Hackers Use Fake T-Mobile Rewards Expiry Texts to Lure Users to Phishing Sites
Malwarebytes tracks a T-Mobile smishing campaign using 1,000+ fake rewards-expiry text templates and 81+ disposable .top domains to steal credentials and payment data.
Malwarebytes has tracked a widespread T-Mobile smishing campaign since early May 2026 that uses fake rewards-expiry texts claiming balances such as 18,400 points will vanish within a day. Analysts identified more than 1,000 closely related message templates, with attackers rotating greetings, balances, dates, and links to evade detection. Links route through at least 81 short-lived .top domains over four months to pages harvesting logins, payment data, and one-time verification codes. Users are urged to verify claims through official apps and avoid links in unsolicited texts.