MALWAREBYTES says a large phishing campaign has been sending fake T-Mobile rewards messages since early May 2026. The texts falsely claim that the recipient has points, often citing a balance of 18,400, which will expire imminently unless redeemed. They use urgency, generic greetings and fabricated account details to encourage recipients to click a link before checking the claim independently.
The campaign is not based on one fixed SMS: researchers identified more than 1,000 closely related templates, with the 199 nearest matches recording a semantic similarity score of at least 0.95. The messages direct victims to rotating domains designed to resemble T-Mobile websites. Malwarebytes said the campaign used at least 81 domains over four months, including addresses following the pattern `t-mobile.[random].top`, and that activity produced two major spikes before falling considerably.
The links are short-lived, but messages are still being observed. Recipients should not enter login credentials, personal information, payment details or verification codes after following an unsolicited link. Instead, they should open T-Mobile’s website or app independently to check their account and verify the domain before providing information.