Those “your T-Mobile Rewards points are about to expire” texts are a phishing scam — not a real account notice — Malwarebytes threat intel reported Sept. 17. The campaign has been running since early May 2026, waving invented balances (often ~18,400 points), urgent expiry dates, and links that push you to “redeem” before you can check.
Researchers found more than 1,000 closely related SMS templates. The story stays the same; only the greeting, headline, point total, and deadline change. Links rotate through lookalike domains patterned like t-mobile.*.top (at least 81 domains over four months) that harvest logins, payment details, and one-time passcodes. Do not type credentials or OTPs after following an unsolicited text link.
What normals should do: Don’t tap SMS links. Open the official T-Mobile app or type the real site yourself and check Rewards there. Forward suspicious texts to 7726 (SPAM). If you already entered info on a lookalike page, change your password from a trusted device, watch bank/carrier alerts, and treat any “verification code” requests as hostile.
Sources: Malwarebytes


Leave a Reply