Retail Reward Email Scam: Hidden Text Helps Fake Gift Cards Reach Inboxes

An email says your store points expire tonight. A gift card, a tool set, or another tempting reward is waiting behind one button.

The retail reward email scam is easy to dismiss as ordinary spam. Its recent versions have a quieter trick that helps them reach real inboxes.

Barracuda capture of a fake retailer reward email promising a Kobalt tool set and store card

Overview

The visible offer is a prize you did not request

One captured message announces a Lowe’s loyalty reward: a Kobalt tool set and a $100 card. Another claims Walmart points will expire today.

Those are not notices we are attributing to the retailers. The scam uses familiar names and invented account benefits to pull readers toward a link.

The offers change, but the central request remains familiar: stop reading the email and follow its button to claim something supposedly reserved for you.

You do not need a loyalty account for this message to arrive. Bulk senders can make a reward sound personal without knowing your actual balance.

Barracuda documented the campaign, not just a single complaint

Barracuda’s threat researchers reported more than one million detected retail-themed phishing attacks using hidden-text tactics since April 2026.

That number counts detected attempts. It does not mean one million people clicked, lost money, or had a retailer account compromised.

The researchers reviewed message content and supplied examples of the visible lures. That is stronger evidence than an isolated customer asking whether a reward is genuine.

Their report does not establish a single checkout outcome for every recipient. Some landing pages may collect information; others may route elsewhere or disappear.

The unexpected part sits inside the email’s code

The recipient sees the offer. Behind it, the message includes ordinary-looking text concealed from view, which can change how automated filters interpret the email.

This technique is called text salting. It is not a hidden reward condition and it does not make the promised prize real.

  • A recognizable retailer name supplies a quick reason to open the message.
  • An expiring reward or points balance creates a reason to act immediately.
  • Invisible filler text tries to soften the email’s suspicious signals.
  • A claim button moves the reader from the inbox to an unverified destination.
  • The safe check starts inside the retailer’s own app or independently entered website.

The present assessment is clear: these captured messages are phishing lures, not evidence that the real stores are offering the depicted prizes.

Why a Convincing Reward Email Can Still Be Fake

Loyalty programs have trained customers to expect points, coupons, and occasional special offers. Fraudsters borrow that language because it sounds routine.

A number such as “1,590 points” looks specific. Unless you verify it in your own account, it is simply a number the sender chose.

The same goes for a member ID, gold status, or a carefully named product. Specific detail can be invented as easily as a generic promise.

In the Lowe’s-themed example, the message pairs a Kobalt tool set with a store card. The combination makes the offer feel tangible and valuable.

In the Walmart-themed example, the alleged points expire today. That deadline invites a hurried click before the reader checks whether such points exist.

Retailers may run real promotions. The existence of legitimate promotions is exactly why an imitation can seem plausible at first glance.

The useful question is not whether a retailer ever sends offers. It is whether this offer appears in the account you opened independently.

A fake message may display a real logo or product image. Neither proves that the sender controls the retailer’s loyalty system.

Even the displayed sender name can be chosen by the person sending the email. Expand the actual address, but do not stop your check there.

Some attacks use compromised websites or lookalike domains to send messages. Technical mail authentication may therefore look less obviously broken than expected.

That is why “it landed in my inbox” is not a reliable safety test. Filters are valuable, but they do not make every delivered email trustworthy.

How the Retail Reward Email Scam Works

Step 1: The sender builds a reward around a familiar store

The lure borrows a retailer’s identity and a product or points story that fits its customers. It may promise a card, tool set, or limited redemption.

For a recipient who shops there, the subject line feels relevant. For someone who does not, the same message may simply look like a stray promotion.

The captured Lowe’s and Walmart examples show variation inside one broader pattern. Do not memorize one store name as the only warning sign.

A later version can change the brand, amount, product, and deadline while preserving the same request to click before verifying.

Step 2: Invisible filler changes what a filter reads

Barracuda found hidden stretches of harmless-looking copy inside the email. The person reading the rendered message would not ordinarily notice them.

Those extra words can dilute terms associated with a scam or alter the message’s apparent topic for automated analysis.

Some filler uses styling that crops text out of view, reduces its height to zero, or moves it beyond the visible edge.

Other versions insert zero-size characters into words. A person sees a normal phrase, while a simple text scanner sees separated fragments.

The hidden copy is not useful advice for the customer. Its role is to help the deceptive message survive checks before delivery.

A recipient generally cannot spot that by glancing at the email. The practical defense is to verify the offer, not to inspect HTML.

Step 3: The visible email asks for one small action

Once the message arrives, the claim button gives the reader a clear next step. It is deliberately easier than opening an app and checking benefits.

The Walmart-themed example frames the button as a way to view points and details. The wording does not reveal where the link actually goes.

The deadline makes independent checking feel expensive. If points expire today, the reader may think a few seconds of caution will cost the reward.

That pressure belongs to the sender’s story. An unverified email cannot establish the real state of your retailer account.

Step 4: The button leaves the trusted account behind

The decisive risk begins when the message directs you to a page chosen by the sender. It may resemble a retailer page without being one.

Its address might contain the store name, a promotional word, or a shortened redirect. Those surface clues do not establish ownership.

We do not have a verified final checkout for every example Barracuda captured. Do not assume each click produces the same form or charge.

However, submitting credentials, contact details, payment data, or a verification code to an unverified destination would give the operator something valuable.

Barracuda capture of a fake Walmart points-expiration email with a button to view points and details

Notice how the second captured email changes the store and the reason to hurry. It keeps the reader focused on the imagined reward.

Step 5: The prize story can continue after the first page

A destination may ask for another click, a survey, account confirmation, or a shipping payment. Those are possible follow-on moves, not verified steps for every email.

Stop at the first unexpected request. A claimed reward does not justify disclosing a password, card number, or one-time code.

If the page redirects, keep the address chain for a report, but do not keep following it merely to discover how far the offer goes.

Fraud pages often change quickly. A dead link tomorrow would not make the original message safe or erase a disclosure made today.

What the Hidden Text Does and Does Not Tell You

“Text salting” describes a delivery tactic. It explains why a phishing email may evade screening, not what happened inside your retailer account.

It also does not mean an AI system was fully controlled by the attacker. The research describes attempts to distort automated classification.

The distinction matters because people sometimes hear “AI bypass” and assume all protections are pointless. That would give the scam too much credit.

Mail screening, reputation checks, and user reporting still remove many bad messages. The lesson is simply that the inbox is not a seal of authenticity.

Nor does the presence of a retailer’s brand establish that the retailer’s systems were breached. The brand is what the message imitates.

A real account notification should stand up to a separate check. Open the store app you already use and look for the same points or reward.

If your account shows no matching offer, treat the email as suspect. If it does show something, use the account’s own redemption path.

Never type a familiar retailer’s name into a search ad as your only verification route. A sponsored result can point somewhere else.

Use an established bookmark, the app already installed from a trusted store, or a website address you know independently.

Warning Signs in a Fake Points or Gift Card Offer

A countdown, “expires today” line, or unusually generous exchange rate deserves a pause. Legitimate rewards can expire, but urgency is also a common lure.

A message that claims a reward you cannot find in your account is more telling than imperfect grammar. Modern phishing can be neatly written.

Watch for a button that asks you to log in again, even though you already reached the offer from an email supposedly tied to your account.

A tiny delivery fee for a free gift can still expose a card. Read what the page actually requests before entering payment information.

Do not trust a browser padlock alone. Encryption protects a connection to a site; it does not tell you who operates that site.

A visible brand mark, product photo, or copied loyalty tier can be reproduced. Your independent account view remains the stronger check.

If you manage email for an organization, preserved headers and the original file can help security staff inspect hidden content and sender infrastructure.

For a personal inbox, you do not need specialist tools. Report the message as phishing and avoid its claim route.

What to Do if You Have Fallen Victim to This Scam

  1. Identify exactly what happened.

    Receiving or reading the email is not the same as submitting information. Note whether you clicked, entered details, paid, or approved a login code.

    That difference determines the next action. A clicked link without any input calls for caution, while an exposed password needs an immediate change.

  2. Leave the link and verify the retailer independently.

    Close the page. Open the retailer’s own app or type its known address yourself, then check the actual loyalty balance and recent account activity.

    If you see an unfamiliar order or account change, contact the retailer through its official support channel and explain the sequence.

  3. Secure any account whose credentials you entered.

    Change the password on the real service, review active sessions, and enable or strengthen multifactor authentication. Replace reused passwords on other accounts.

    If you gave an email password, treat that account as urgent because it may receive password-reset messages for other services.

  4. Contact the card issuer if payment details were shared.

    Tell the issuer where you entered the card number and ask about monitoring, replacement, and disputes for any unauthorized transactions.

    Do not rely on a support number printed inside the questionable email or page. Use the number on your card or official account.

  5. Preserve and report the evidence.

    Keep the original email, sender details, URL, dates, and screenshots. Do not publish passwords, codes, full card numbers, or personal identifiers.

    Use your mail provider’s phishing report tool. If money was lost, file a report with the appropriate consumer or cybercrime authority.

  6. Check the device only if the link introduced another risk.

    If you downloaded a file, allowed notifications, or installed software, remove that permission or software and use a reputable security check such as Malwarebytes.

    If the lure came through repeated malicious ads, AdGuard can reduce exposure. Neither product reverses a password or card disclosure already made.

Frequently Asked Questions

Is a Lowe’s or Walmart reward email always fake?

No. Real retailers send promotions. The captured messages discussed here are deceptive examples; verify any offer in the independently opened retailer account.

Does landing in my inbox mean the offer passed a safety check?

No. Mail filters reduce risk, but this campaign deliberately hides filler text to influence classification. Delivery is not authentication.

Did Barracuda say one million people lost a gift card?

No. Its figure refers to more than one million detected attacks using these tactics, not successful redemptions or confirmed victims.

Can I recognize text salting without opening email code?

Usually not reliably. Focus on the visible claim and whether the retailer’s own account confirms the reward.

What if I clicked but entered nothing?

Close the page, avoid later prompts, and check for downloaded files or browser notification permissions. A click alone does not prove account theft.

Why would a free reward ask for card information?

A page might call it shipping or verification. Do not pay through an unverified claim link; check the real retailer’s offer terms independently.

The Bottom Line

The retail reward email scam turns a familiar loyalty offer into a reason to leave your inbox and trust a sender-controlled link.

Hidden text may help that email arrive, but it cannot make the reward genuine. Verify the offer inside your own retailer account before claiming anything.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

NervoFlow Pink Salt Nerve Pain Ads Exposed: Fake FDA Approval and Dr. Oz

Next

Roarium Dino Projector Review: Urgency, Returns and Buyer Risks Checked