Fake T-Mobile Points Expiry Texts Hit Phones

Malwarebytes Blog · Medium sophistication
Last updated September 17, 2026

A large phishing (smishing) campaign is sending messages that claim a T-Mobile customer’s rewards points are about to expire. The texts use urgency, made-up point balances, and lookalike “t-mobile.*.top” links to push people into clicking and entering sensitive information. Malwarebytes observed heavy templating and fast-rotating domains, indicating an organized, ongoing operation.

Key findings

  • Campaign has been active since early May 2026 and is described as a “large phishing campaign based on T-Mobile rewards points.”
  • Messages create urgency with imminent expiry dates and invented balances (example: 18,400 points) to drive clicks.
  • Attackers use rotating, lookalike domains (at least 81 over four months) following a recognizable pattern such as “t-mobile.<random>.top”.
  • There are extensive message variations: “more than 1,000 closely related campaign templates,” changing superficial fields but keeping the same central story and link-click prompt.
  • The campaign warns recipients not to enter “login credentials, personal information, payment details, or verification codes” after following unsolicited links.

Who’s being targeted

  • Commonly targeted roles: All staff (mobile device users), Customer Support/Call Center, Finance/Payroll, IT/Helpdesk.
  • Affected industries: Telecommunications, Consumers/General public (cross-industry employees using personal phones).
  • Attack channels: smishing.
  • Impersonated: T-Mobile Rewards / T-Mobile Customer Service Team.

Awareness takeaways

  • Treat “points expiring” or “limited-time” texts as suspicious, don’t click links from unsolicited messages; open the official app/website yourself.
  • Verify the real website before entering any data; attackers use lookalike domains that can appear convincing at a glance.
  • Never enter passwords, payment details, or one-time verification codes after clicking a link in an unexpected text.

Red flags to watch for

  • Lookalike domain using a non-T-Mobile TLD and random subdomain (e.g., t-mobile.<random>.top)
  • Urgency with an imminent expiry date like “today or tomorrow”
  • Generic greeting and lack of verifiable account details (no name/account identifiers)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

If you get a text saying, “T‑Mobile Rewards Points Reminder: Your Points Are About to Expire”, pause. There’s a big smishing campaign faking T‑Mobile rewards, claiming you’ve got things like 18,400 points expiring today, and pushing you to tap a link like t-mobile.s8k9.top/pay. The trick: more than a thousand text templates, all the same story, points expiring, generic greeting, and that lookalike t-mobile..top link, then a fake page asking for your login, payment info, or verification codes. Here’s the move: if a text says your points are expiring, don’t tap the link, open the real T‑Mobile app or website yourself and check your rewards there.

Similar attacks

Revolut Users Hit With SMS Phish After Breach

Revolut Users Hit With SMS Phish After Breach

Days after Revolut disclosed that customer records were shared with an unauthorized party, some customers reported receiving phishing texts that appeared in the same SMS thread as real Revolut messages. The link led to a fake site that asked for camera access to mimic Revolut’s identity “liveness”…

September 17, 2026
Fake Helpdesk Passkey Setup Steals Cloud Access

Fake Helpdesk Passkey Setup Steals Cloud Access

The article describes real intrusions where attackers impersonate a company helpdesk and lure employees into "passkey, MFA, or SSO setup" steps. Victims are sent links via text (often to personal phones), leading to account takeover through adversary-in-the-middle phishing or device-code…

September 16, 2026
AI “Apple Support” Calls Steal iPhone Passcodes

AI “Apple Support” Calls Steal iPhone Passcodes

Researchers say a phishing-as-a-service platform called AnonyMousKIT targets people who recently lost or had an iPhone stolen by pretending to be “Apple Support.” The operation uses email/SMS/WhatsApp and AI-assisted voice calls to convince victims to share their iPhone passcode and follow a…

August 26, 2026
Fake Fortnite Rewards Lure Epic Login Theft

Fake Fortnite Rewards Lure Epic Login Theft

Scammers are setting up fake Fortnite “rewards,” “locker value,” and “competition” websites that funnel players to a fake Epic Games login page. The sites trick people into signing in so attackers can steal Epic usernames and passwords, then take over accounts for resale, fraud, or further scams. A…

July 31, 2026
Fake bpost Customs Fee Scam Steals Bank Details

Fake bpost Customs Fee Scam Steals Bank Details

A real phishing campaign impersonated postal couriers (including Belgium’s bpost) to trick people into paying a small “customs fee” for an undelivered parcel. Victims were sent to a fake courier website that collected personal details, then escalated to stealing full card and banking (IBAN)…

September 18, 2026
Passkey-Themed Phishing Hits Microsoft 365

Passkey-Themed Phishing Hits Microsoft 365

Microsoft warns of an active social engineering campaign where attackers pose as an IT help desk and pressure employees to “update” passkeys/MFA/SSO. Victims are sent to fake Microsoft sign-in pages or tricked into approving access via device-code login, enabling attackers to add their own MFA…

September 14, 2026