Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News Editorials & Other Articles General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

usonian

(22,861 posts)
Thu Dec 4, 2025, 07:11 PM 7 hrs ago

SMS Phishers Pivot to Points, Taxes, Fake Retailers ( BEWARE of text messages!)

Posted in GD because it's everywhere, and everyone gets these.

https://krebsonsecurity.com/2025/12/sms-phishers-pivot-to-points-taxes-fake-retailers/

China-based phishing groups blamed for non-stop scam SMS messages about a supposed wayward package or unpaid toll fee are promoting a new offering, just in time for the holiday shopping season: Phishing kits for mass-creating fake but convincing e-commerce websites that convert customer payment card data into mobile wallets from Apple and Google. Experts say these same phishing groups also are now using SMS lures that promise unclaimed tax refunds and mobile rewards points.

Over the past week, thousands of domain names were registered for scam websites that purport to offer T-Mobile customers the opportunity to claim a large number of rewards points. The phishing domains are being promoted by scam messages sent via Apple’s iMessage service or the functionally equivalent RCS messaging service built into Google phones.

The website scanning service urlscan.io shows thousands of these phishing domains have been deployed in just the past few days alone. The phishing websites will only load if the recipient visits with a mobile device, and they ask for the visitor’s name, address, phone number and payment card data to claim the points.

skip ...

If you receive a message warning about a problem with an order or shipment, visit the e-commerce or shipping site directly, and avoid clicking on links or attachments — particularly missives that warn of some dire consequences unless you act quickly. Phishers and malware purveyors typically seize upon some kind of emergency to create a false alarm that often causes recipients to temporarily let their guard down.


Lots of sample images there.



If you can actually see the bogus URL, great, but most are disguised, AFAICT.
The above site is com-xrw.com, NOT tmobile.com

WORSE, I copied the image to disk to scrape the text of the link, and Apple Preview and Quick Look made the damn link active, so the browser went to that site --- but Firefox reported it as a scam site and blocked it. Sometimes, I hate computers.


The last paragraph is key.

Just don't click on links in messages, and if there's any doubt (as there should be) go to the merchant's or institution's home page that you know is real (because you typed in its URL) and check things there.
7 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
SMS Phishers Pivot to Points, Taxes, Fake Retailers ( BEWARE of text messages!) (Original Post) usonian 7 hrs ago OP
"and payment card data" Norrrm 4 hrs ago #1
Is that Bill Gates or George Soros? usonian 4 hrs ago #2
Conservatives will believe any lie, especially if it involves Soros. Norrrm 3 hrs ago #5
Just got one for door dash that had me thinking... Hassin Bin Sober 4 hrs ago #3
See if you can identify the real link, supposing that it's disguised. usonian 4 hrs ago #4
I got one from... róisín_dubh 2 hrs ago #6
All kinds of EZ passes are common phishing fake messages. usonian 1 hr ago #7

Norrrm

(3,647 posts)
1. "and payment card data"
Thu Dec 4, 2025, 09:35 PM
4 hrs ago

Use this. Be generous. Be very slow, methodical, and thorough. Use up their time.
PIN is 5311



usonian

(22,861 posts)
2. Is that Bill Gates or George Soros?
Thu Dec 4, 2025, 09:45 PM
4 hrs ago

Inquiring minds want to know.
For no particular reason.
Thanks.

Norrrm

(3,647 posts)
5. Conservatives will believe any lie, especially if it involves Soros.
Thu Dec 4, 2025, 10:59 PM
3 hrs ago

Conservatives will believe any lie, especially if it involves Soros.

This guy claims he has gotten rich from Soros.

And the Congressman 'believes' him.


usonian

(22,861 posts)
4. See if you can identify the real link, supposing that it's disguised.
Thu Dec 4, 2025, 10:07 PM
4 hrs ago

Right now, with mac, if I right-click or control-click on a link in messages, I can copy the link, and paste it into some text editor for a look-see.

Don't forget that links can have unicode characters that LOOK LIKE the real deal, say doordash.com but some of those characters could be look-alikes.

Anyway, if you have business with them, just go to their site or use their (highly intrusive) app.

Good luck.

róisín_dubh

(12,203 posts)
6. I got one from...
Fri Dec 5, 2025, 12:08 AM
2 hrs ago

A law firm purporting to represent the PA Highway Authority regarding an unpaid toll on the PA turnpike.
1) I have an EZ Pass
2) I live in the UK so said EZ Pass only gets used when I’m visiting my sister and mum

It nearly got me though because I do sometimes take the PA Turnpike while in the US, but again…EZPass

usonian

(22,861 posts)
7. All kinds of EZ passes are common phishing fake messages.
Fri Dec 5, 2025, 12:38 AM
1 hr ago

Deliveries, repair charges, renewals, and for me, 99% are for accounts I don't have.

Sometimes they come soooo close.

Latest Discussions»General Discussion»SMS Phishers Pivot to Poi...