A large phishing (smishing) campaign is sending messages that claim a T-Mobile customer’s rewards points are about to expire. The texts use urgency, made-up point balances, and lookalike “t-mobile.*.top” links to push people into clicking and entering sensitive information. Malwarebytes observed heavy templating and fast-rotating domains, indicating an organized, ongoing operation.
Key findings
- Campaign has been active since early May 2026 and is described as a “large phishing campaign based on T-Mobile rewards points.”
- Messages create urgency with imminent expiry dates and invented balances (example: 18,400 points) to drive clicks.
- Attackers use rotating, lookalike domains (at least 81 over four months) following a recognizable pattern such as “t-mobile.<random>.top”.
- There are extensive message variations: “more than 1,000 closely related campaign templates,” changing superficial fields but keeping the same central story and link-click prompt.
- The campaign warns recipients not to enter “login credentials, personal information, payment details, or verification codes” after following unsolicited links.
Who’s being targeted
- Commonly targeted roles: All staff (mobile device users), Customer Support/Call Center, Finance/Payroll, IT/Helpdesk.
- Affected industries: Telecommunications, Consumers/General public (cross-industry employees using personal phones).
- Attack channels: smishing.
- Impersonated: T-Mobile Rewards / T-Mobile Customer Service Team.
Awareness takeaways
- Treat “points expiring” or “limited-time” texts as suspicious, don’t click links from unsolicited messages; open the official app/website yourself.
- Verify the real website before entering any data; attackers use lookalike domains that can appear convincing at a glance.
- Never enter passwords, payment details, or one-time verification codes after clicking a link in an unexpected text.
Red flags to watch for
- Lookalike domain using a non-T-Mobile TLD and random subdomain (e.g., t-mobile.<random>.top)
- Urgency with an imminent expiry date like “today or tomorrow”
- Generic greeting and lack of verifiable account details (no name/account identifiers)
Read the video transcript
If you get a text saying, “T‑Mobile Rewards Points Reminder: Your Points Are About to Expire”, pause. There’s a big smishing campaign faking T‑Mobile rewards, claiming you’ve got things like 18,400 points expiring today, and pushing you to tap a link like t-mobile.s8k9.top/pay. The trick: more than a thousand text templates, all the same story, points expiring, generic greeting, and that lookalike t-mobile..top link, then a fake page asking for your login, payment info, or verification codes. Here’s the move: if a text says your points are expiring, don’t tap the link, open the real T‑Mobile app or website yourself and check your rewards there.