Skip to content
Unlisted Report logoUnlisted ReportSubscribe
Phishing

T-Mobile rewards points texts are a phishing scam

Malwarebytes found 1,000+ variations of texts warning T-Mobile reward points are about to expire, all leading to phishing sites.

By · Published · Updated · 9 min read

T-Mobile rewards points texts are a phishing scam

Texts warning that your T-Mobile Rewards points are about to expire are a phishing scam, Malwarebytes warns.

What the texts look like

A typical message says your account holds a specific number of points — such as 18,400 — that will expire today or tomorrow. It links to a site like `t-mobile.[random].top/pay`. Malwarebytes has tracked the campaign since May 2026 and found more than 1,000 closely related templates, changing only small details like greetings, dates and point balances, including 199 highly similar messages identified with a semantic similarity score of at least 0.60, according to Cybersecurity News.

A sample message captured by Malwarebytes reads:

> "T-Mobile Rewards Points Reminder: Your Points Are About to Expire. Dear Customer, We are hereby reminding you that your T-Mobile Rewards account points are about to expire. You currently have 18,400 points, which will expire on June 4, 2026, if unused. ... Points will not be recovered after this date."

Timeline

  • Early May 2026: Malwarebytes begins monitoring the campaign. Around the same time, PhoneArena reported on an individual recipient who received a nearly identical text on May 3, listing the expiration date as the same day it was sent.
  • September 17, 2026: Malwarebytes publishes its full analysis after months of tracking, confirming the campaign remained active despite a later drop in volume.
  • September 18–20, 2026: Additional outlets including Cybersecurity News and MalwareTips report on the findings, warning that the fake redemption pages can also harvest payment card details.

Warning signs

  • Urgency: points "expire" today and "will not be recovered."
  • Odd web address: real T-Mobile links go to t-mobile.com, not a `.top` domain or a lookalike subdomain designed to include the word "t-mobile" before an unrelated root domain.
  • Payment pages: a rewards site should never ask for card details to "redeem" points. Scam pages built to resemble a mobile rewards portal, complete with a fake balance and checkout-style form, are designed to collect login details, personal contact information, card data and one-time verification codes, according to MalwareTips.
  • Rotating domains: researchers observed dozens of short-lived web addresses following the same lookalike pattern, most ending in `.top`.

Why these scams work

Specific numbers and dates make a mass message feel personal. Rewards scams also feel low-risk — you are being offered something, not asked to pay a bill — so people let their guard down. Cybersecurity News noted the scam's reach comes from rapid variation: attackers alter small details in each text, allowing the same core deception to be sent at scale while evading simple message-matching defenses used by carriers and spam filters. As Malwarebytes put it, a text can arrive when a person is distracted, and an apparent loss of rewards "feels personal," making it more likely to prompt an impulsive click.

How a victim who checked it out responded

In one account documented by PhoneArena, a recipient who received the text chose not to tap the link, instead calling a verified phone number for T-Mobile directly and confirming that the rewards points program referenced in the text was not part of any legitimate T-Mobile program. The outlet also noted that an AI assistant it consulted separately flagged the message as a likely smishing (SMS phishing) attempt — illustrating that a simple independent verification step, rather than clicking any link in the text itself, is the safest way to check such claims.

Scale of the operation

Malwarebytes analyst Pieter Arntz, who authored the September 17, 2026 report, said the operation "does not rely on a single, identical SMS," instead cycling through more than 1,000 closely related templates to dodge simple spam filters. Cybersecurity News, which reviewed the findings with Malwarebytes, noted the campaign had been "tracked since early May 2026" and "continued despite a later drop in volume," suggesting the operators adjusted their output rather than shutting the campaign down entirely.

How the scam pages are built

MalwareTips, which separately analyzed the destination pages, found the sites are "built to collect information that is worth far more than any promised reward," presenting a convincing rewards-balance display, redemption options and a checkout-style form before asking for card data and one-time verification codes. The outlet observed "dozens of short-lived web addresses" following the same lookalike pattern, most of them registered under the `.top` top-level domain, a pattern consistent with disposable infrastructure designed to be abandoned once flagged.

Background: SMS phishing and brand impersonation

This campaign is part of a broader and long-running trend of "smishing" attacks that impersonate trusted brands — including banks, delivery companies, toll agencies and mobile carriers — to trick recipients into visiting fraudulent websites. T-Mobile itself maintains dedicated guidance for customers on identifying and reporting SMS scams, including the ability to forward suspicious texts to a short code for analysis and blocking, and offers tools such as Scam ID, Scam Block and Scam Shield within its T-Life app to help filter unwanted or fraudulent messages, according to T-Mobile's own support page.

Mobile carriers have increasingly become a target of brand impersonation precisely because nearly every phone user has some kind of relationship with a carrier, making a "rewards" or "account" themed lure broadly plausible regardless of which actual carrier a given recipient uses.

What to do

  • Do not tap the link. Open the official T-Mobile app to check your rewards.
  • Forward scam texts to 7726 (SPAM) to report them to your carrier.
  • If you entered card details, call your bank and cancel the card.
  • Enable T-Mobile's Scam Shield or Scam ID/Scam Block features, or the equivalent spam-filtering tools offered by your own carrier.
  • Check your account directly through the official T-Mobile app or website rather than trusting any link sent by text, regardless of how official it looks.

What readers should do

  • Treat any unsolicited text claiming a reward, point balance, or account benefit is about to expire as suspicious by default, especially if it pressures you to act immediately.
  • Verify directly with your carrier through its official app or a phone number you already trust — never one provided in the suspicious text itself.
  • If you have already entered any personal or payment information on a suspicious rewards page, contact your bank immediately to monitor or cancel the card, and consider placing a fraud alert with credit bureaus.
  • Report the scam text to your carrier's spam-reporting short code (7726 in the US) and consider reporting it to your country's consumer protection or telecommunications regulator.
  • Remember that even if you are not a T-Mobile customer, similar "rewards expiring" templates are reused across other carriers and brands, so apply the same scrutiny to any text referencing points, rewards or account benefits regardless of the sender name.

Sources

Read next