Scammers are dispatching fraudulent text messages impersonating T-Mobile, claiming loyalty rewards are about to expire to trick users into visiting deceptive reward-redemption sites designed to harvest login credentials and sensitive information. These smishing messages have been in circulation since early May 2026 and continue despite a decline in frequency.
How the Scam Operates
The messages allege a user has a specific number of ‘T-Mobile Rewards points’—for example, around 18,400—that will vanish by that evening or the next day. To avoid losing them, recipients are urged to click a link to redeem the rewards, presented under the guise of a plausible policy on point expiration.
Although the balance and deadline are fabricated, the texts are crafted with subtle variations—altered greetings, dates, and rewards amounts—to make each version appear personalized. Generic salutations like “Dear T-Mobile Customer” are common and serve as early red flags.
Technical Tricks and Domain Churn
Links in those messages redirect to fake web pages using short-lived domains that mimic T-Mobile’s branding. These often end with “.top” and are built with random strings to stay ahead of automated defenses. In the last four months, researchers identified over 80 such disposable domains tied to this campaign.
Analysts counted more than 1,000 closely related message templates overall—including nearly 200 that were highly similar—to help the scheme fly under the radar of matching-based filters.
How to Protect Yourself
If you receive a message claiming your rewards are expiring, do not click any links. Instead, open the official T-Mobile app or navigate directly to the provider’s verified website. Check inside your account for any real notifications.
Exercising caution is crucial when asked for credentials, payment info, or codes via these sites. Even if the logo looks legitimate, a phishing site may still be fake. Viewing the full URL in your browser before entering any information helps.
If you believe you’ve already provided such information, change passwords immediately—especially if reused—review recent account activity, and contact financial institutions if payment or verification details were exposed.
Why This Matters
This kind of threat reiterates the potency of urgency and reward in phishing: people are more likely to act when they believe something valuable is at risk with a tight deadline. Brand impersonation, rotating domains, and variable message templates show how attackers adapt speedily to evade defenses.
Organizations must prioritize user education about smishing, ensure official communications are easily verifiable, and continue tracking and blocking emerging phishing domains. Users who pause to verify before clicking are far less likely to fall victim to costly fraud.
Analytically, this campaign illustrates several critical trends in phishing. First, attackers are moving beyond generic spoofing and employing scale plus personalization through variable templates. Second, the use of domain rotation and deceptive TLDs like “.top” shows the need for more dynamic threat detection and domain-reputation tools. Going forward, what to watch: whether mobile carriers increase direct alerts of impersonation scams; whether regulation tightens on domain registration transparency; and how anti-phishing filters evolve to contend with high-velocity, template-driven attacks.