Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News Editorials & Other Articles General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

usonian

(22,858 posts)
Thu Dec 4, 2025, 07:11 PM 3 hrs ago

SMS Phishers Pivot to Points, Taxes, Fake Retailers ( BEWARE of text messages!)

Posted in GD because it's everywhere, and everyone gets these.

https://krebsonsecurity.com/2025/12/sms-phishers-pivot-to-points-taxes-fake-retailers/

China-based phishing groups blamed for non-stop scam SMS messages about a supposed wayward package or unpaid toll fee are promoting a new offering, just in time for the holiday shopping season: Phishing kits for mass-creating fake but convincing e-commerce websites that convert customer payment card data into mobile wallets from Apple and Google. Experts say these same phishing groups also are now using SMS lures that promise unclaimed tax refunds and mobile rewards points.

Over the past week, thousands of domain names were registered for scam websites that purport to offer T-Mobile customers the opportunity to claim a large number of rewards points. The phishing domains are being promoted by scam messages sent via Apple’s iMessage service or the functionally equivalent RCS messaging service built into Google phones.

The website scanning service urlscan.io shows thousands of these phishing domains have been deployed in just the past few days alone. The phishing websites will only load if the recipient visits with a mobile device, and they ask for the visitor’s name, address, phone number and payment card data to claim the points.

skip ...

If you receive a message warning about a problem with an order or shipment, visit the e-commerce or shipping site directly, and avoid clicking on links or attachments — particularly missives that warn of some dire consequences unless you act quickly. Phishers and malware purveyors typically seize upon some kind of emergency to create a false alarm that often causes recipients to temporarily let their guard down.


Lots of sample images there.



If you can actually see the bogus URL, great, but most are disguised, AFAICT.
The above site is com-xrw.com, NOT tmobile.com

WORSE, I copied the image to disk to scrape the text of the link, and Apple Preview and Quick Look made the damn link active, so the browser went to that site --- but Firefox reported it as a scam site and blocked it. Sometimes, I hate computers.


The last paragraph is key.

Just don't click on links in messages, and if there's any doubt (as there should be) go to the merchant's or institution's home page that you know is real (because you typed in its URL) and check things there.
4 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
SMS Phishers Pivot to Points, Taxes, Fake Retailers ( BEWARE of text messages!) (Original Post) usonian 3 hrs ago OP
"and payment card data" Norrrm 1 hr ago #1
Is that Bill Gates or George Soros? usonian 1 hr ago #2
Just got one for door dash that had me thinking... Hassin Bin Sober 54 min ago #3
See if you can identify the real link, supposing that it's disguised. usonian 40 min ago #4

Norrrm

(3,646 posts)
1. "and payment card data"
Thu Dec 4, 2025, 09:35 PM
1 hr ago

Use this. Be generous. Be very slow, methodical, and thorough. Use up their time.
PIN is 5311



usonian

(22,858 posts)
2. Is that Bill Gates or George Soros?
Thu Dec 4, 2025, 09:45 PM
1 hr ago

Inquiring minds want to know.
For no particular reason.
Thanks.

usonian

(22,858 posts)
4. See if you can identify the real link, supposing that it's disguised.
Thu Dec 4, 2025, 10:07 PM
40 min ago

Right now, with mac, if I right-click or control-click on a link in messages, I can copy the link, and paste it into some text editor for a look-see.

Don't forget that links can have unicode characters that LOOK LIKE the real deal, say doordash.com but some of those characters could be look-alikes.

Anyway, if you have business with them, just go to their site or use their (highly intrusive) app.

Good luck.

Latest Discussions»General Discussion»SMS Phishers Pivot to Poi...