Scammers Tell T-Mobile Users Their Rewards Are Expiring to Trick Them Into Clicking Phishing Links
Malwarebytes tracked a large T-Mobile smishing campaign using 81+ rotating .top domains and 1,000+ template variants to harvest credentials via fake rewards-expiry lures.
Malwarebytes has tracked an SMS phishing campaign impersonating T-Mobile since early May 2026, using lures about expiring rewards points (e.g., a claimed 18,400-point balance) to push victims to lookalike domains such as t-mobile.biktpw[.]top. Researchers identified at least 81 short-lived .top domains and more than 1,000 semantically similar message templates, with the 199 closest variants scoring 0.95+ similarity. Links lead to fake login, personal-data, or payment pages aimed at credential harvesting, and attackers may also request one-time verification codes to enable account takeover despite MFA. Users are advised to verify notifications inside the official app and report suspicious texts to 7726.
- 81+ short-lived .top lookalike domains rotate to evade domain-based blocking
- 1,000+ message templates share semantic similarity of at least 0.60; 199 score 0.95+
- Fake pages harvest credentials, card details, and one-time codes for account takeover
- Generic greetings and mismatched domains are key detection signals
- Victims should verify via the official app and report texts to 7726
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | biktpw.top | s used across four months, with examples including t-mobile.biktpw[.]top , t-mobile.cugbjl[.]top , and t-mobile.gdikxv[.]top . The |
| domain | cugbjl.top | s, with examples including t-mobile.biktpw[.]top , t-mobile.cugbjl[.]top , and t-mobile.gdikxv[.]top . The rapidly changing infras |
| domain | cymfjd.top | 1 t-mobile.biktpw[.]top 2 t-mobile.cugbjl[.]top 3 t-mobile.cymfjd[.]top 4 t-mobile.gdikxv[.]top 5 t-mobile.hdzcnb[.]top 6 t-mobil |
| domain | gdikxv.top | -mobile.biktpw[.]top , t-mobile.cugbjl[.]top , and t-mobile.gdikxv[.]top . The rapidly changing infrastructure complicates simple |
| domain | hdzcnb.top | 3 t-mobile.cymfjd[.]top 4 t-mobile.gdikxv[.]top 5 t-mobile.hdzcnb[.]top 6 t-mobile.koxetp[.]top 7 t-mobile.nxdcfp[.]top 8 t-mobil |
| domain | koxetp.top | 4 t-mobile.gdikxv[.]top 5 t-mobile.hdzcnb[.]top 6 t-mobile.koxetp[.]top 7 t-mobile.nxdcfp[.]top 8 t-mobile.pkrbai[.]top Note: IP |
| domain | nxdcfp.top | 5 t-mobile.hdzcnb[.]top 6 t-mobile.koxetp[.]top 7 t-mobile.nxdcfp[.]top 8 t-mobile.pkrbai[.]top Note: IP addresses and domains ar |
| domain | pkrbai.top | 6 t-mobile.koxetp[.]top 7 t-mobile.nxdcfp[.]top 8 t-mobile.pkrbai[.]top Note: IP addresses and domains are intentionally defanged |
| domain | t-mobile.com | ile should not route users to a domain that is unrelated to t-mobile.com . Users should treat any reward-redemption link pointing to |
Full article868 words · extracted from gbhackers.com · click to collapse
A large-scale SMS phishing campaign is impersonating T-Mobile and warning recipients that their “rewards points” are about to expire, using fabricated balances, urgent deadlines, and lookalike redemption links to steal sensitive information.
Security researchers have tracked the operation since early May 2026 and continue to observe new message variants despite a decline from its peak activity.
One commonly observed lure tells recipients that their T-Mobile Rewards account contains 18,400 points that will be removed unless redeemed by an imminent expiry date.
The messages instruct targets to visit URLs resembling t-mobile.[random-string].top/pay, or to use an alleged Rewards & Benefits section in the T-Mobile app.
The notices are fraudulent. Rather than directing subscribers to a legitimate T-Mobile property, the attackers rotate through short-lived domains constructed to visually associate themselves with the carrier.
Malwarebytes identified at least 81 domains used across four months, with examples including t-mobile.biktpw[.]top, t-mobile.cugbjl[.]top, and t-mobile.gdikxv[.]top.
The rapidly changing infrastructure complicates simple domain-based blocking while preserving a recognizable naming pattern for defenders.
The scam messages are designed to feel personalized without using genuine account data.
They include a precise-looking point balance, a date set to the day of delivery or the following day, and formal language suggesting that the expiration is governed by program policy.
Yet the greetings are usually generic: “Dear Customer,” “Dear T-Mobile Customer,” “Dear Valued Customer,” or “T-Mobile User.”
That inconsistency is an important detection signal. Legitimate account notifications generally provide verifiable context through authenticated channels, while phishing messages frequently use generic salutations and push the recipient away from the official application or website.
Researchers found more than 1,000 closely related message templates with a semantic similarity score of at least 0.60.
Malwarebytes Researchers said that, the smishing campaign relies on a familiar but effective social-engineering formula: present a valuable asset, claim it will disappear within hours or days, and offer a single-click path to “save” it.
T-Mobile Phishing Scam
The 199 closest examples scored 0.95 or higher, indicating that operators are producing high-volume variations of a stable template rather than independently crafted campaigns.

The edits are mostly cosmetic: salutation, subject line, claimed balance, expiry date, and wording such as “reminder,” “alert,” or “important update.”
The core call to action remains unchanged redeem allegedly expiring points through a link immediately.
The campaign began with relatively low detection volume before generating two substantial activity spikes.
Malwarebytes telemetry distinguishes between previously observed variants and message templates seen for the first time, showing that the operators continually refreshed lure text while maintaining the same underlying narrative and infrastructure approach.
This pattern illustrates why static keyword filtering alone is insufficient for SMS security. Attackers can swap dates, reward balances, URL hostnames, and message wording at little cost.
Effective detection therefore requires behavioral and semantic analysis, URL reputation checks, lookalike-domain detection, and real-time mobile protections.
The campaign’s use of the .top top-level domain is also a notable indicator. While no TLD is inherently malicious, an unsolicited message claiming to represent T-Mobile should not route users to a domain that is unrelated to t-mobile.com.
Users should treat any reward-redemption link pointing to an unfamiliar or randomly generated domain as hostile until independently verified.
The immediate risk is credential harvesting. A victim who follows the link may encounter a counterfeit T-Mobile login page, a form requesting personal details, or a payment page claiming that a card is required to process the redemption.
Attackers may also request one-time verification codes, which can enable account takeover even where multifactor authentication is enabled.
Recipients should not enter account credentials, payment-card details, personally identifiable information, or SMS verification codes after following links in unsolicited messages.
The safest validation method is to open the official T-Mobile app directly or manually enter the carrier’s known website in a browser, then inspect account notifications from within the authenticated session.
Subscribers who receive a suspicious rewards-expiration notice should avoid replying, clicking, or calling any number provided in the message.
They should report the text through their device’s spam-reporting function and, where supported, forward it to 7726, the standard U.S. short code for reporting spam texts. Reports can also be submitted to the FTC through its fraud-reporting channel.
Users who already submitted credentials should immediately reset their T-Mobile password through official channels, review account and recovery settings, check for unauthorized changes, and contact their financial institution if card details were entered.
The central rule remains simple: legitimate rewards or account alerts can be verified independently inside the official app or at the genuine T-Mobile website never through an unsolicited text-message link.
IOCs
| # | Domains |
|---|---|
| 1 | t-mobile.biktpw[.]top |
| 2 | t-mobile.cugbjl[.]top |
| 3 | t-mobile.cymfjd[.]top |
| 4 | t-mobile.gdikxv[.]top |
| 5 | t-mobile.hdzcnb[.]top |
| 6 | t-mobile.koxetp[.]top |
| 7 | t-mobile.nxdcfp[.]top |
| 8 | t-mobile.pkrbai[.]top |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.
Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/t-mobile-phishing-scam/