General Discussion
Related: Editorials & Other Articles, Issue Forums, Alliance Forums, Region ForumsSMS Phishers Pivot to Points, Taxes, Fake Retailers ( BEWARE of text messages!)
Posted in GD because it's everywhere, and everyone gets these.
https://krebsonsecurity.com/2025/12/sms-phishers-pivot-to-points-taxes-fake-retailers/
Over the past week, thousands of domain names were registered for scam websites that purport to offer T-Mobile customers the opportunity to claim a large number of rewards points. The phishing domains are being promoted by scam messages sent via Apples iMessage service or the functionally equivalent RCS messaging service built into Google phones.
The website scanning service urlscan.io shows thousands of these phishing domains have been deployed in just the past few days alone. The phishing websites will only load if the recipient visits with a mobile device, and they ask for the visitors name, address, phone number and payment card data to claim the points.
skip ...
If you receive a message warning about a problem with an order or shipment, visit the e-commerce or shipping site directly, and avoid clicking on links or attachments particularly missives that warn of some dire consequences unless you act quickly. Phishers and malware purveyors typically seize upon some kind of emergency to create a false alarm that often causes recipients to temporarily let their guard down.
Lots of sample images there.

If you can actually see the bogus URL, great, but most are disguised, AFAICT.
The above site is com-xrw.com, NOT tmobile.com
WORSE, I copied the image to disk to scrape the text of the link, and Apple Preview and Quick Look made the damn link active, so the browser went to that site --- but Firefox reported it as a scam site and blocked it. Sometimes, I hate computers.
The last paragraph is key.
Just don't click on links in messages, and if there's any doubt (as there should be) go to the merchant's or institution's home page that you know is real (because you typed in its URL) and check things there.
Norrrm
(3,647 posts)Use this. Be generous. Be very slow, methodical, and thorough. Use up their time.
PIN is 5311

usonian
(22,861 posts)Inquiring minds want to know.
For no particular reason.
Thanks.
Norrrm
(3,647 posts)Conservatives will believe any lie, especially if it involves Soros.
This guy claims he has gotten rich from Soros.
And the Congressman 'believes' him.
Hassin Bin Sober
(27,340 posts)usonian
(22,861 posts)Right now, with mac, if I right-click or control-click on a link in messages, I can copy the link, and paste it into some text editor for a look-see.
Don't forget that links can have unicode characters that LOOK LIKE the real deal, say doordash.com but some of those characters could be look-alikes.
Anyway, if you have business with them, just go to their site or use their (highly intrusive) app.
Good luck.
róisín_dubh
(12,203 posts)A law firm purporting to represent the PA Highway Authority regarding an unpaid toll on the PA turnpike.
1) I have an EZ Pass
2) I live in the UK so said EZ Pass only gets used when Im visiting my sister and mum
It nearly got me though because I do sometimes take the PA Turnpike while in the US, but again
EZPass
usonian
(22,861 posts)Deliveries, repair charges, renewals, and for me, 99% are for accounts I don't have.
Sometimes they come soooo close.