Your phone lights up with a text saying loyalty points are ready to redeem. The message sounds routine, and the promised reward looks close enough to tap.
One loyalty points text scam makes that ordinary moment unusually hard to investigate. What a curious visitor sees can differ from what the intended recipient sees.

Overview
A reward text is the opening move
The captured Spanish-language message says the recipient has accumulated 7,018 points and can exchange them for a gift. It includes a shortened link.
Nothing in that message proves the recipient actually belongs to a rewards program. The number and apparent urgency are part of the sender’s pitch.
The same operation has copied telecommunications providers, banks, and consumer rewards brands. The logo or institution changes, but the request to follow a text link remains.
That is why this is not an article about one unhappy customer or one legitimate company. It concerns a documented, repeatable card-theft operation.
Researchers found a broad, organized network
Group-IB’s June 2026 investigation identified 4,389 phishing-domain instances connected with this campaign, spanning 72 countries and 267 impersonated brands.
Those figures describe observed infrastructure and brand abuse. They do not mean 4,389 victims, or prove that every domain successfully stole a card.
The strongest concentration was in Latin America, particularly Mexico, Chile, and Colombia. Researchers also found domains aimed at European, Asian, and North American audiences.
These geographic details matter because a message may arrive in Spanish or reference a local provider, while the underlying phishing machinery is reusable elsewhere.
The page changes according to who opens it
A qualifying visitor can see a rewards page and eventually a payment form. An analyst or visitor outside the target profile may see a timeout page instead.
The false timeout imitates a Cloudflare-style error. It is a decoy, not proof that Cloudflare runs the phishing site or has suffered a breach.
- The text claims points or a reward associated with a familiar brand.
- A short link moves the reader to a domain controlled by the campaign.
- Device and location checks decide whether to display the fraudulent offer.
- The reward story can end with a small delivery charge and a card form.
- Visitors outside the target group may see a fake error instead.
The practical conclusion is simple: do not judge an unsolicited rewards link by its logo, a tiny shipping fee, or what the page shows on someone else’s computer.
Why the Text Feels More Personal Than It Is
A points balance gives the message the appearance of account data. In the captured example, the figure is precise enough to look retrieved from a database.
It may not be. A bulk phishing message can include a plausible number without knowing whether the recipient has any account with the named provider.
Short links add another layer. They conceal the eventual destination until the redirect completes, making a glance at the text less informative.
Even a full URL containing a recognizable brand word would not establish ownership. Criminal operators routinely register addresses that borrow brand terms.
A real loyalty offer should be visible after you open the provider’s app or website independently. The SMS is not the place to prove its own claim.
That independent check also protects you when a message arrives in a thread that has carried legitimate alerts. Sender IDs and message threads are not guarantees.
The campaign uses reward language because it gives a reason to enter both personal details and a payment card. The promised item supplies the excuse.
In one captured page, the supposed cost is only a small delivery amount. That modest price can make a card request seem proportionate.
The risk is not limited to the amount displayed. The form asks for card details that can be used beyond the advertised delivery charge.
Group-IB captured card fields and described real-time data collection. That is direct evidence of the theft mechanism, not merely a suspicious-looking promotion.
How the Loyalty Points Text Scam Works
Step 1: A brand-shaped reward arrives by SMS
The operator sends a message that resembles a telecom, bank, or rewards notice. It may mention expiring points, a gift, or a benefit waiting for collection.
Recipients are expected to supply their own context. Someone who uses that provider may assume the balance is genuine and overlook the unexpected link.
The captured SMS does not explain why the points exist. Its job is to make the reader curious enough to leave the messaging app.
Sometimes the message includes a recognizable shortened-link service. That service did not create the scam; it simply hides the final destination from quick inspection.
Step 2: The link selects the visitor
The landing system checks factors such as device type and location. A mobile visitor in a target region may receive the full fraudulent offer.
A desktop browser, automated scanner, or visitor outside the chosen country can receive a different response. This makes quick verification unreliable.
Group-IB found decoy pages imitating web-service timeout errors. The campaign is known for an Error 524-style screen, although a captured variant displays a different number.
The number itself is not the warning. The important fact is that the operator uses an error-looking page to hide the card-theft page from scrutiny.
If a friend opens your link and sees an error, that does not mean your earlier screen was safe. The site may be serving different content deliberately.
Step 3: A familiar-looking page asks for identity details
On a targeted device, the site may show a brand-colored rewards page and a form for a phone number or national identifier.
The user interface borrows the language of checking a balance. It encourages a small first disclosure before presenting the more consequential payment step.
These pages are not account portals belonging to the impersonated brands. They are fraudulent pages that copy enough visual cues to create confidence.
Some versions show a generous prize. Others emphasize a specific product or a limited-time discount. The template can change without changing the objective.
Do not test the form with your real details to see what happens next. Even a preliminary lookup box can collect information useful in later fraud.
Step 4: A small charge leads to the card form
After the reward is supposedly confirmed, the page can request a delivery or processing payment. One captured form displayed a low amount in local currency.
That figure is bait. The form requests the cardholder name, card number, expiration date, and security code, which are worth far more than the stated fee.
The fact that a page displays familiar payment-card logos proves nothing about its legitimacy. Those images are easy to copy.
Likewise, a padlock indicates an encrypted connection to the website you reached. It does not verify that the website represents the named brand.

This captured card page is the point where the reward story becomes a payment-data theft attempt. The screenshot comes from Group-IB’s investigation.
Step 5: The operator can use the data quickly
Group-IB describes real-time transmission from the phishing pages to the campaign’s infrastructure. The visitor may not see any sign that information has left.
A failed transaction or spinning page should not reassure you. The fields may have been collected when you pressed submit, before any confirmation appeared.
The operator can rotate domains, logos, and texts after a page is reported. Searching for one exact URL may miss the next active version.
Nor does a dead site erase card details already submitted. Recovery should start with the card issuer rather than another attempt to reopen the link.
What the Error Page Really Means
Readers may hear that this is an “Error 524 scam” and imagine the timeout is the part that steals money. It is not.
The fake error is camouflage. The theft opportunity is the targeted reward and payment journey shown to qualifying visitors.
A genuine website can of course experience a real timeout. An error page alone is not evidence of fraud, and no single error code proves intent.
Here, the conclusion comes from the combined research: clustered phishing domains, captured reward texts, copied brands, card forms, and visitor-dependent decoys.
That distinction prevents an easy mistake. A person should not report Cloudflare as the merchant that requested card data simply because its design was imitated.
If you are gathering evidence for a bank or provider, save the original message, the link, page address, screenshots, and any transaction notice.
Do not keep revisiting the fraudulent site to see whether the error disappears. Each visit can reveal more about your device and location to its operator.
How to Check a Real Rewards Offer Without Following the Text
Start with an app you installed before the message arrived. Sign in normally and look for the same points balance or reward in your account.
If you do not use the app, type the provider’s known address yourself. Avoid a sponsored search result when you are trying to verify a suspicious offer.
Compare the offer’s terms, expiry, and redemption path. A genuine program should not require you to use an unrelated short link sent by SMS.
If nothing appears in your account, treat the text as unverified. Contact the provider through the number printed on a card or its official site.
Do not call a phone number supplied by the suspicious message or page. That merely returns you to the same operator if the number is part of the trap.
People sometimes ask whether the low fee makes the offer believable. A small fee is exactly how a full card form can be made to feel ordinary.
Also check for a follow-up request to install an app, approve notifications, or enter a one-time code. Those are separate risks, not routine redemption steps.
Group-IB’s captured version centered on personal and card data. We are not claiming that every linked site in this network also installs malware.
What to Do if You Have Fallen Victim to This Scam
- If you entered a card, contact its issuer now. Use the number on the physical card or in your banking app. Request a replacement and discuss fraud monitoring.
- Review pending and posted activity. Ask the issuer how to dispute unauthorized charges and whether any card-on-file tokens should be replaced or blocked.
- If you entered a password, change it from the real site. Change reused passwords too, enable stronger sign-in protection, and review active sessions.
- If you disclosed an ID number or personal details, document them. Ask the relevant provider or local identity-protection service what monitoring is appropriate in your country.
- Preserve the message and page details. Screenshots, the shortened link, final visible URL, time, and any charge help your bank and the impersonated brand investigate.
- Report the text. Use your phone’s spam control, your carrier’s reporting channel, and the real brand’s fraud contact page when available.
- Check the device if anything was downloaded or permissions changed. Malwarebytes can scan suspicious software; AdGuard can reduce exposure to malicious ads and domains. Neither reverses a card disclosure.
- Ignore recovery offers. Anyone claiming they can retrieve stolen card data for an upfront fee is adding another problem, not fixing this one.
If you clicked but entered nothing, close the page and clear any notification permission you granted. A click alone is different from handing over card details.
If the site charged you a small fee, do not wait for a larger charge before calling your issuer. The visible price was not a reliable limit.
Tell the bank that the payment followed an unsolicited rewards text. That context helps it assess the merchant, card exposure, and dispute route.
Frequently Asked Questions
Is the loyalty-points text from my phone company or bank?
Do not decide from the sender name. Open your provider’s existing app or known website and check the reward independently.
Why did my friend see only a timeout page?
This campaign can show a decoy to visitors outside its chosen device or location profile. Two people may see different pages from the same link.
Does an Error 524 page mean Cloudflare is involved in the fraud?
No. Researchers found a fake timeout design used as camouflage. The brand shown on a decoy page is not evidence that the real company runs it.
Can a small shipping charge still put my card at risk?
Yes. The captured checkout requested full card details. The small displayed fee does not restrict how stolen details might be used later.
Does an expired phishing link mean my submitted details are safe?
No. A domain can be disabled after data was already transmitted. If you entered card information, contact the issuer even if the page no longer loads.
What if I only opened the message and never tapped its link?
Reading the text does not give the sender your card number. Mark it as spam, verify any claimed reward independently, and do not engage.
The Bottom Line
The loyalty points text scam is not a misunderstood promotion. Researchers captured the texts, the reward pages, and the forms built to collect card data.
Its cleverest trick is showing the wrong visitors an error while selected recipients see a prize. Your safest check stays outside the text link, inside the real account.