Your phone lights up: 18,400 T-Mobile rewards points are about to expire, and there is a link to claim them. Nobody asks for money. Somebody wants to give you a gift. That's what makes the rewards points expiring text so easy to tap, and it's also why it deserves a slower look. Of all the text scams I write about here, this one has the friendliest pitch.
What does the text actually say?
The version going around right now pretends to be T-Mobile. It tells you a large pile of rewards points is about to expire, gives you a very short deadline, and links to a page to "redeem" them. The sample that Malwarebytes published shows a balance of 18,400 points that "will expire on June 4, 2026, if unused".
That number is invented. So is the deadline. The researchers at Malwarebytes say they have tracked this campaign since early May 2026, and in September they reported finding more than 1,000 closely related versions of the text. They measured how close the wording was with a similarity score, and the 199 closest versions scored at least 0.95. In plain words: it's one message with the greeting, the date and the balance swapped out. The rest is copy and paste.
Is it only T-Mobile?
No. In January, Malwarebytes described the same kind of text aimed at AT&T customers. That one claimed 11,430 reward points were expiring on January 26, 2026, and hid its destination behind a shortened link.
The page behind the link was a copied AT&T look-alike, and a careful one: it was full of real links out to att.com, so most of what you could click on went somewhere genuine. First it asked for your phone number to "verify" you. Then it showed a two-day expiry warning and a list of gifts. Then came the part that matters, a "Delivery Information" form asking for your name, address, phone number, email and more. The page's code sent all of it to the attackers.
So the prize is not your points. It's you. 😅
Where is the lie in the link?
Here is the trick both campaigns share. The brand name is in the address, just not in the part that counts.
t-mobile.comT-Mobile's own registered domaint-mobile.[random letters][.]topthe owner is the random word + .top; "t-mobile" is only a label in frontatt.comAT&T's own registered domainatt.hgfxp[.]cc/pay/the owner is hgfxp.cc; "att" is only a label in frontWhoever owns a domain can put any word they like in front of it. That's why you read a web address from the right: find the ending (.com, .top, .cc), take the word just before it, and that pair is the real owner. I wrote a whole post on reading a domain right to left, because this one habit takes apart a surprising number of scams. 🤓
The T-Mobile campaign also burns through addresses quickly. Malwarebytes counted at least 81 short-lived domains over four months, mostly on the .top ending, built from random strings of letters. By the time one address gets reported, the next text points somewhere new.
How do you check a points text before you tap?
- Don't tap the link. On a phone, long-press it to see the address without opening it. On a computer, hover over it.
- Read the address from the right. Find the ending and the word just before it. If that pair isn't
t-mobile.comoratt.com, the page doesn't belong to your carrier, whatever the front of the address says. - Go to your carrier yourself. Open the carrier's own app, or type its real address into the browser. Malwarebytes gives the same advice for AT&T: type att.com directly. If your points exist, they will be waiting in your account.
- Ignore the deadline. The expiry date is the pressure, not the information. Real points don't vanish because you took ten minutes to check.
- Never type personal details into a page you reached from a text. Not your phone number to "verify", not a delivery address for a gift.
- Or paste the address into IP Tracker for a second look at the domain before you decide.
If you have had a text pretending to be your bank, the rules are the same ones from "Your account was compromised": is that bank text fake?. The brand changes. The habit doesn't.
What does IP Tracker show for a link like this?
IP Tracker is my free Chrome extension. You paste a domain, a link or an email address into the popup and it runs a set of checks; the free tier gives you 50 checks a day, with no account and no tracking. Only the value you paste is looked up.
First, the honest part. T-Mobile and AT&T are both on the extension's list of roughly 125 widely impersonated brands, but that doesn't help much with this scam. The lookalike check compares the registered domain with the brands' real ones, and in these links the registered domain is a random word like hgfxp.cc. A random word looks like no brand, so you should not expect a lookalike warning here.
What it can still surface:
- No "verified" note. Paste
t-mobile.comoratt.comand you get a note that it's the brand's official domain. A scam link with the brand stuck on the front won't get that note. Its absence is a clue in itself. - Google Safe Browsing (Google's list of reported dangerous sites) and how many security vendors flag the address on VirusTotal. Here's what Google's list catches and what it misses.
- The domain's age, where registration data is available. A domain created last week sending you "loyalty rewards" is a strong hint, not a verdict on its own.
What can't it do?
- It won't raise a lookalike flag on these links. The brand sits in front of a random domain, so there's nothing for the lookalike comparison to match. You still have to read the address yourself.
- Blocklists lag. With at least 81 domains rotating over four months, the newest address in a batch may not be on Google's list or with any security vendor yet.
- It doesn't read your texts. IP Tracker only checks what you paste into it. It can't block the message, and it can't stop the page from asking for your details.
- Smaller rewards programs aren't on the brand list. The ~125 brands are big banks, couriers, payment services, tech companies, government sites, crypto services and streaming platforms. A fake points text from a local shop or a small airline program won't get a lookalike check against that shop's real domain.
This scam works because it flips the usual script. There is no bill and no threat, just a gift with a timer. However, the timer is the whole trick, and the address is the one thing the scammer couldn't make match.
To summarize:
- ✓ The points balance and the deadline are made up.
- ✓ Read the link from the right: the real owner is the ending plus the word before it.
- ✓ Check your points in the carrier's own app or at t-mobile.com / att.com, typed by you.
- ✓ Never give a phone number or delivery address to a page you reached from a text.
- ✓ Paste the address into IP Tracker for a second look, and treat "not flagged" as "not known yet".
Happy (real) point-collecting! 😉
Sources
- Pieter Arntz, T-Mobile rewards points expiry texts are a phishing scam, Malwarebytes, September 17, 2026.
- Pieter Arntz, Watch out for AT&T rewards phishing text that wants your personal details, Malwarebytes, January 27, 2026.