KEMETIC MINDS
Cybersecurity & Scam Daily Briefing — August 28, 2026
Photo: Gustavo Fring via Pexels (source)
- WhatsApp account hijacking scams are “out of hand” in South Africa — turn on two-step verification now (Mungoni, 2026).
- “MyChart Medicare Kit” phishing emails are hitting patients at 41+ health systems nationwide (Becker’s Hospital Review, 2026).
- Penn Medicine: fake portal email is a scam; reset your password if you clicked and shared info (WGAL News 8, 2026).
- Manchester Airport data breach reportedly affects 8.7 million customers (Tech Insider, 2026).
- ATF declares “major incident” after ransomware gang claims a hack of the federal agency (MSN News, 2026).
- Research: real ransomware attacks force on-the-spot plan changes — rehearse your family plan before a crisis (Ghanbari & Koskinen, 2025, Journal of Information Technology Teaching Cases).
1. WhatsApp Account Hijacking Wave
Watch how a real whatsapp verification code hijack unfolds — and the red flags that give it away.
Cybersecurity educator Michael Buswell posted a warning about a wave of WhatsApp account hijackings in South Africa on 25 August 2026, saying the problem is “getting out of hand” (Mungoni, 2026). His warning was covered by Briefly News.
Scammers use phishing links, fake QR codes, and social engineering — tricking people into giving up their codes instead of hacking in (Mungoni, 2026). Victims click a suspicious link or hand over their six-digit WhatsApp verification code, and the scammer instantly gains full control of the account (Mungoni, 2026).
Once inside, the attacker impersonates the account owner and asks their contacts for money (Mungoni, 2026).
How to Avoid This Scam
- Turn on WhatsApp’s two-step verification right now — it adds an extra layer an attacker would need to bypass (Mungoni, 2026).
- Open WhatsApp Settings, review linked devices, and remove anything that looks unfamiliar (Mungoni, 2026).
- Never share your six-digit verification code, even if the message looks like it comes from WhatsApp (Mungoni, 2026).
- Because a hijacked account directly targets your contacts, be extra suspicious of money requests that arrive via WhatsApp (Mungoni, 2026).
Video: A Tumultuous Life: The First Wife's Father Returns to Get a Signature from Omid. Source: storm28.
2. MyChart “Medicare Kit” Phishing
Watch how a real 'medicare kit' portal phish unfolds — and the red flags that give it away.
Forty-one health systems — from Sentara Health to MetroHealth — are warning patients about a “MyChart Medicare Kit” phishing scam that impersonates the patient portal (Becker’s Hospital Review, 2026).
Patients across the country should treat any unsolicited “Medicare kit” email as part of this wave (Becker’s Hospital Review, 2026). The details of the scam’s email are covered in the Penn Medicine section below.
How to Avoid This Scam
- If an email offers a free “Medicare kit,” don’t click its link — verify with your hospital’s official patient portal first (Becker’s Hospital Review, 2026).
- Check whether your own health system has published an alert, since dozens of systems are issuing warnings right now (Becker’s Hospital Review, 2026).
- Use only the official patient portal website to check your messages, not links inside emails (Becker’s Hospital Review, 2026).
Video: Penn Medicine warns patients of phishing scam targeting its portal. Source: wgaltv.
3. Penn Medicine Portal Phishing
Watch how a real free home health kit phishing unfolds — and the red flags that give it away.
Penn Medicine has alerted patients to a phishing scam aimed at its patient portal, one of about a dozen health systems hit through portals operated by Epic (WGAL News 8, 2026). The email offers a free “Medicare home health kit” for home health monitoring and is addressed generically as “Dear Member” (WGAL News 8, 2026).
Penn Medicine scanned the link in the email, found it insecure, and suspects it would request personal information (WGAL News 8, 2026). Patients who clicked the link and provided details are being told to reset their MyChart and MyLGHealth passwords (WGAL News 8, 2026).
The health system also published its official email addresses and text-message short codes so patients can recognize legitimate messages (WGAL News 8, 2026).
How to Avoid This Scam
- A generic greeting like “Dear Member” instead of your name is a red flag for this specific scam (WGAL News 8, 2026).
- Don’t click links in unsolicited emails or texts unless you’re absolutely certain they’re safe (WGAL News 8, 2026).
- If you clicked and shared personal information, reset your MyChart and MyLGHealth passwords immediately (WGAL News 8, 2026).
- Keep a copy of your health system’s official email addresses and short codes to compare against suspicious messages (WGAL News 8, 2026).

4. Manchester Airport Data Breach
Watch how a real fake breach compensation email unfolds — and the red flags that give it away.
Manchester Airport is reported to have suffered a data breach affecting 8.7 million customers (Tech Insider, 2026). The report gives no further details about when the breach occurred or what data was exposed (Tech Insider, 2026).
No further details were included in the report, so continue to rely on official updates (Tech Insider, 2026).
How to Avoid This Scam
- Expect phishing messages to piggyback on this news — don’t click links in texts or emails claiming to be breach updates (Tech Insider, 2026).
- Get updates only from Manchester Airport’s official website until investigators release more details (Tech Insider, 2026).
- If you receive a suspicious breach-notification email, delete it and don’t enter any personal information (Tech Insider, 2026).

5. ATF Ransomware “Major Incident”
Watch how a real fake ransomware extortion after breach news unfolds — and the red flags that give it away.
The ATF has declared a “major incident” after a ransomware gang claimed responsibility for hacking the federal agency (MSN News, 2026). The ATF is the latest federal government agency in recent years to notify Congress of a major cybersecurity incident (MSN News, 2026).
Ransomware is an attack where criminals lock systems and demand payment to restore them — and this case shows that even federal agencies can be hit.
How to Avoid This Scam
- If you use ATF online services, use a strong, separate password and turn on two-factor authentication if offered (MSN News, 2026).
- Watch for phishing emails impersonating the ATF that ask you to verify your identity in the wake of the hack (MSN News, 2026).
- Don’t wait for a crisis: research on a real ransomware attack found that people end up improvising their response on the spot, so plan your family’s response now (Ghanbari & Koskinen, 2025, Journal of Information Technology Teaching Cases).
What the Research Actually Says
In a 2025 teaching case based on a ransomware attack at a European manufacturer, researchers found that companies often have to adjust their incident response procedures on the spot and improvise as the attack evolves (Ghanbari & Koskinen, 2025, Journal of Information Technology Teaching Cases). In plain terms: no plan survives contact with a crisis untouched.
The same case found that incident response is not just technical — the “social and business dimensions” matter, including how people coordinate and communicate during a response (Ghanbari & Koskinen, 2025, Journal of Information Technology Teaching Cases). For a family, that means agreeing in advance who to call and how to verify each other’s identities before an emergency happens.
Today’s Family Safety Checklist
- Turn on two-step verification on WhatsApp today — the clearest protective step in this briefing (Mungoni, 2026).
- Decide today which phone number is the family “trust line” — research shows smooth responses depend on people and communication, not just tech (Ghanbari & Koskinen, 2025, Journal of Information Technology Teaching Cases).
- Keep your health system’s official email addresses and short codes somewhere you can check before clicking a link (WGAL News 8, 2026).
- Rehearse the “what if” now: name one person you’d call and one rule you’d follow if an account is hijacked tomorrow (Mungoni, 2026; Ghanbari & Koskinen, 2025, Journal of Information Technology Teaching Cases).
SUPPORT KEMETIC MINDS
Enjoying this coverage? Back the work and find every way to connect with us in one place.
Support the Page →Kemetic Minds Analysis
Today’s briefing pulled from 5 news sources and 1 peer-reviewed study. Today’s strongest research signal comes from Journal of Information Technology Teaching Cases (2025), cited 3 times — the kind of study worth weighing more heavily than a single news anecdote. The pattern worth watching isn’t any single scam headline — it’s whether today’s news matches what the research already predicts about who gets targeted and what actually reduces risk, or whether it’s a genuinely new variant the literature hasn’t caught up to yet.
References
- Bing News. (2026, August 28). “Getting Out of Hand”: SA Expert Warns of Rising WhatsApp Hijacking Scam and Shares Tips, SA Reacts. briefly.co.za
- Bing News. (2026, August 27). 41 health systems warn of MyChart ‘Medicare Kit’ scam. beckershospitalreview.com
- Bing News. (2026, August 27). Penn Medicine warns patients of phishing scam targeting its portal. wgal.com
- tech-insider.org. (2026, August 27). Manchester Airport Data Breach: 8.7M Customers Hit – tech-insider.org. news.google.com
- Bing News. (2026, August 27). ATF declares ‘major incident’ as ransomware gang claims hack. msn.com
- Ghanbari, Koskinen (2025). When ransomware hits the fan: Navigating a ransomware attack in the manufacturing industry. Journal of Information Technology Teaching Cases. doi.org/10.1177/20438869251349852
Investigative Methodology: This briefing is generated on a fixed daily schedule (6:00 AM, America/Chicago) from live news wires and the CrossRef scholarly database. Every news claim is grounded in fetched source text with an APA7 in-text citation. Every peer-reviewed source is a real, DOI-verifiable journal article — filtered to results with a named author list, a named journal, and at least 3 citations to screen out predatory or uncited entries — never a fabricated or paraphrased-from-memory study. Every video embed is verified to be a real, existing video via YouTube’s oEmbed endpoint before publication. The featured image is a real photograph sourced from Pexels, not an AI-generated image. No Wikipedia sources are used.
Stay Connected

