threat_intelligence672 wordsRead on Arc Codex

T-Mobile rewards points expiry texts are a phishing scam

Since early May 2026, we’ve been monitoring a large phishing campaign based on T-Mobile rewards points. The messages falsely warn that a customer’s rewards points are about to expire. They aren’t legitimate account notices: They use urgency, invented point balances, and phishing links to push recipients into acting before they can verify the claim. A typical message says that a T-Mobile Rewards account holds 18,400 points, gives an imminent expiry date, and states that unused points will be removed under the program’s terms. These details make the message look as though it was written specifically for the recipient, even though it was sent to many people. “T-Mobile Rewards Points Reminder: Your Points Are About to Expire Dear Customer, We are hereby reminding you that your T-Mobile Rewards account points are about to expire. You currently have 18,400 points, which will expire on June 4, 2026, if unused. Your Points Overview: Current Balance: 18,400 Points Expiry Date: {today or tomorrow} Points will not be recovered after this date. Redeem Points: Visit: https://t-mobile.{rotating domains}.top/pay Use the T-Mobile App: Account > Rewards & Benefits Our points expiry policy aims to ensure the fairness of the program and encourage active participation. Please don’t let these valuable points go to waste. Thank you for choosing T-Mobile. Customer Service Team” This phishing operation does not rely on a single, identical SMS. We found more than 1,000 closely related campaign templates with a semantic similarity score of at least 0.60. The 199 closest matches all scored at least 0.95. This means the variations only change superficial elements, such as the salutation, headline, expiry date, point balance, and whether the message is called a “reminder,” “alert,” or “important update.” The central story remains the same: T-Mobile rewards points are supposedly expiring, and the recipient must follow a link to redeem them as soon as possible. The messages use formal but generic language, such as “Dear T-Mobile Customer,” “Dear Valued Customer,” or “T-Mobile User,” rather than naming the recipient or providing verifiable account information. The campaign began slowly before producing two huge spikes in activity. The green line shows detections of message variants seen previously, while the red line shows messages detected on the first day that particular variant appeared. We’re still seeing messages from the campaign, although activity has fallen considerably since those spikes. The scam relies on a familiar social engineering formula: a valuable-looking reward, a deadline, and a simple action that supposedly protects the customer from losing out. A recipient who has a T-Mobile account may click first and question the message later. The links use rotating domains designed to look as though they belong to T-Mobile. Their purpose is to persuade recipients to follow the link to supposedly redeem their points. Do not enter login credentials, personal information, payment details, or verification codes after following a link in an unsolicited message. How to stay safe The anonymized data used in this analysis was gathered through Text Protection in Malwarebytes Mobile Security, which alerts users to potentially malicious or scam text messages. You can also reduce your risk by following these tips: - Don’t follow links in unsolicited messages. Instead, open the alleged sender’s website or app independently and check for notifications there. - Check the domain in your browser’s address bar to make sure it matches the site you expected to visit. - Use an up-to-date, real-time anti-malware solution with web protection. - Malwarebytes Scam Guard can help you determine whether a message is a scam and advise you on what to do next. The URLs in this campaign are very short-lived. The criminals used at least 81 domains over four months, but the domains follow a recognizable pattern that is blocked in Malwarebytes Browser Guard. IOCs Example domains showing the pattern used by the campaign: t-mobile.biktpw[.]top t-mobile.cugbjl[.]top t-mobile.cymfjd[.]top t-mobile.gdikxv[.]top t-mobile.hdzcnb[.]top t-mobile.koxetp[.]top t-mobile.nxdcfp[.]top t-mobile.pkrbai[.]top t-mobile.qfrhkt[.]top t-mobile.qscizj[.]top t-mobile.tmfncb[.]top t-mobile.vmnqsu[.]top Stop threats before they can do any harm. Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.