Phishing and smishing waves impersonate T-Mobile Rewards, Revolut, and bpost to harvest credentials, card details, and one-time codes
Malwarebytes is tracking overlapping phishing campaigns: a T-Mobile Rewards smishing wave with 1,000+ templates and 81+ rotating .top domains, Revolut texts sent days after a data breach with a fake liveness-check page, and bpost customs-fee emails (€4.95)…
Malwarebytes Labs, corroborated by GBHackers and Cyber Security News, is tracking a large SMS phishing campaign monitored since early May 2026 that falsely claims recipients' T-Mobile Rewards points are expiring, using invented balances such as 18,400 points — reportedly claimed to vanish within a day — and imminent deadlines to create urgency. Researchers identified more than 1,000 semantically similar message templates (sharing at least 0.60 similarity, with the 199 closest variants scoring 0.95+) that vary only in salutation, headline, expiry date, and point balance. Links resolve to at least 81 short-lived rotating .top domains observed over four months (e.g., t-mobile.biktpw[.]top), a rotation tactic that evades domain-based blocking, and lead to fake login, personal-data, or payment pages that harvest credentials, card details, and one-time verification codes, potentially enabling account takeover despite MFA. Activity peaked in two large spikes and has since declined, though messages still circulate; the analysis draws on Malwarebytes Mobile Security Text Protection telemetry and Browser Guard blocks. Generic greetings and mismatched domains are key detection signals, and users are advised to verify notifications in the official T-Mobile app, avoid links in unsolicited texts, never share one-time codes, and report suspicious texts to 7726. A second campaign impersonates Revolut. Revolut disclosed a breach in which criminals obtained sensitive customer data by sending fraudulent information requests from an email address on a legitimate government agency domain, exposing names, dates of birth, addresses, passport and driver's license copies, verification selfies, and account/transaction statements. Within days, affected customers received smishing texts appearing in the same message thread as genuine Revolut messages; the phishing domain was first scanned on September 14 per VirusTotal. The fake page requests camera access, imitates Revolut's live-video liveness check, then prompts for a password, potentially enabling account takeover. Whether the campaign actually uses the breached data remains unconfirmed. The third campaign, an email scheme targeting Belgian customers of the postal service bpost, uses Dutch-language messages claiming a package was undelivered due to unpaid €4.95 customs duties. Links route through the URL shortener qr.paps.jp to fake bpost domains such as bpost.center, which collect name, phone number, IBAN, and full card…
- T-Mobile Rewards smishing active since early May 2026, claiming invented balances such as 18,400 points expiring imminently (reportedly within a day).
- More than 1,000 semantically similar SMS templates detected (minimum 0.60 similarity), with the 199 closest variants scoring 0.95+; they differ only in salutation, headline, expiry date, and point balance.
- At least 81 short-lived rotating .top domains used over four months (e.g., t-mobile.biktpw[.]top) to evade domain-based blocking.
- T-Mobile phishing pages harvest logins, card details, and one-time verification codes, potentially enabling account takeover despite MFA.
- T-Mobile campaign activity peaked in two large spikes and has since declined, though messages still circulate; analysis relies on Malwarebytes Mobile Security Text Protection telemetry and Browser Guard blocks.
- Detection signals for the T-Mobile texts: generic greetings and mismatched domains; report suspicious texts to 7726 and verify via the official app.
- Revolut breach stemmed from fraudulent information requests sent from an email address on a legitimate government agency domain, exposing names, dates of birth, addresses, passport and driver's license copies, verification selfies, and…
- Revolut smishing texts arrived days after disclosure, appeared in the same SMS thread as genuine Revolut messages, and the phishing domain was first scanned September 14 per VirusTotal.
Coverage timelineoldest first · each row is one article
- · 1d agoT-Mobile rewards points expiry texts are a phishing scam
Malwarebytes Labs· 48
Malwarebytes tracks an SMS phishing campaign, active since May 2026, impersonating T-Mobile rewards expiry with 1,000+ templates and 81 rotating domains to lure victims.
- · 1d agoRevolut phishing texts appear days after data breach
Malwarebytes Labs· 58
Phishing texts impersonating Revolut targeted customers days after the fintech disclosed a social-engineering breach exposing IDs, verification selfies, and statements.
- · 8h agoScammers Tell T-Mobile Users Their Rewards Are Expiring to Trick Them Into Clicking Phishing Links
GBHackers· 45
Malwarebytes tracked a large T-Mobile smishing campaign using 81+ rotating .top domains and 1,000+ template variants to harvest credentials via fake rewards-expiry lures.
- · 7h agoFake parcel delivery messages steal your card and bank details
Malwarebytes Labs· 38
Phishing emails impersonating bpost claim a €4.95 customs fee to trick Belgian customers into submitting card and bank details on fake courier sites.
- · 5h agoHackers Use Fake T-Mobile Rewards Expiry Texts to Lure Users to Phishing Sites
Cyber Security News· 45
Malwarebytes tracks a T-Mobile smishing campaign using 1,000+ fake rewards-expiry text templates and 81+ disposable .top domains to steal credentials and payment data.