ZeroHour
Story · 3 sources · 5 articlesfirst updated ()

Phishing and smishing waves impersonate T-Mobile Rewards, Revolut, and bpost to harvest credentials, card details, and one-time codes

mediumPhishing & fraudexploited in the wildimportance 58
What's new: New report added: Cyber Security News (2026-09-18T09:47Z) corroborates the Malwarebytes-tracked T-Mobile Rewards smishing campaign and adds two details — texts claim the 18,400-point balance will expire within a day, and the reiterated advice to never share one-time verification codes. No new campaigns, indicators, or contradictions; the T-Mobile, Revolut, and bpost coverage otherwise matches the…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Malwarebytes is tracking overlapping phishing campaigns: a T-Mobile Rewards smishing wave with 1,000+ templates and 81+ rotating .top domains, Revolut texts sent days after a data breach with a fake liveness-check page, and bpost customs-fee emails (€4.95)…

Malwarebytes Labs, corroborated by GBHackers and Cyber Security News, is tracking a large SMS phishing campaign monitored since early May 2026 that falsely claims recipients' T-Mobile Rewards points are expiring, using invented balances such as 18,400 points — reportedly claimed to vanish within a day — and imminent deadlines to create urgency. Researchers identified more than 1,000 semantically similar message templates (sharing at least 0.60 similarity, with the 199 closest variants scoring 0.95+) that vary only in salutation, headline, expiry date, and point balance. Links resolve to at least 81 short-lived rotating .top domains observed over four months (e.g., t-mobile.biktpw[.]top), a rotation tactic that evades domain-based blocking, and lead to fake login, personal-data, or payment pages that harvest credentials, card details, and one-time verification codes, potentially enabling account takeover despite MFA. Activity peaked in two large spikes and has since declined, though messages still circulate; the analysis draws on Malwarebytes Mobile Security Text Protection telemetry and Browser Guard blocks. Generic greetings and mismatched domains are key detection signals, and users are advised to verify notifications in the official T-Mobile app, avoid links in unsolicited texts, never share one-time codes, and report suspicious texts to 7726. A second campaign impersonates Revolut. Revolut disclosed a breach in which criminals obtained sensitive customer data by sending fraudulent information requests from an email address on a legitimate government agency domain, exposing names, dates of birth, addresses, passport and driver's license copies, verification selfies, and account/transaction statements. Within days, affected customers received smishing texts appearing in the same message thread as genuine Revolut messages; the phishing domain was first scanned on September 14 per VirusTotal. The fake page requests camera access, imitates Revolut's live-video liveness check, then prompts for a password, potentially enabling account takeover. Whether the campaign actually uses the breached data remains unconfirmed. The third campaign, an email scheme targeting Belgian customers of the postal service bpost, uses Dutch-language messages claiming a package was undelivered due to unpaid €4.95 customs duties. Links route through the URL shortener qr.paps.jp to fake bpost domains such as bpost.center, which collect name, phone number, IBAN, and full card…

  • T-Mobile Rewards smishing active since early May 2026, claiming invented balances such as 18,400 points expiring imminently (reportedly within a day).
  • More than 1,000 semantically similar SMS templates detected (minimum 0.60 similarity), with the 199 closest variants scoring 0.95+; they differ only in salutation, headline, expiry date, and point balance.
  • At least 81 short-lived rotating .top domains used over four months (e.g., t-mobile.biktpw[.]top) to evade domain-based blocking.
  • T-Mobile phishing pages harvest logins, card details, and one-time verification codes, potentially enabling account takeover despite MFA.
  • T-Mobile campaign activity peaked in two large spikes and has since declined, though messages still circulate; analysis relies on Malwarebytes Mobile Security Text Protection telemetry and Browser Guard blocks.
  • Detection signals for the T-Mobile texts: generic greetings and mismatched domains; report suspicious texts to 7726 and verify via the official app.
  • Revolut breach stemmed from fraudulent information requests sent from an email address on a legitimate government agency domain, exposing names, dates of birth, addresses, passport and driver's license copies, verification selfies, and…
  • Revolut smishing texts arrived days after disclosure, appeared in the same SMS thread as genuine Revolut messages, and the phishing domain was first scanned September 14 per VirusTotal.

Coverage timeline

  1. · 1d ago
    Malwarebytes Labs· 48
    T-Mobile rewards points expiry texts are a phishing scam

    Malwarebytes tracks an SMS phishing campaign, active since May 2026, impersonating T-Mobile rewards expiry with 1,000+ templates and 81 rotating domains to lure victims.

  2. · 1d ago
    Malwarebytes Labs· 58
    Revolut phishing texts appear days after data breach

    Phishing texts impersonating Revolut targeted customers days after the fintech disclosed a social-engineering breach exposing IDs, verification selfies, and statements.

  3. · 8h ago
    GBHackers· 45
    Scammers Tell T-Mobile Users Their Rewards Are Expiring to Trick Them Into Clicking Phishing Links

    Malwarebytes tracked a large T-Mobile smishing campaign using 81+ rotating .top domains and 1,000+ template variants to harvest credentials via fake rewards-expiry lures.

  4. · 7h ago
    Malwarebytes Labs· 38
    Fake parcel delivery messages steal your card and bank details

    Phishing emails impersonating bpost claim a €4.95 customs fee to trick Belgian customers into submitting card and bank details on fake courier sites.

  5. · 5h ago
    Cyber Security News· 45
    Hackers Use Fake T-Mobile Rewards Expiry Texts to Lure Users to Phishing Sites

    Malwarebytes tracks a T-Mobile smishing campaign using 1,000+ fake rewards-expiry text templates and 81+ disposable .top domains to steal credentials and payment data.