T-Mobile rewards points expiry texts are a phishing scam
Since early May 2026, a large-scale phishing campaign has targeted individuals with fraudulent SMS messages claiming their T-Mobile rewards points are about to expire. The messages urge recipients to click on phishing links hosted on rotating domains that mimic legitimate T-Mobile websites. Over 1,000 message templates with minor variations have been used, leveraging social engineering to trick victims into revealing login credentials, personal data, or payment information. The campaign used at least 81 domains over four months and experienced two major spikes in activity before declining.
AI Analysis
Technical Summary
This campaign involves smishing attacks where threat actors send fraudulent text messages impersonating T-Mobile, warning recipients that their rewards points (commonly cited as 18,400 points) will expire soon. The messages contain links to phishing websites hosted on numerous rotating domains designed to look like official T-Mobile sites. The attackers use generic greetings and formal language to appear credible and employ social engineering to steal sensitive information. The campaign generated over 1,000 closely related message templates and operated with at least 81 domains over a four-month period, with two notable spikes in activity.
Potential Impact
Recipients of these phishing SMS messages risk divulging sensitive information such as login credentials, personal details, or payment information to attackers. This can lead to account compromise, financial loss, and identity theft. The campaign's scale and use of numerous domains increase the likelihood of victim exposure.
Mitigation Recommendations
No official patch or fix applies as this is a phishing campaign rather than a software vulnerability. Users should be advised not to click on links in unsolicited messages claiming urgent rewards expiration and to verify communications directly with T-Mobile through official channels. Organizations should raise awareness about this smishing campaign and encourage users to report suspicious messages. Blocking known malicious domains and employing SMS filtering solutions may help reduce exposure.
Indicators of Compromise
- domain: t-mobile.biktpw.top
- domain: t-mobile.cugbjl.top
- domain: t-mobile.cymfjd.top
- domain: t-mobile.gdikxv.top
- domain: t-mobile.hdzcnb.top
- domain: t-mobile.koxetp.top
- domain: t-mobile.nxdcfp.top
- domain: t-mobile.pkrbai.top
- domain: t-mobile.qfrhkt.top
- domain: t-mobile.qscizj.top
- domain: t-mobile.tmfncb.top
- domain: t-mobile.vmnqsu.top
T-Mobile rewards points expiry texts are a phishing scam
Description
Since early May 2026, a large-scale phishing campaign has targeted individuals with fraudulent SMS messages claiming their T-Mobile rewards points are about to expire. The messages urge recipients to click on phishing links hosted on rotating domains that mimic legitimate T-Mobile websites. Over 1,000 message templates with minor variations have been used, leveraging social engineering to trick victims into revealing login credentials, personal data, or payment information. The campaign used at least 81 domains over four months and experienced two major spikes in activity before declining.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This campaign involves smishing attacks where threat actors send fraudulent text messages impersonating T-Mobile, warning recipients that their rewards points (commonly cited as 18,400 points) will expire soon. The messages contain links to phishing websites hosted on numerous rotating domains designed to look like official T-Mobile sites. The attackers use generic greetings and formal language to appear credible and employ social engineering to steal sensitive information. The campaign generated over 1,000 closely related message templates and operated with at least 81 domains over a four-month period, with two notable spikes in activity.
Potential Impact
Recipients of these phishing SMS messages risk divulging sensitive information such as login credentials, personal details, or payment information to attackers. This can lead to account compromise, financial loss, and identity theft. The campaign's scale and use of numerous domains increase the likelihood of victim exposure.
Defensive Guidance
No official patch or fix applies as this is a phishing campaign rather than a software vulnerability. Users should be advised not to click on links in unsolicited messages claiming urgent rewards expiration and to verify communications directly with T-Mobile through official channels. Organizations should raise awareness about this smishing campaign and encourage users to report suspicious messages. Blocking known malicious domains and employing SMS filtering solutions may help reduce exposure.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.malwarebytes.com/blog/threat-intel/2026/09/t-mobile-rewards-points-expiry-texts-are-a-phishing-scam"]
- Pulse Id
- 6aac141e2773119436b98523
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domaint-mobile.biktpw.top | — | |
domaint-mobile.cugbjl.top | — | |
domaint-mobile.cymfjd.top | — | |
domaint-mobile.gdikxv.top | — | |
domaint-mobile.hdzcnb.top | — | |
domaint-mobile.koxetp.top | — | |
domaint-mobile.nxdcfp.top | — | |
domaint-mobile.pkrbai.top | — | |
domaint-mobile.qfrhkt.top | — | |
domaint-mobile.qscizj.top | — | |
domaint-mobile.tmfncb.top | — | |
domaint-mobile.vmnqsu.top | — |
Threat ID: 6aacfa7155bf5e2cf5c39c58
Added to database: 09/18/2026, 08:46:41 UTC
Last enriched: 09/18/2026, 09:01:38 UTC
Last updated: 09/18/2026, 09:10:40 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.