T-Mobile Points Scam: New Research Tracks 81 Phishing Domains

Daniel Zimmermann
4 Min Read
A T-Mobile message pours reward tokens into a phishing trap.
A rewards deadline can pressure recipients into following an unverified link.

A T-Mobile text that gives you thousands of points and a deadline can look like an account update. New research published on September 17 identifies a phishing campaign monitored since May: more than 1,000 related message templates and at least 81 domains over four months. The promise changes shape; the pressure to redeem remains. [1]

A balance is not proof of an account

The revealing mismatch is between a precise number and an unverified sender. A balance can be typed into a message as easily as a greeting. Before treating it as money you might lose, ask where you can independently see that same balance.

Researcher graph of T-Mobile phishing detections and newly observed message variants.
Green: detection events; red: newly seen message variants. These are not victim counts. Source: Malwarebytes Labs.

The graph measures detections, not people who lost money. A campaign can produce many message variations without demonstrating the same number of victims. That distinction matters when deciding whether a warning describes an observed lure or a confirmed loss.

Read the address past the brand name

Consider the deliberately nonworking example t-mobile.reward-check.example/pay. Its recognizable opening does not make it part of t-mobile.com: the brand appears in a subdomain controlled by whoever controls reward-check.example. The path /pay adds no authentication.

This is the trust decision behind the trap. The SMS supplies both the claim and the place where you are supposed to verify it. Following that route lets the same sender control both sides of the conversation. Changing the route—opening an app you already use—breaks that dependency.

Real rewards exist; verify them independently

Do not rely on the blanket claim that T-Mobile has no rewards. Its US Visa card has a real program. T-Mobile’s FAQ says those rewards remain valid while the card account is open, although closing it can forfeit unused rewards. Cardholders can check their balance through T-Life or their Capital One account. [2]

The FTC’s advice for expiring-points texts is to find the company’s website or app yourself and check there. T-Mobile and Metro customers in the US can forward suspicious SMS to 7726. [3] [4]

If you already supplied information, use the relevant branch in our spam-text response guide: opening a page, disclosing a password and entering card details call for different responses. An optional Gridinsoft domain reputation check can add context, but cannot authenticate a rewards balance.

The useful check is not whether the message looks professional. It is whether the claimed reward still exists when you leave the sender’s link behind.

References

  1. Pieter Arntz. T-Mobile rewards phishing campaign analysis. Malwarebytes Labs, September 17, 2026. Research report.
  2. T-Mobile. Visa credit card FAQs: rewards and expiration. Accessed September 17, 2026. Official FAQ.
  3. Federal Trade Commission. Expiring reward points text warning. April 2026; accessed September 17, 2026. Consumer alert.
  4. T-Mobile. Online safety resources: reporting suspicious messages. Accessed September 17, 2026. Reporting guidance.
Share This Article
With a strong background in consumer safety and fraud prevention, Daniel specializes in providing actionable tips and advice to users. His focus is on helping individuals understand the risks of interacting with fraudulent sites and services
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?