A large SMS phishing campaign is targeting T-Mobile customers with fake rewards-point expiry alerts, using more than 1,000 message variants and at least 81 malicious domains.
The campaign has been active since early May 2026 and attempts to pressure recipients into clicking phishing links by claiming their T-Mobile Rewards points are about to expire.
The messages use urgent deadlines, fabricated point balances, and official-sounding wording to make the scam appear legitimate.
One common version tells recipients that they have 18,400 reward points that will expire within one or two days. It warns that unused points will be permanently removed and directs users to a link that appears to be related to T-Mobile.
The messages often include phrases such as “Dear T-Mobile Customer,” “Dear Valued Customer,” or “T-Mobile User.”
However, they do not contain a recipient’s verified name or reliable account-specific details. Instead, attackers use generic information that can be sent to thousands of phone numbers at once.
Researchers identified more than 1,000 closely related phishing templates connected to the campaign.
The messages are not identical, but they use the same core social-engineering story T-Mobile reward points are expiring, and the recipient must immediately follow a link to redeem them.
Attackers change small details between versions to avoid detection. These changes include the greeting, headline, expiry date, point balance, and wording of the warning. Some messages call themselves a “reminder,” while others use terms such as “alert” or “important update.”
Despite these changes, the underlying message remains consistent. The criminals create urgency by telling customers they will lose valuable rewards if they do not act quickly.
This tactic may be especially effective against real T-Mobile customers who believe they could have an unused rewards balance.
Campaign activity initially appeared at a lower volume before producing two major spikes in detections. Researchers continue to observe messages linked to the operation, although the volume has decreased following the peaks.
The phishing links use rotating domains that imitate T-Mobile branding. The attackers used at least 81 domains during a four-month period, with many following a similar naming pattern: t-mobile.[random characters].top.
These domains are short-lived, allowing operators to replace blocked sites with new ones quickly. The pages likely attempt to collect T-Mobile login credentials, personal information, payment details, or verification codes, malwarebytes said.
Indicators of Compromise
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort. Explore for your team
