{"id":286,"date":"2026-09-20T16:18:32","date_gmt":"2026-09-20T16:18:32","guid":{"rendered":"https:\/\/bugleblast.com\/?p=286"},"modified":"2026-09-20T16:18:32","modified_gmt":"2026-09-20T16:18:32","slug":"fake-t-mobile-rewards-expiring-texts-are-a-scam","status":"publish","type":"post","link":"https:\/\/bugleblast.com\/?p=286","title":{"rendered":"FAKE T-MOBILE \u201cREWARDS EXPIRING\u201d TEXTS ARE A SCAM! | ~18,400 points, urgent deadline, 1,000+ templates \u2014 don\u2019t tap the SMS link"},"content":{"rendered":"<p>Those \u201cyour T-Mobile Rewards points are about to expire\u201d texts are a phishing scam \u2014 not a real account notice \u2014 Malwarebytes threat intel reported Sept. 17. The campaign has been running since early May 2026, waving invented balances (often ~18,400 points), urgent expiry dates, and links that push you to \u201credeem\u201d before you can check.<\/p>\n<p>Researchers found more than 1,000 closely related SMS templates. The story stays the same; only the greeting, headline, point total, and deadline change. Links rotate through lookalike domains patterned like <code>t-mobile.*.top<\/code> (at least 81 domains over four months) that harvest logins, payment details, and one-time passcodes. Do not type credentials or OTPs after following an unsolicited text link.<\/p>\n<p><strong>What normals should do:<\/strong> Don\u2019t tap SMS links. Open the official T-Mobile app or type the real site yourself and check Rewards there. Forward suspicious texts to <strong>7726<\/strong> (SPAM). If you already entered info on a lookalike page, change your password from a trusted device, watch bank\/carrier alerts, and treat any \u201cverification code\u201d requests as hostile.<\/p>\n<p><strong>Sources:<\/strong> <a href=\"https:\/\/www.malwarebytes.com\/blog\/threat-intel\/2026\/09\/t-mobile-rewards-points-expiry-texts-are-a-phishing-scam\">Malwarebytes<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>~18,400 points, urgent deadline, 1,000+ templates \u2014 don\u2019t tap the SMS link<\/p>\n","protected":false},"author":1,"featured_media":285,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[1],"tags":[],"class_list":["post-286","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"https:\/\/bugleblast.com\/wp-content\/uploads\/2026\/09\/bb-tmobile-phishing-0920.jpg","_links":{"self":[{"href":"https:\/\/bugleblast.com\/index.php?rest_route=\/wp\/v2\/posts\/286","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bugleblast.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bugleblast.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bugleblast.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bugleblast.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=286"}],"version-history":[{"count":0,"href":"https:\/\/bugleblast.com\/index.php?rest_route=\/wp\/v2\/posts\/286\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bugleblast.com\/index.php?rest_route=\/wp\/v2\/media\/285"}],"wp:attachment":[{"href":"https:\/\/bugleblast.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=286"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bugleblast.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=286"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bugleblast.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=286"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}