Scammers Tell T-Mobile Users Their Rewards Are Expiring to Trick Them Into Clicking Phishing Links
Malwarebytes tracked a large T-Mobile smishing campaign using 81+ rotating .top domains and 1,000+ template variants to harvest credentials via fake rewards-expiry lures.
Malwarebytes has tracked an SMS phishing campaign impersonating T-Mobile since early May 2026, using lures about expiring rewards points (e.g., a claimed 18,400-point balance) to push victims to lookalike domains such as t-mobile.biktpw[.]top. Researchers identified at least 81 short-lived .top domains and more than 1,000 semantically similar message templates, with the 199 closest variants scoring 0.95+ similarity. Links lead to fake login, personal-data, or payment pages aimed at credential harvesting, and attackers may also request one-time verification codes to enable account takeover despite MFA. Users are advised to verify notifications inside the official app and report suspicious texts to 7726.