Your phone lights up: 18,400 T-Mobile rewards points are about to expire, and there is a link to claim them. Nobody asks for money. Somebody wants to give you a gift. That's what makes the rewards points expiring text so easy to tap, and it's also why it deserves a slower look. Of all the text scams I write about here, this one has the friendliest pitch.

What does the text actually say?

The version going around right now pretends to be T-Mobile. It tells you a large pile of rewards points is about to expire, gives you a very short deadline, and links to a page to "redeem" them. The sample that Malwarebytes published shows a balance of 18,400 points that "will expire on June 4, 2026, if unused".

That number is invented. So is the deadline. The researchers at Malwarebytes say they have tracked this campaign since early May 2026, and in September they reported finding more than 1,000 closely related versions of the text. They measured how close the wording was with a similarity score, and the 199 closest versions scored at least 0.95. In plain words: it's one message with the greeting, the date and the balance swapped out. The rest is copy and paste.

The points balance is not a clue that the text knows you. A scammer can type any number into a template. A precise-looking figure like 18,400 is there to feel personal, not because anyone looked up your account.

Is it only T-Mobile?

No. In January, Malwarebytes described the same kind of text aimed at AT&T customers. That one claimed 11,430 reward points were expiring on January 26, 2026, and hid its destination behind a shortened link.

The page behind the link was a copied AT&T look-alike, and a careful one: it was full of real links out to att.com, so most of what you could click on went somewhere genuine. First it asked for your phone number to "verify" you. Then it showed a two-day expiry warning and a list of gifts. Then came the part that matters, a "Delivery Information" form asking for your name, address, phone number, email and more. The page's code sent all of it to the attackers.

So the prize is not your points. It's you. 😅

Where is the lie in the link?

Here is the trick both campaigns share. The brand name is in the address, just not in the part that counts.

Realt-mobile.comT-Mobile's own registered domain
Faket-mobile.[random letters][.]topthe owner is the random word + .top; "t-mobile" is only a label in front
Realatt.comAT&T's own registered domain
Fakeatt.hgfxp[.]cc/pay/the owner is hgfxp.cc; "att" is only a label in front

Whoever owns a domain can put any word they like in front of it. That's why you read a web address from the right: find the ending (.com, .top, .cc), take the word just before it, and that pair is the real owner. I wrote a whole post on reading a domain right to left, because this one habit takes apart a surprising number of scams. 🤓

The T-Mobile campaign also burns through addresses quickly. Malwarebytes counted at least 81 short-lived domains over four months, mostly on the .top ending, built from random strings of letters. By the time one address gets reported, the next text points somewhere new.

How do you check a points text before you tap?

  1. Don't tap the link. On a phone, long-press it to see the address without opening it. On a computer, hover over it.
  2. Read the address from the right. Find the ending and the word just before it. If that pair isn't t-mobile.com or att.com, the page doesn't belong to your carrier, whatever the front of the address says.
  3. Go to your carrier yourself. Open the carrier's own app, or type its real address into the browser. Malwarebytes gives the same advice for AT&T: type att.com directly. If your points exist, they will be waiting in your account.
  4. Ignore the deadline. The expiry date is the pressure, not the information. Real points don't vanish because you took ten minutes to check.
  5. Never type personal details into a page you reached from a text. Not your phone number to "verify", not a delivery address for a gift.
  6. Or paste the address into IP Tracker for a second look at the domain before you decide.

If you have had a text pretending to be your bank, the rules are the same ones from "Your account was compromised": is that bank text fake?. The brand changes. The habit doesn't.

What does IP Tracker show for a link like this?

IP Tracker is my free Chrome extension. You paste a domain, a link or an email address into the popup and it runs a set of checks; the free tier gives you 50 checks a day, with no account and no tracking. Only the value you paste is looked up.

First, the honest part. T-Mobile and AT&T are both on the extension's list of roughly 125 widely impersonated brands, but that doesn't help much with this scam. The lookalike check compares the registered domain with the brands' real ones, and in these links the registered domain is a random word like hgfxp.cc. A random word looks like no brand, so you should not expect a lookalike warning here.

What it can still surface:

What can't it do?

"Not flagged" is not the same as "safe." A brand-new scam domain can be live for hours or days before any list catches it, and a random-word domain won't look like a lookalike at all. IP Tracker flags and names what it can see. The final check is still the address, read from the right, compared with your carrier's real one.

This scam works because it flips the usual script. There is no bill and no threat, just a gift with a timer. However, the timer is the whole trick, and the address is the one thing the scammer couldn't make match.

To summarize:

Happy (real) point-collecting! 😉

Sources