An expiring reward points text says thousands of points you earned are disappearing tonight. One tap will supposedly preserve the balance or exchange it for a gift that feels too valuable to waste. The deadline makes checking the message feel slower than clicking it.

The FTC reported in April 2026 that scammers were sending messages about expiring loyalty points. The link did not lead to a normal rewards account and could be used to steal personal information or deliver harmful software.
A copied redemption page may ask for an email address and password, followed by card details for a small reactivation or shipping fee. The inexpensive charge lowers resistance while handing over the most valuable payment fields.
The brand can change from an airline to a hotel, pharmacy, supermarket, or retailer. The story remains the same: use an immediate loss to make the recipient enter secrets on a site they did not independently choose.

Overview
That tiny decision is exactly what the sender is trying to control.
The message turns a vague balance into an urgent loss
Many people belong to several loyalty programs and do not remember every balance. A specific number of points sounds like account knowledge, even when the same message was sent to thousands of numbers.
Words such as final notice, today, and account closure compress the decision. The recipient is pushed to protect value before checking whether the program even has that phone number.
The copied page collects more than a rewards login
The first screen may request an email and password. A second screen offers a voucher or gift, then asks for a card to cover a small fee. Address, date of birth, and phone fields can also appear.
That sequence gives criminals a reusable credential, a complete card record, and enough identity data for follow-up phishing. The reward itself never needs to exist.
The official app breaks the illusion quickly
A real balance, expiration date, and redemption catalog should appear inside the program's official app or a website reached from a saved bookmark. The unexpected text is not needed to access them.
The FTC advises recipients to avoid the link and check through the company site or app they locate themselves. If the account shows no deadline, the text has answered its own credibility question.
- A surprise text claims a precise points balance expires today.
- The sender name resembles a familiar rewards program.
- A shortened or lookalike link opens a copied redemption page.
- The page asks for an account password to reveal the offer.
- A tiny fee is added to capture complete card details.
- The stolen information is tested on other accounts or used in later scams.
Why Losing Points Feels More Urgent Than Gaining a Reward
People react strongly to losing something they believe they already own. A scammer does not need to promise a fantastic prize when the message can say an existing balance is about to vanish.
Reward programs also train members to expect promotional texts, limited offers, bonus periods, and branded links. The phishing message borrows that familiar rhythm and removes the normal time available for comparison.
A point total can look personalized without being accurate. Criminals may rotate plausible amounts and common program names, then learn which brand matters when recipients click or reply.
The small-fee stage is especially effective. Paying $1.95 to protect a $100 voucher feels rational, but the payment form captures the card number, expiration date, security code, billing ZIP code, and sometimes the account password.
The safest habit is to treat loyalty points like a bank balance. Never access them from an unsolicited message. Open the installed app or type the known company address separately.
What the FTC Warning Confirms About These Messages
The FTC said consumers reported texts warning that reward points would expire unless they clicked immediately. The agency identified the messages as a phishing pattern rather than a normal loyalty reminder.
The warned-about destinations could seek Social Security numbers, card information, or other personal data. A link might also attempt to install harmful software on the phone.
The recommended check is independent: visit the company website or app without using the text link, then inspect the real balance and expiration policy.
Phone software updates and spam filtering reduce risk, but neither makes an unexpected redemption page trustworthy. The decision still depends on the destination and request.
The message should also be reported as junk or spam. Reporting helps carriers and platforms identify campaigns that continually change sender numbers and domains.
How the Expiring Reward Points Text Scam Works
Step 1: A familiar brand and exact balance appear
The text names a popular program and displays a believable point total. It may arrive during travel season, after a purchase, or when a real promotion makes the theme feel timely.
Sender-name spoofing and branded preview images can make the thread look official. Neither verifies the actual origin of the message.
Step 2: A same-day deadline blocks careful checking
The points expire at midnight, the account will close, or the voucher can be claimed only now. The warning makes a separate visit to the app feel like wasted time.
A legitimate program normally publishes expiration rules and displays them in the account. It does not need to punish a member for pausing to verify a text.
Step 3: The link hides a lookalike destination
A shortened URL or long subdomain can conceal the true registered domain. The page then copies colors, menus, and reward imagery from the brand being impersonated.
HTTPS only means the connection to that domain is encrypted. It does not prove the domain belongs to the loyalty program.
Step 4: Login credentials unlock the supposed catalog
The visitor is told to sign in before viewing or preserving the reward. The submitted email, membership number, and password go to the criminal rather than the real program.
If that password is reused, attackers can try it against email, retail, travel, streaming, and financial accounts.
Step 5: A small fee captures the complete card
The fake catalog highlights a voucher or premium item, then adds a reactivation, tax, delivery, or verification fee. The amount is intentionally small enough to avoid serious comparison.
The form still requests every field needed for online purchases. The criminals may test the card immediately with small charges before attempting larger transactions.
Step 6: The account and mailbox are attacked
Stolen credentials may be used to redeem real points, change contact details, access stored payment methods, or search email for travel plans and receipts.
A compromised mailbox can also reset the loyalty password and hide alerts, allowing the theft to continue after the victim changes only the rewards account password.
Step 7: The campaign rotates to another program
Blocked domains are cheap to replace. The same page can return with a hotel, airline, pharmacy, supermarket, or credit-card rewards identity.
The recipient may also receive follow-up calls about a failed redemption or refund. That second contact uses the first submission to sound informed.
Company, Address, and Fulfillment Checks
The displayed brand is not the domain owner
A copied logo and sender label do not connect the site to the loyalty company. Inspect the registered domain itself, not just a brand word buried inside a longer address.
Open the real app independently and compare its official contact and redemption paths. Do not use the suspicious page to verify itself.
The website address may exist only for one short campaign
Phishing domains often use privacy services, recent registrations, disposable hosting, or compromised websites. A padlock and polished page do not create an accountable business address.
The program's official terms should identify the company and expiration policy. If the text destination cannot be found there, it is not an authorized redemption path.
Support is another controlled part of the trap
A help number or chat on the copied page returns the victim to the criminals. The agent may request a one-time code or insist on another payment.
Contact support through the installed app, membership card, or a statement. Ask whether the exact message, balance, and domain are legitimate.
The reward and payment trail must reconcile
A real redemption should appear in account history with clear points deducted and a confirmation from the official program. A charge should use a recognizable, disclosed merchant.
A random card descriptor, separate commercial checkout, or payment to preserve free points shows that the promised reward and money recipient are not connected.
How to Check the Message Without Sacrificing Real Points
Take a screenshot, then close the message. Open the program app from the phone's home screen or use a bookmark created before the text arrived.
Check the balance, account inbox, expiration policy, and recent redemptions. If action is genuinely required, the same notice should exist inside the authenticated account.
Compare the complete domain character by character. Watch for added words, swapped letters, unusual endings, and brand names placed before an unrelated registered domain.
Never provide a one-time code to someone who contacted you. That code may approve a login, password reset, card wallet, or transfer rather than preserve points.
If support needs to be contacted, use a number from the official app, physical membership card, or verified company page. Describe the message without opening its link again.
Check saved payment methods and recent activity even if the phishing page displayed an error. A failure message can appear after the submitted record was successfully transmitted.
Change the exposed password anywhere it was reused, beginning with email. Control of the mailbox can let an attacker reset the rewards account again after the first password change.
Warning Signs to Watch For
- A points balance you did not check is said to expire tonight.
- The text threatens account closure if you do nothing.
- The link uses a shortened or lookalike domain.
- The page asks for an email password before showing the reward.
- A small reactivation, tax, or shipping fee requires card details.
- A one-time code is requested after submitting the form.
- The offer is absent from the official app.
- The sender discourages calling the program through a known number.
Real points do not become safer because you rush. If the balance exists, it will still be visible when you open the official account through a path you trust.
What to Do if You Have Fallen Victim to This Scam
- Close the page and preserve the evidence. Save the text, sender, URL, screenshots, form, charge, and confirmation. Do not revisit the link to gather more information.
- Change the loyalty password from the official app. Use a unique password, sign out other sessions, review contact details, remove unknown devices, and check the redemption history.
- Secure the connected email account next. Change its password if reused or exposed, enable multifactor authentication, inspect forwarding rules and recovery details, and sign out unfamiliar sessions.
- Call the card issuer if payment data was entered. Report phishing, replace the card if advised, dispute unauthorized charges, and ask the issuer to watch for small test transactions.
- Protect identity information you submitted. If the form collected a Social Security number, license, or date of birth, consider a credit freeze and follow an IdentityTheft.gov recovery plan.
- Scan the phone or computer for unwanted software. Update the device and run a full Malwarebytes scan if a file, profile, extension, or app was downloaded. Remove unknown installations and permissions.
- Block malicious advertising and repeat pages. AdGuard can block many known scam domains and malicious ads. It does not replace account recovery, but it can reduce repeat exposure.
- Report the phishing campaign. Use the phone's Report Junk feature, forward the text to 7726 when supported, alert the impersonated program, and file a report at ReportFraud.ftc.gov.
- Ignore recovery and refund follow-ups. A new caller may claim the failed redemption qualifies for compensation. Do not pay a fee or provide another code to recover points or charges.
Frequently Asked Questions
Do legitimate reward points ever expire?
Yes, some programs have expiration rules. Verify the date inside the official app or website, not through an unsolicited text link.
Does a specific points balance prove the text is real?
No. The number may be guessed, fabricated, leaked, or copied from compromised data. Confirm it in your authenticated account.
Is the page safe if it uses HTTPS?
No. HTTPS protects the connection to the domain, including a phishing domain. It does not authenticate the business behind the page.
Why does the site charge only $1.95?
A tiny fee lowers hesitation while collecting the complete card record. The card can then be tested or used for larger unauthorized purchases.
What if I clicked but entered nothing?
Close the page, update the device, remove unexpected downloads or profiles, and scan if anything installed. Clicking alone does not always mean compromise.
Can I recover points stolen from my account?
Contact the real program immediately. Recovery depends on its rules and how quickly the unauthorized redemption or account change is reported.
The Bottom Line
The expiring reward points text is built around a believable loss and an artificial deadline. The copied login and tiny fee are not conveniences. They are collection points for credentials and card data.
Open the official app yourself and check the balance there. If the deadline or offer does not appear in the authenticated account, do not give the text another chance to persuade you.
If information was submitted, secure the loyalty account, email, and card together. Report the message and expect follow-up attempts that reuse the same stolen details.