ZeroHour
Cyber Security Newspublished ()ingested Tushar Subhra Dutta
Part of a story covered by 5 sources: “Phishing and smishing waves impersonate T-Mobile Rewards, Revolut, and bpost to harvest credentials, card details, and one-time codes” — merged summary and timeline →

Hackers Use Fake T-Mobile Rewards Expiry Texts to Lure Users to Phishing Sites

mediumPhishing & fraudimportance 45
AI summary · glm-5.3-flash

Malwarebytes tracks a T-Mobile smishing campaign using 1,000+ fake rewards-expiry text templates and 81+ disposable .top domains to steal credentials and payment data.

Malwarebytes has tracked a widespread T-Mobile smishing campaign since early May 2026 that uses fake rewards-expiry texts claiming balances such as 18,400 points will vanish within a day. Analysts identified more than 1,000 closely related message templates, with attackers rotating greetings, balances, dates, and links to evade detection. Links route through at least 81 short-lived .top domains over four months to pages harvesting logins, payment data, and one-time verification codes. Users are urged to verify claims through official apps and avoid links in unsolicited texts.

  • Campaign active since early May 2026, using urgent fake balances like 18,400 points expiring the same day.
  • Over 1,000 related text templates and 81+ short-lived .top domains complicate blocklisting.
  • Phishing pages harvest logins, card data, and one-time verification codes from T-Mobile customers.
  • Users should verify via official apps, avoid embedded links, and never share one-time codes.

Indicators of compromiseAll →

TypeIndicatorContext
domainbiktpw.toppromise (IoCs):- Type Indicator Description Domain t-mobile.biktpw[.]top Example phishing domain following the campaign’s T-Mobile
domaincugbjl.tope campaign’s T-Mobile impersonation pattern Domain t-mobile.cugbjl[.]top Example phishing domain following the campaign’s T-Mobile
domaincymfjd.tope campaign’s T-Mobile impersonation pattern Domain t-mobile.cymfjd[.]top Example phishing domain following the campaign’s T-Mobile
domaingdikxv.tope campaign’s T-Mobile impersonation pattern Domain t-mobile.gdikxv[.]top Example phishing domain following the campaign’s T-Mobile
domainhdzcnb.tope campaign’s T-Mobile impersonation pattern Domain t-mobile.hdzcnb[.]top Example phishing domain following the campaign’s T-Mobile
domainkoxetp.tope campaign’s T-Mobile impersonation pattern Domain t-mobile.koxetp[.]top Example phishing domain following the campaign’s T-Mobile
domainnxdcfp.tope campaign’s T-Mobile impersonation pattern Domain t-mobile.nxdcfp[.]top Example phishing domain following the campaign’s T-Mobile
domainpkrbai.tope campaign’s T-Mobile impersonation pattern Domain t-mobile.pkrbai[.]top Example phishing domain following the campaign’s T-Mobile
domainqfrhkt.tope campaign’s T-Mobile impersonation pattern Domain t-mobile.qfrhkt[.]top Example phishing domain following the campaign’s T-Mobile
domainqscizj.tope campaign’s T-Mobile impersonation pattern Domain t-mobile.qscizj[.]top Example phishing domain following the campaign’s T-Mobile
domaintmfncb.tope campaign’s T-Mobile impersonation pattern Domain t-mobile.tmfncb[.]top Example phishing domain following the campaign’s T-Mobile
domainvmnqsu.tope campaign’s T-Mobile impersonation pattern Domain t-mobile.vmnqsu[.]top Example phishing domain following the campaign’s T-Mobile
Full article885 words · extracted from cybersecuritynews.com · click to collapse

A widespread text-message phishing campaign is posing as T-Mobile to pressure customers into visiting fraudulent reward-redemption pages.

The messages claim that loyalty points are about to expire, turning an ordinary account reminder into a trap for login details, personal data, payment information, and verification codes. The activity has been tracked since early May 2026 and has continued despite a later drop in volume.

Its reach comes from rapid variation: attackers alter small details in each text, allowing the same core deception to be sent at scale while evading simple message-matching defenses. Malwarebytes analysts identified more than 1,000 closely related templates, including 199 highly similar messages.

Malwarebytes said in a report shared with Cyber Security News (CSN) that the campaign combines false point balances, urgent deadlines, and rotating links to push recipients into acting before they verify the claim.

The scam illustrates why SMS remains useful to criminals. A text can arrive when a person is distracted, and an apparent loss of rewards feels personal.

Similar real-time smishing fraud campaigns have shown how a single tap can lead to pages built to collect passwords, card data, and one-time codes.

Hackers Use Fake T-Mobile Rewards Expiry Texts

A typical lure says the recipient has 18,400 T-Mobile Rewards points that will disappear the same day or the next. It calls the link a way to redeem them and frames the deadline as part of a fair points policy.

The claimed balance and expiry date are invented, but they give the message a tailored appearance. The wording changes from one version to another.

Attackers swap greetings, subject lines, balances, and dates, while keeping the central claim intact: valuable points will be lost unless the recipient follows the link immediately.

Generic salutations such as “Dear T-Mobile Customer” offer an important warning sign because they lack verifiable account detail.

The links lead through short-lived domains made to resemble T-Mobile addresses, commonly using random letter strings and the .top domain. That infrastructure is deliberately disposable.

Malwarebytes observed at least 81 domains over four months, a pattern that complicates blocklisting and gives criminals fresh addresses when older ones are reported.

This style of brand impersonation is not limited to rewards programs. Earlier large-scale iMessage smishing domains likewise used lookalike web addresses and familiar services to make recipients lower their guard.

The constant is psychological pressure: an attractive benefit, a looming deadline, and a simple action presented as the solution.

Verification Limits the Damage

Recipients should not use a link in an unsolicited message, even if the text looks polished or mentions a plausible balance. Instead, they should independently open the provider’s official app or enter its known website address in a browser, then check whether any genuine account notice appears there.

Anyone who reaches a suspicious page should avoid entering credentials, personal details, card information, or a code received by text.

Checking the full browser address before signing in is essential, since a convincing logo does not make a site legitimate. The iMessage smishing safety guidance also stresses that replying to unknown senders can signal that a phone number is active.

For people who have already shared information, quick action matters. Change the affected password immediately, especially if it was reused elsewhere, review account activity, and contact the relevant financial institution if payment details or verification codes were provided.

Account recovery contacts should come from an official site, statement, or app, not the original text. Organizations can help by warning customers about current impersonation attempts and making genuine notifications easy to verify in official channels.

Users should report suspect texts through their mobile platform and provider, while defenders track the rotating domains listed below. The campaign is a reminder that urgency is a tactic, not proof that a message is real.

No legitimate support team should object to a customer refusing an embedded link and checking a claim through a trusted route first. That brief pause prevents costly mistakes.

Indicators of Compromise (IoCs):-

TypeIndicatorDescription
Domaint-mobile.biktpw[.]topExample phishing domain following the campaign’s T-Mobile impersonation pattern
Domaint-mobile.cugbjl[.]topExample phishing domain following the campaign’s T-Mobile impersonation pattern
Domaint-mobile.cymfjd[.]topExample phishing domain following the campaign’s T-Mobile impersonation pattern
Domaint-mobile.gdikxv[.]topExample phishing domain following the campaign’s T-Mobile impersonation pattern
Domaint-mobile.hdzcnb[.]topExample phishing domain following the campaign’s T-Mobile impersonation pattern
Domaint-mobile.koxetp[.]topExample phishing domain following the campaign’s T-Mobile impersonation pattern
Domaint-mobile.nxdcfp[.]topExample phishing domain following the campaign’s T-Mobile impersonation pattern
Domaint-mobile.pkrbai[.]topExample phishing domain following the campaign’s T-Mobile impersonation pattern
Domaint-mobile.qfrhkt[.]topExample phishing domain following the campaign’s T-Mobile impersonation pattern
Domaint-mobile.qscizj[.]topExample phishing domain following the campaign’s T-Mobile impersonation pattern
Domaint-mobile.tmfncb[.]topExample phishing domain following the campaign’s T-Mobile impersonation pattern
Domaint-mobile.vmnqsu[.]topExample phishing domain following the campaign’s T-Mobile impersonation pattern

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/fake-t-mobile-rewards/