ZeroHour
Organization

T-Mobile

3 mentions in 7 days · 3 in 30 days · 3 total · first seen · last

Timeline

Hackers Use Fake T-Mobile Rewards Expiry Texts to Lure Users to Phishing Sites

Malwarebytes tracks a T-Mobile smishing campaign using 1,000+ fake rewards-expiry text templates and 81+ disposable .top domains to steal credentials and payment data.

Malwarebytes has tracked a widespread T-Mobile smishing campaign since early May 2026 that uses fake rewards-expiry texts claiming balances such as 18,400 points will vanish within a day. Analysts identified more than 1,000 closely related message templates, with attackers rotating greetings, balances, dates, and links to evade detection. Links route through at least 81 short-lived .top domains over four months to pages harvesting logins, payment data, and one-time verification codes. Users are urged to verify claims through official apps and avoid links in unsolicited texts.

Scammers Tell T-Mobile Users Their Rewards Are Expiring to Trick Them Into Clicking Phishing Links

Malwarebytes tracked a large T-Mobile smishing campaign using 81+ rotating .top domains and 1,000+ template variants to harvest credentials via fake rewards-expiry lures.

Malwarebytes has tracked an SMS phishing campaign impersonating T-Mobile since early May 2026, using lures about expiring rewards points (e.g., a claimed 18,400-point balance) to push victims to lookalike domains such as t-mobile.biktpw[.]top. Researchers identified at least 81 short-lived .top domains and more than 1,000 semantically similar message templates, with the 199 closest variants scoring 0.95+ similarity. Links lead to fake login, personal-data, or payment pages aimed at credential harvesting, and attackers may also request one-time verification codes to enable account takeover despite MFA. Users are advised to verify notifications inside the official app and report suspicious texts to 7726.

GBHackersupdated · 6h agofirst · 9h agoPhishing & fraud in the wild 5 sources

T-Mobile rewards points expiry texts are a phishing scam

Malwarebytes tracks an SMS phishing campaign, active since May 2026, impersonating T-Mobile rewards expiry with 1,000+ templates and 81 rotating domains to lure victims.

Malwarebytes Labs has monitored a large smishing campaign since early May 2026 that falsely claims recipients' T-Mobile Rewards points are expiring, using invented balances like 18,400 points and imminent deadlines to create urgency. Researchers identified more than 1,000 semantically similar message templates (199 scoring at least 0.95 similarity) that vary only in salutation, headline, expiry date, and point balance. The links resolve to rotating domains such as t-mobile.biktpw[.]top, with at least 81 short-lived domains observed over four months, pushing victims to fake redemption pages where they may enter credentials or payment details. Activity peaked in two large spikes and has since declined, though messages are still circulating.

Malwarebytes Labsupdated · 6h agofirst · 1d agoPhishing & fraud in the wild 5 sources