Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Smishing Campaign Uses Fake T‑Mobile Rewards Expiry Notices to Harvest Credentials

A coordinated SMS phishing operation has been sending fake T‑Mobile rewards‑expiry alerts to millions of users, aiming to steal credentials. The campaign underscores the need for robust security‑awareness training and evidential logging for audit readiness.

LiveThreat™ Intelligence · 📅 September 17, 2026· 📰 malwarebytes.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
malwarebytes.com

Smishing Campaign Uses Fake T‑Mobile Rewards Expiry Notices to Harvest Credentials

What Happened – Since May 2026, a large‑scale SMS phishing (smishing) campaign has been sending messages that appear to be T‑Mobile Rewards expiry notices. The texts claim a specific points balance and an imminent expiry date, then direct recipients to rotating malicious domains that mimic T‑Mobile URLs. Over 1,000 template variants have been observed, with activity spikes still producing new messages.

Why It Matters for Trust & Control Assurance

  • Highlights the need for a continuous security‑awareness program that can detect and mitigate social‑engineering attempts before credentials are compromised.
  • Demonstrates the importance of logging and monitoring inbound SMS traffic and domain‑reputation data as evidence of control effectiveness.
  • Provides a real‑world test case for the “Security Awareness and Training” control objective, which maps to many frameworks (e.g., NIST CSF 2.0).

Who Is Affected – Telecommunications providers, mobile‑service customers, and any organization that communicates with users via SMS.

Recommended Actions

  • Refresh phishing‑awareness training with specific examples of reward‑expiry smishing and conduct regular simulated SMS phishing drills.
  • Deploy SMS filtering and domain‑reputation services to block known malicious rotating domains.
  • Capture and retain user‑report logs and block‑list updates as audit evidence of the control in action. Source: https://www.malwarebytes.com/blog/threat-intel/2026/09/t-mobile-rewards-points-expiry-texts-are-a-phishing-scam

Technical Notes

  • Attack vector: Phishing via SMS (smishing) with rotating malicious domains.
  • No CVE; the threat relies on social engineering rather than a software flaw.
  • Data at risk: Mobile credentials, personal identifiers, and potentially payment information if users follow the link. Source: https://www.malwarebytes.com/blog/threat-intel/2026/09/t-mobile-rewards-points-expiry-texts-are-a-phishing-scam
📰 Original Source
https://www.malwarebytes.com/blog/threat-intel/2026/09/t-mobile-rewards-points-expiry-texts-are-a-phishing-scam ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →