T-Mobile Rewards Points Expiry Texts Lead Widespread Phishing Campaign
A large-scale phishing campaign is impersonating T-Mobile, sending SMS messages claiming rewards points are about to expire to trick users into clicking malicious links.

Since early May 2026, security researchers have been tracking a significant phishing operation that impersonates T-Mobile by sending SMS messages warning recipients that their rewards points are about to expire. These messages are not legitimate communications from the mobile carrier; instead, they leverage a sense of urgency and fabricated point balances to coerce users into clicking malicious links. The goal is to steal credentials or personal information by directing victims to phishing websites.
A typical message in this campaign informs the recipient that their T-Mobile Rewards account holds a substantial number of points, such as 18,400, which are set to expire imminently. The message often includes a fabricated expiry date and urges the user to redeem their points before they are lost, citing program terms. This personalization, even if false, aims to make the message appear specific to the recipient, increasing the likelihood of a click.
The campaign is notable for its sophisticated evasion tactics, employing over 1,000 distinct message templates. These templates share a high degree of semantic similarity, with variations only in superficial elements like greetings, headlines, expiry dates, and point balances. This strategy allows the attackers to bypass spam filters and detection mechanisms more effectively, while maintaining a consistent core message: T-Mobile rewards points are expiring, and immediate action via a provided link is required.
The messages often use generic salutations such as "Dear T-Mobile Customer" or "Dear Valued Customer," avoiding personalized details that could be easily verified. The campaign experienced two significant spikes in activity, indicating coordinated pushes of these phishing messages, although overall activity has since decreased. The core social engineering tactic relies on presenting a seemingly valuable reward coupled with a strict deadline, prompting users to act impulsively without verifying the legitimacy of the message.
Threat actors are using rotating domains designed to mimic legitimate T-Mobile URLs. The purpose of these links is to trick users into believing they are visiting an official T-Mobile site to redeem their points. Security experts strongly advise against entering login credentials, personal information, or payment details on any site accessed through unsolicited messages. Instead, users should independently navigate to the official website or app of the service provider to check for any relevant notifications.
Malwarebytes' Text Protection feature has been instrumental in detecting these malicious messages, alerting users to potential scams. To further mitigate risks, users are advised to avoid clicking links in unsolicited messages, to always verify the domain in their browser's address bar, and to use up-to-date anti-malware solutions with web protection. The domains used in this campaign are short-lived, with attackers frequently registering new ones, but they often follow recognizable patterns that security software can block.
This campaign highlights the persistent threat of SMS-based phishing, or 'smishing,' which continues to evolve with advanced evasion techniques. By impersonating trusted brands like T-Mobile and leveraging common user incentives like rewards points, attackers exploit the trust users place in their mobile carriers to compromise accounts and steal sensitive data.