Email
Hi, this is the IT provider managing the breach notice for your workplace. Your employee passport scan and customer records were found on the leak site. Verify your ID here to have them removed: hxxp://secure-id-check[.]
RED FLAG: Impersonates breach vendor
RED FLAG: Leak-site fear hook
🖱️ Click — If our IT provider really needed this, they'd call me on the number in our contract. I'm not clicking a link from an unexpected email — I'll check with our actual office first.
🔒 Ransomware Activates
Removal requests close in 30 minutes. If you don't confirm now, your ID and customer data stay public permanently. We also need your card details for the ID-monitoring fee.
RED FLAG: Countdown pressure
RED FLAG: Card details demanded
RED FLAG: Threatens public leak
HOW TO RESPOND
Never act on a breach notice via a link in an unsolicited email — type your employer's or the provider's real web address yourself and call the number on your contract to confirm. Legitimate breach responders and ID-monitoring services never charge a card or promise to "un-publish" your data for a fee; report suspected notices to the ACSC and IDCARE.

Watch how a real fake breach-notification phishing (third-party vendor impersonation) unfolds — and the red flags that give it away.

A 20-person engineering company in Port Melbourne was listed on the Storm ransomware group’s leak site on September 1, 2026 (Insurance Business Mag, 2026).

Macquarrie Corporation provides diesel engine and machinery management services across Australia and New Zealand. The attack did not start inside its own network (Insurance Business Mag, 2026).

The door was a supplier

“Macquarrie Corporation is aware of a cyber security incident involving one of its external technology providers, resulting in unauthorised access to certain systems used by the business,” a company spokesperson said (Insurance Business Mag, 2026).

Storm set a September 16 publication deadline — the standard pressure tactic used before stolen data goes public (Insurance Business Mag, 2026).

What leaked as proof

Storm posted an employee passport scan, a death certificate, company correspondence, customer data and credit listings (Insurance Business Mag, 2026). The group does not disclose total volume and routinely publishes samples to establish credibility with victims (Insurance Business Mag, 2026).

Macquarrie said it secured affected systems, brought in outside specialists and restored operations through arrangements independent of the provider (Insurance Business Mag, 2026). It is notifying affected people and working with the Australian Cyber Security Centre and the Office of the Australian Information Commissioner (Insurance Business Mag, 2026).

Storm only emerged in August 2026 and has listed 49 alleged victims since (Insurance Business Mag, 2026). Two weeks of existence, 49 names.

How to Avoid This Scam

  • Ask your IT provider and any outside software vendor what access they hold to your systems, and whether it is still needed.
  • Put a notification deadline in vendor contracts. You cannot respond to a breach you learn about from a leak site.
  • Keep backups that the vendor cannot reach — offline or isolated copies.
  • If a supplier is breached, assume your customer data is exposed even if your own network looks clean, and notify early.

5. Conti Developer Sentenced to Four Years

SCAM WATCH: Fake Invoice Attachment That Drops a Ransomware Loader
kemeticmind.com — Cybersecurity Scam Watch
✉Email • "Accounts Payable" (spoofed)
✉📧 New Email • Email
Hi, attached is invoice #INV-44821 from your vendor. The PDF is password-protected for security — open the .zip, run the file, and click "Enable Content" to view it. Payment is due today.
RED FLAG: Unexpected attachment
RED FLAG: Zip plus Enable Content
RED FLAG: Same-day payment demand
🖱️ Click — We don't have a vendor by that name, and I'm not enabling macros on an invoice. What's the company name and the last four of the account you're billing?
🔒 Ransomware Activates
Our system will reissue the invoice with a 2% late fee and suspend your account if the payment link isn't confirmed within 2 hours. Reply with the login for the billing portal so we can verify the account.
RED FLAG: Countdown threat
RED FLAG: Asks for credentials
RED FLAG: Refuses to verify identity
HOW TO RESPOND
Never open a .zip/.iso attachment or click "Enable Content" for an invoice you weren't expecting — that's exactly how a loader like Conti's gets in. Confirm the invoice through a phone number you already have on file, keep offline backups, and remember a real vendor will never ask for your billing-portal login by email.

Watch how a real fake invoice attachment that drops a ransomware loader unfolds — and the red flags that give it away.

Oleksii Oleksiyovych Lytvynenko, 44, a Ukrainian national, has been sentenced to four years in US federal prison for his role in the Conti ransomware operation (Bitdefender, 2026).

He pleaded guilty in June to conspiracy to commit wire fraud after his extradition from Ireland in October last year (Bitdefender, 2026).

What he admitted to

Prosecutors said Lytvynenko joined the Conti conspiracy around September 2021. He admitted possessing data stolen from eight US victims and four victims overseas, and working on code for a malware “loader” — software built to launch other malicious components during an attack (Bitdefender, 2026).

Conti infected more than 1,000 victims worldwide between 2020 and 2022, hitting networks in 47 US states and 31 foreign countries (Bitdefender, 2026).

The money is the point

The FBI estimated that Conti-linked victims had paid more than $150 million in ransoms by January 2022 (Bitdefender, 2026).

Prosecutors tied the conspiracy to more than $500,000 in cryptocurrency extorted from two victims in Tennessee, plus the publication of data stolen from a third (Bitdefender, 2026). Four other alleged conspirators were indicted in the same federal district in 2023 (Bitdefender, 2026).

Lytvynenko was arrested in County Cork, Ireland, in July 2023. Forensic evidence recovered then showed continued involvement in ransomware activity even after the original Conti operation ended (Bitdefender, 2026).

Sentences like this close one case. They do not close the model — which is why the practical advice below still matters for households.

How to Avoid This Scam

  • Keep operating systems and applications patched. Unpatched software is how most ransomware gets its first foothold (Bitdefender, 2026).
  • Maintain offline or isolated backups so a ransom demand is an inconvenience, not a decision (Bitdefender, 2026).
  • Don’t open unexpected attachments or links — including files that look like invoices, shipping notices or résumés.
  • If your files suddenly won’t open, unplug the device from the network and your backup drive before you do anything else.

What the Research Actually Says

No peer-reviewed studies were retrieved for today’s briefing, so nothing here is presented as a research finding.

What we can say, and whose words they are

Every defensive step in this briefing comes from the reporting itself, not from a study. Where research would normally sit, the sourced guidance stands in.

The Conti sentencing coverage states the consumer-side basics directly: patch systems, keep offline or isolated backups, and avoid unexpected attachments and links (Bitdefender, 2026).

The American Tower coverage documents why a breach matters long after it drops off the news: 216,601 accounts were added to Have I Been Pwned, with names, addresses and phone numbers included (Rojas, 2026).

The Macquarrie case shows a pattern worth remembering on its own evidence — the entry point was an external technology provider, not the company’s own network (Insurance Business Mag, 2026).

What to do with that

When no study tells you what works, the reported facts still point one direction: check your exposure, treat your data as already circulating, and mind the suppliers you trust with access.


Today’s Family Safety Checklist

  • Check your email address on Have I Been Pwned today — 216,601 accounts from the American Tower breach are listed there (Rojas, 2026).
  • Treat a caller or email that knows your name, address and phone number as unverified, not as proof. That data comes from breach files (Rojas, 2026).
  • Ask every outside company with access to your accounts or devices what they hold — Macquarrie was breached through a technology provider, not its own network (Insurance Business Mag, 2026).
  • Patch your devices and keep one backup that is not connected to the internet, so a ransomware demand doesn’t decide your week (Bitdefender, 2026).
  • During big news events — a phone launch, a global summit — slow down before clicking anything that says “official” (Winder, 2026; Dynamite News, 2026).

Figure 1
Who is covering this

Note. Built from the Scam Watch stories cited in this report.

Black Excellence This Week

The hard news is real, and so is this. Wins reported by the Black press in the last 14 days:

  • ‘I made those!’: 11-year-old designer Brooke Sumpter makes history with American Girl collaboration
    thegrio.com · 2026-09-10
  • 5 Things You May Not Know About XCEL Award Honoree Dr. Bernard Harris
    blackenterprise.com · 2026-09-10
  • By Us Beauty: The Best Black-Owned Beauty Launches From August 2026
    essence.com · 2026-09-09
  • HBCUs Are Building New Support Systems for Black Male Students
    capitalbnews.org · 2026-09-08

What You Can Do This Week

Not just bad news — here is where to push.

  • Freeze your credit at all three bureaus to block identity thieves using personal data exposed in the American Tower cell tower breach. — Freeze your credit (annualcreditreport.com)
  • File a complaint about fake iPhone 18 Pro pre-order sites that took your money and vanished. — File a consumer complaint (CFPB)
  • Report a cyber incident to federal authorities if ransomware hit your workplace through an outside technology provider. — CISA: report a cyber incident

SUPPORT KEMETIC MINDS

Enjoying this coverage? Back the work and find every way to connect with us in one place.

Support the Page →

Kemetic Minds Analysis

Today’s briefing pulled from 5 news sources and 0 peer-reviewed studies. No peer-reviewed source cleared today’s citation-count bar; treat today’s protection advice as news-grounded, not research-grounded. The pattern worth watching isn’t any single scam headline — it’s whether today’s news matches what the research already predicts about who gets targeted and what actually reduces risk, or whether it’s a genuinely new variant the literature hasn’t caught up to yet.


References

  1. Bing News. (2026, September 11). Apple iPhone 18 Pro Scam Warning As Pre-Orders Go Live September 12. forbes.com
  2. Bing News. (2026, September 11). BRICS Summit 2026 Cyber Alert: Hackers Target Global Meet, Delhi Builds Digital Shield. dynamitenews.com
  3. Bing News. (2026, September 11). ShinyHunters publishes physical access codes for US cell towers in American Tower breach. gcn.com
  4. Bing News. (2026, September 10). Ransomware attack reaches Victorian business through external technology provider. insurancebusinessmag.com
  5. Bing News. (2026, September 11). Conti ransomware developer sentenced to four years in US prison. bitdefender.com

Investigative Methodology: This briefing is generated on a fixed daily schedule (6:00 AM, America/Chicago) from live news wires and the CrossRef scholarly database. Every news claim is grounded in fetched source text with an APA7 in-text citation. Every peer-reviewed source is a real, DOI-verifiable journal article — filtered to results with a named author list, a named journal, and at least 3 citations to screen out predatory or uncited entries — never a fabricated or paraphrased-from-memory study. Every video embed is verified to be a real, existing video via YouTube’s oEmbed endpoint before publication. The featured image is a real photograph sourced from Pexels, not an AI-generated image. No Wikipedia sources are used.

Stay Connected

Join @kemeticMinds on Telegram →

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

📩 Subscribe for New Posts

Get notified whenever Kemetic Minds publishes a new story.

📡 Subscribe via RSS

Get every new Kemetic Minds post delivered straight to your favorite RSS reader (Feedly, Inoreader, Apple News, etc.).

Subscribe to RSS Feed →
Live Alerts
Fetching verified headlines...
Real-time news • Updates every minute

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • September 11, 2026 by Kemetic Mind 4th Circuit Blocks ICE No-Bond Rule, Teeing up Supreme Court
  • September 11, 2026 by Kemetic Mind Oil Jumps 8% as Houthis Near Control of Bab al-Mandeb Strait
  • September 11, 2026 by Kemetic Mind Anak Krakatau Ash Reaches 50,000 Feet and Grounds Flights
  • September 11, 2026 by Kemetic Mind FirstEnergy: Tens of Thousands of Attacks Blocked Each Month
  • September 11, 2026 by Kemetic Mind Raul Morales Indicted on Hate Crime Charges in N.Y. Stabbings

Browse by Topic

Pages

  • About Kemetic Minds
  • Bomb Threat Tracker: Live U.S. Map
  • Contact
  • Cookie Policy
  • Cyclospora Outbreak Map: U.S. State-by-State Tracker (Live)
  • Cyclospora Tracker Subscribers (do not delete)
  • Disclaimer
  • Frequently Asked Questions
  • Home
  • Live Settlement Tracker: Open Class Action Claims
  • LIVE UPDATES: Justice for Kohen Wiley — Tracking the Senatobia Police Killing
  • LIVE UPDATES: Middle East Escalation & Global War Tensions
  • LIVE UPDATES: The Karmelo Anthony Case — Austin Metcalf Murder Trial & Appeal
  • LIVE UPDATES: The Nolan Wells Case — Horn Island, Mississippi
  • LIVE: Food Recall & Foodborne Illness Tracker — Search by State
  • Ma'at Feedback Log (Internal)
  • Missing People in the United States
  • Moved: About Kemetic Minds
  • Privacy Policy
  • Project 2025 Tracker: Timeline & Impact on the Black Community
  • Pythagorean Numerology Calculator — Words, Names, Dates & Historical Connections
  • Terms of Service
  • U.S. Voting Dates

Kemetic Mind Telegram

Click Here
© 2026 Kemetic Minds | Powered by Minimalist Blog WordPress Theme
Ask Ma’at
Ma’at is thinking…

Powered by
Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
None
Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
None
Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
None
Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
None
Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
None
Powered by