T-Mobile rewards points expiry texts are a phishing scam
At a glance
- Severity
- Low
- Used in attacks
- No flaws named
- Reported by
- 1 outlet
The messages falsely warn that a customer’s rewards points are about to expire. They aren’t legitimate account notices: They use urgency, invented point balances, and phishing links to push recipients into acting before they can verify the claim.
A typical message says that a T-Mobile Rewards account holds 18,400 points, gives an imminent expiry date, and states that unused points will be removed under the program’s terms. These details make the message look as though it was written specifically for the recipient, even though it was sent to many people.
“T-Mobile Rewards Points Reminder: Your Points Are About to Expire
Dear Customer,
We are hereby reminding you that your T-Mobile Rewards account points are about to expire. You currently have 18,400 points, which will expire on June 4, 2026, if unused.
Your Points Overview:
Current Balance: 18,400 Points
Expiry Date: {today or tomorrow}
Points will not be recovered after this date.
Redeem Points:
Visit:
https://t-mobile.{rotating domains}.top/pay
Use the T-Mobile App: Account > Rewards & Benefits
Our points expiry policy aims to ensure the fairness of the program and encourage active participation. Please don’t let these valuable points go to waste.
Thank you for choosing T-Mobile.
Customer Service Team”
This phishing operation does not rely on a single, identical SMS. We found more than 1,000 closely related campaign templates with a semantic similarity score of at least 0.60. The 199 closest matches all scored at least 0.95.
This means the variations only change superficial elements, such as the salutation, headline, expiry date, point balance, and whether the message is called a “reminder,” “alert,” or “important update.” The central story remains the same: T-Mobile rewards points are supposedly expiring, and the recipient must follow a link to redeem them as soon as possible.
The messages use formal but generic language, such as “Dear T-Mobile Customer,” “Dear Valued Customer,” or “T-Mobile User,” rather than naming the recipient or providing verifiable account information.
The campaign began slowly before producing two huge spikes in activity. The green line shows detections of message variants seen previously, while the red line shows messages detected on the first day that particular variant appeared. We’re still seeing messages from the campaign, although activity has fallen considerably since those spikes.
The scam relies on a familiar social engineering formula: a valuable-looking reward, a deadline, and a simple action that supposedly protects the customer from losing out. A recipient who has a T-Mobile account may click first and question the message later.
The links use rotating domains designed to look as though they belong to T-Mobile. Their purpose is to persuade recipients to follow the link to supposedly redeem their points. Do not enter login credentials, personal information, payment details, or verification codes after following a link in an unsolicited message.
How to stay safe
The anonymized data used in this analysis was gathered through Text Protection in Malwarebytes Mobile Security, which alerts users to potentially malicious or scam text messages.
You can also reduce your risk by following these tips:
- Don’t follow links in unsolicited messages. Instead, open the alleged sender’s website or app independently and check for notifications there.
- Check the domain in your browser’s address bar to make sure it matches the site you expected to visit.
- Use an up-to-date, real-time anti-malware solution with web protection.
- Malwarebytes Scam Guard can help you determine whether a message is a scam and advise you on what to do next.
The URLs in this campaign are very short-lived. The criminals used at least 81 domains over four months, but the domains follow a recognizable pattern that is blocked in Malwarebytes Browser Guard.
IOCs
Example domains showing the pattern used by the campaign:
t-mobile.biktpw[.]top
t-mobile.cugbjl[.]top
t-mobile.cymfjd[.]top
t-mobile.gdikxv[.]top
t-mobile.hdzcnb[.]top
t-mobile.koxetp[.]top
t-mobile.nxdcfp[.]top
t-mobile.pkrbai[.]top
t-mobile.qfrhkt[.]top
t-mobile.qscizj[.]top
t-mobile.tmfncb[.]top
t-mobile.vmnqsu[.]top
Stop threats before they can do any harm.
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →
About the author
Was a Microsoft MVP in consumer security for 12 years running. Can speak four languages. Smells of rich mahogany and leather-bound books.
Originally published by Malwarebytes Labs. © Malwarebytes Labs.
Fastnexa security experts
Dealing with this in your own company?
If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-09-17 10:44 UTC
Related stories
- Times Car confirms data breach affecting 6.6 million user accounts
BleepingComputer · 2026-09-28
- Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts
Dark Reading · 2026-09-28
- Dutch police confirm arrest in ShinyHunters hacking investigation
BleepingComputer · 2026-09-28
- ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns
The Record · 2026-09-28
- Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
The Hacker News · 2026-09-28