{"id":406500,"date":"2026-08-27T15:33:22","date_gmt":"2026-08-27T15:33:22","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=406500"},"modified":"2026-08-27T15:33:22","modified_gmt":"2026-08-27T15:33:22","slug":"commbank-points-text-scam","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/commbank-points-text-scam\/","title":{"rendered":"CommBank Points Text Scam: Your Rewards Won&#8217;t Vanish Tonight"},"content":{"rendered":"<p>A message from \u201cCommBank\u201d says your reward points are about to expire. The balance looks valuable, the deadline feels close, and a link offers a quick way to save what you have earned.<\/p><div id=\"mwtad1958296987\" class=\"gas_fallback-ad_318933-ad_309691-placement_406056\" style=\"margin-top: 40px;margin-bottom: 40px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1213439544\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>It can arrive while you are busy, appear beside genuine bank messages, and use enough familiar wording to make tapping feel routine.<\/p>\n<div id=\"mwtad1648810229\" class=\"gas_fallback-ad_360567-ad_309691-placement_406064\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6224621518\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>The CommBank points text scam depends on several details the message hopes you will not check before following its link.<\/p>\n<figure class=\"wp-block-image size-large\"><img width=\"1024\" height=\"521\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/commbank-points-text-scam-1024x521.jpg\" class=\"wp-image-406497\" alt=\"Commonwealth Bank branch used to illustrate the CommBank points text scam\" loading=\"lazy\" decoding=\"async\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/commbank-points-text-scam-1024x521.jpg 1024w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/commbank-points-text-scam-300x153.jpg 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/commbank-points-text-scam.jpg 1080w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" title=\"\"><figcaption class=\"wp-element-caption\">Scammers borrow the name of a real bank to make an unexpected rewards message feel familiar and safe.<\/figcaption><\/figure>\n<div id=\"mwtad3601242613\" class=\"gas_fallback-ad_406051-ad_309691-placement_406057\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6424692219\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>The message invents an urgent points deadline<\/h3>\n<p>The CommBank points text scam claims that Awards or rewards points will expire unless the recipient redeems them immediately. Some versions show a precise balance. Others promise a gift, bonus, cash credit, or special catalogue item.<\/p>\n<p>The deadline is the engine of the scam. Points feel like stored value, so the message creates a small but believable fear of loss. A person who would ignore a strange payment request may still tap to protect rewards they think they already own.<\/p>\n<div id=\"mwtad1013762090\" class=\"gas_fallback-ad_360571-ad_309691-placement_406065\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5867729999\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>CommBank has published alerts about Awards-themed phishing campaigns. Its guidance says customers should not redeem points through a link in an email or SMS. The bank also warns that fraudulent messages can appear in the same thread as genuine ones.<\/p>\n<h3>The link opens a login trap, not a rewards page<\/h3>\n<p>The text uses a shortened or unrelated web address that hides the real destination. The landing page may copy CommBank colours, logos, menu labels, and NetBank language, then ask for a Client ID and password before showing the supposed offer.<\/p>\n<div id=\"mwtad3942460477\" class=\"gas_fallback-ad_360576-ad_309691-placement_406066\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6594472392\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>That form does not need to look perfect. It only needs to keep the victim moving. A second screen may ask for a card number, expiry date, security code, mobile number, or a one-time NetCode under the pretext of confirming the redemption.<\/p>\n<p>Anything entered can go directly to the operator. The reward is bait; account access and payment data are the real targets. If a one-time code is requested, criminals may be attempting a live login, card transaction, or digital-wallet registration at that moment.<\/p>\n<h3>The safest check happens outside the text<\/h3>\n<p>Do not use the sender name, conversation thread, button, short link, or callback number as proof. Open the CommBank app yourself or type <a href=\"https:\/\/www.commbank.com.au\/\" rel=\"nofollow noopener\" target=\"_blank\">commbank.com.au<\/a> into a fresh browser window.<\/p>\n<p>Your real points balance and legitimate program notices should be visible after a login you started through the official app or site. If the message claims an urgent change that is absent there, stop and report the text.<\/p><div id=\"mwtad1164100650\" class=\"gas_fallback-ad_360583-ad_309691-placement_406067\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8849826992\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>Key warning signs include:<\/p>\n<ul>\n<li>An unexpected warning that points expire today or within hours<\/li>\n<li>A shortened link or a domain that is not controlled by CommBank<\/li>\n<li>A request to log in through an SMS link<\/li>\n<li>A page asking for a NetCode, PIN, card security code, or password<\/li>\n<li>A reward that requires a small card payment for delivery<\/li>\n<li>A sender that discourages checking the CommBank app<\/li>\n<li>Pressure to reply, call, or act before a countdown ends<\/li>\n<\/ul>\n<figure class=\"wp-block-image size-large\"><img width=\"580\" height=\"1024\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/fake-commbank-rewards-sms-580x1024.jpg\" class=\"wp-image-406498\" alt=\"Fake CommBank text claiming Awards points are about to expire\" loading=\"lazy\" decoding=\"async\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/fake-commbank-rewards-sms-580x1024.jpg 580w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/fake-commbank-rewards-sms-170x300.jpg 170w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/fake-commbank-rewards-sms-870x1536.jpg 870w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/fake-commbank-rewards-sms.jpg 945w\" sizes=\"auto, (max-width: 580px) 100vw, 580px\" title=\"\"><figcaption class=\"wp-element-caption\">A reported CommBank impersonation text uses a points-expiry warning and a shortened link. The sender label does not prove that the bank sent it.<\/figcaption><\/figure>\n<div id=\"mwtad1490825002\" class=\"gas_fallback-ad_406052-ad_309691-placement_406058\" style=\"margin-top: 40px;margin-bottom: 40px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6148928849\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the CommBank Points Text Scam Works<\/h2>\n<h3>Step 1: A familiar sender name lowers your guard<\/h3>\n<p>The message may display \u201cCommBank,\u201d \u201cCBA,\u201d or another familiar sender label instead of a normal phone number. On some phones, manipulated sender information can make a fraudulent text appear near an existing conversation with the bank.<\/p>\n<div id=\"mwtad2700898077\" class=\"gas_fallback-ad_360584-ad_309691-placement_406068\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3952847241\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>That placement is persuasive, but it is not authentication. CommBank notes that scam messages may appear in the same thread as real communications. New Australian sender-ID protections improve filtering, but the bank still tells customers to verify unexpected requests independently.<\/p>\n<h3>Step 2: A believable points balance creates ownership<\/h3>\n<p>The text may claim that thousands of points are waiting. A precise-looking number makes the message seem connected to an account, even when it was sent in bulk and the sender knows nothing about the recipient.<\/p>\n<p>People also forget exact rewards balances. That uncertainty helps the story. If the number seems plausible, the victim may focus on preserving it instead of asking why a bank would send an unrequested login link.<\/p>\n<h3>Step 3: A short deadline blocks careful checking<\/h3>\n<p>Phrases such as \u201cexpires today,\u201d \u201cfinal reminder,\u201d and \u201credeem now\u201d turn a low-stakes message into a decision. The goal is to make opening the link feel safer than pausing.<\/p>\n<p>Scamwatch describes the same pattern across loyalty programs: a message says points are expiring, a link opens a fake website, and the site asks for login or card details. The brand can change while the sequence remains the same.<\/p>\n<h3>Step 4: The link hides a copied banking page<\/h3>\n<p>The example shown above uses a shortened address rather than a CommBank domain. Shorteners are not automatically malicious, but they conceal the destination. That makes them a poor foundation for a sensitive banking action.<\/p>\n<p>A copied page can display the correct logo and still be controlled by criminals. The padlock in a browser only means the connection to that particular site is encrypted. It does not prove that Commonwealth Bank owns the site.<\/p>\n<h3>Step 5: The fake redemption collects credentials<\/h3>\n<p>The first form may ask for NetBank credentials. A later page can request identity details, card information, or a one-time code. Each screen is framed as another ordinary step needed to access the reward.<\/p>\n<p>In a live phishing operation, the criminals may enter stolen credentials into the real bank site while the victim remains on the fake page. A request for a fresh NetCode can therefore be tied to an actual action, not a harmless verification.<\/p>\n<h3>Step 6: A small delivery fee opens a second route<\/h3>\n<p>Some loyalty scams skip the bank login and offer a desirable item for a small postage charge. The amount looks trivial compared with the promised reward, so the victim supplies full card details without treating the page like a serious purchase.<\/p>\n<p>The card can then be used for unauthorised transactions or passed to other criminals. A deceptive checkout may also hide recurring billing language, although the exact outcome depends on the page and should not be assumed from the opening text alone.<\/p>\n<h3>Step 7: The operator keeps the victim engaged<\/h3>\n<p>After data is submitted, the page may show an error, claim the NetCode was wrong, or request another code. Repeated prompts help criminals obtain a valid credential while making the victim think the redemption system is simply slow.<\/p>\n<p>A later caller may pose as CommBank fraud staff and refer to the earlier interaction. Possessing the victim&#8217;s name or partial details can make that follow-up sound convincing. The caller may then request more codes or instruct the victim to move money.<\/p>\n<figure class=\"wp-block-image size-large\"><img width=\"1024\" height=\"675\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/official-commbank-awards-phishing-alert-1024x675.png\" class=\"wp-image-406499\" alt=\"Official CommBank alert for Awards themed phishing messages\" loading=\"lazy\" decoding=\"async\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/official-commbank-awards-phishing-alert-1024x675.png 1024w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/official-commbank-awards-phishing-alert-300x198.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/official-commbank-awards-phishing-alert.png 1365w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" title=\"\"><figcaption class=\"wp-element-caption\">CommBank&#8217;s own scam-alert page lists Awards-themed and Rewards-themed phishing messages among its archived warnings.<\/figcaption><\/figure>\n<div id=\"mwtad728286559\" class=\"gas_fallback-ad_406053-ad_309691-placement_406059\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5354318971\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>The Real CommBank Update Does Not Require an SMS Login<\/h2>\n<p>There is a genuine program change that scammers may try to exploit. CommBank says its Awards program will close on September 29, 2026, with existing points handled through a transition to CommBank Yello, a Qantas transfer, or another stated process depending on eligibility.<\/p>\n<p>That real announcement does not make an urgent points-expiry text trustworthy. CommBank&#8217;s <a href=\"https:\/\/www.commbank.com.au\/credit-cards\/card-updates.html\" rel=\"nofollow noopener\" target=\"_blank\">official card update<\/a> explains the timeline and what happens to existing points. Customers can review it from the bank&#8217;s website or app without using an unsolicited link.<\/p>\n<p>This is an important distinction. Criminals often build phishing around real events because a recipient may have heard part of the news. A program migration, data breach, policy change, or new sender-ID rule can give a false message just enough truth to survive a quick glance.<\/p>\n<p>If the wording changes after the migration, the method may remain familiar. A future message could claim that Yello points, a cash conversion, a transfer, or an account update needs immediate confirmation. The label is disposable; the off-platform login request is the durable warning sign.<\/p>\n<div id=\"mwtad611372560\" class=\"gas_fallback-ad_406054-ad_309691-placement_406060\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4041237300\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How to Check the Message Without Risking Your Account<\/h2>\n<p>First, leave the text untouched. Do not tap the link, reply, or call a number included in the message. Take a screenshot if you want to report it, then open the official CommBank app from your phone&#8217;s normal app screen.<\/p>\n<p>Check the rewards or account area and look for secure notices. You can also type the official domain into a browser. Do not copy the address from the message, because lookalike spellings can be difficult to notice on a small screen.<\/p>\n<p>If you still cannot resolve the claim, use the contact route shown inside the app or on CommBank&#8217;s <a href=\"https:\/\/www.commbank.com.au\/support\/contact-us.html\" rel=\"nofollow noopener\" target=\"_blank\">official contact page<\/a>. The bank currently directs personal-banking customers to 13 2221 and offers secure messaging through its app.<\/p>\n<p>CommBank also says it will not ask customers to share NetBank Client IDs, passwords, NetCodes, PINs, or card details in response to an unexpected message. It will not ask customers to log in through a link sent by SMS.<\/p>\n<p>For the pictured example, the contradiction is especially strong. The message claims points are about to expire, while CommBank&#8217;s campaign warning stated that Awards points did not expire under the program rules then in force. A false deadline was used to manufacture urgency.<\/p>\n<div id=\"mwtad1112471965\" class=\"gas_fallback-ad_406055-ad_309691-placement_406061\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3690286463\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Company, Address, and Fulfillment Checks<\/h2>\n<h3>Identity: CommBank is real, but the sender is not verified<\/h3>\n<p>Commonwealth Bank of Australia is a real regulated bank. Its official pages identify the entity as Commonwealth Bank of Australia, ABN 48 123 123 124. That genuine identity is exactly what makes an impersonation message useful to criminals.<\/p>\n<p>A logo, sender label, or accurate company name proves only that the sender can copy public information. Authentication must come from a channel controlled by the bank, such as the installed app, a directly typed official website, or a verified phone number found independently.<\/p>\n<h3>Address: a web address matters more than the logo<\/h3>\n<p>For this scam, the critical address is the domain in the link. CommBank&#8217;s public website uses commbank.com.au, while secure services are reached through routes the bank publishes. A random shortener or lookalike spelling should not be used for a banking login.<\/p>\n<p>Do not trust a phishing page because it lists a real branch or corporate address in the footer. Those details can be copied. Use CommBank&#8217;s official branch locator or contact page if an in-person or postal check is needed.<\/p>\n<h3>Fulfillment: there is no legitimate SMS checkout to complete<\/h3>\n<p>A genuine points redemption should be visible after you enter the rewards area through NetBank or the CommBank app. You should not need an unsolicited text to unlock a hidden catalogue, release a prize, or pay an unexplained delivery charge.<\/p>\n<p>If a page promises an item but provides no independently verifiable order record, merchant identity, delivery terms, or support path, stop. The absence of normal fulfillment information is another clue that the product exists only to collect data.<\/p>\n<h3>Contact: use the bank&#8217;s route, not the message&#8217;s route<\/h3>\n<p>CommBank&#8217;s security hub says customers who suspect a scam can message the bank in its app or call 13 2221. Suspicious messages that were not opened can be sent as a screenshot or copy to hoax@cba.com.au.<\/p>\n<p>A callback number supplied by the suspected scammer cannot verify the suspected scammer. The same principle applies to a chat widget, email address, or help desk placed on the linked page. Start a separate conversation using details you found yourself.<\/p>\n<div id=\"deskad1\" class=\"gas_fallback-ad_406036-ad_309691-placement_406062\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5700081834\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What to Do if You Have Fallen Victim to This Scam<\/h2>\n<ol>\n<li><strong>Contact CommBank immediately.<\/strong> Use secure messaging in the official app or call 13 2221 from a number you verified independently. Explain what you entered, whether you approved a NetCode, and whether any transaction or digital-wallet registration occurred.<\/li>\n<li><strong>Lock affected cards and review activity.<\/strong> Check accounts, cards, payees, transfers, and digital wallets for changes you do not recognise. Ask the bank what should be blocked, replaced, disputed, or monitored.<\/li>\n<li><strong>Change exposed credentials from a trusted device.<\/strong> Replace the NetBank password and any reused password. Secure the connected email account as well, because email access can help criminals reset other accounts.<\/li>\n<li><strong>Do not approve another code or prompt.<\/strong> A caller may claim a second NetCode is needed to reverse the fraud. Read every code message carefully and never share it with an unsolicited caller.<\/li>\n<li><strong>Check the device.<\/strong> If you downloaded an app, profile, or file, disconnect the device from sensitive accounts and scan it with reputable security software such as <a href=\"https:\/\/www.malwarebytes.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Malwarebytes<\/a>. Remove unfamiliar remote-access tools only after preserving any evidence the bank requests.<\/li>\n<li><strong>Reduce further exposure.<\/strong> A content blocker such as <a href=\"https:\/\/adguard.com\/\" rel=\"nofollow noopener\" target=\"_blank\">AdGuard<\/a> can help block known malicious pages, but it cannot make an unverified message safe. Continue to enter banking sites through saved official routes.<\/li>\n<li><strong>Report the attempt.<\/strong> Send the suspicious message to CommBank and report it to <a href=\"https:\/\/www.scamwatch.gov.au\/report-a-scam\" rel=\"nofollow noopener\" target=\"_blank\">Scamwatch<\/a>. If identity information was exposed, IDCARE can help Australian and New Zealand victims plan recovery.<\/li>\n<li><strong>Watch for follow-up scams.<\/strong> Criminals may pose as investigators or recovery specialists who already know details from the first page. Do not pay anyone who promises to recover money or secure the account for an upfront fee.<\/li>\n<\/ol>\n<h2>Frequently Asked Questions<\/h2>\n<h3>Do CommBank Awards points expire?<\/h3>\n<p>Under the program rules cited during the 2025 phishing campaign, CommBank said Awards points did not expire while the eligible account remained open. The program is scheduled to close on September 29, 2026, and the bank has published specific transition arrangements.<\/p>\n<p>Check the current position in the CommBank app or on its official card-update page. An unsolicited text claiming that everything disappears today is not a substitute for those terms.<\/p>\n<h3>Can a scam text appear in the same thread as real CommBank messages?<\/h3>\n<p>Yes. CommBank and Scamwatch both warn that manipulated sender information can make a fraudulent message look as if it belongs to a genuine conversation. A familiar thread is therefore a visual clue, not proof of origin.<\/p>\n<p>Judge the requested action instead. A link that asks for banking credentials, card details, or a NetCode should be abandoned, even when the sender label looks correct.<\/p>\n<h3>Is every shortened link in a bank message malicious?<\/h3>\n<p>No. Short links have legitimate uses, but they hide the destination and should not be used as the basis for a sensitive login. The risk is especially high when the message is unexpected and creates an urgent deadline.<\/p>\n<p>There is no need to investigate the short link yourself. Open the official app or type the bank&#8217;s known domain separately and check the same claim there.<\/p>\n<h3>What if I clicked but did not enter anything?<\/h3>\n<p>Close the page and do not return. Clicking alone does not prove that an account was compromised, but the site may have collected technical information and the operator now knows the link reached an active device.<\/p>\n<p>Delete any download, check for unfamiliar apps or profiles, update the browser and operating system, and watch for follow-up messages. Contact the bank promptly if anything was entered or installed.<\/p>\n<h3>What if I entered my password but did not share a NetCode?<\/h3>\n<p>Treat the password as stolen. Change it immediately through the official app or site, review the account, and contact CommBank. Do not assume that multi-factor authentication makes a disclosed password harmless.<\/p>\n<p>Also change the password anywhere else it was reused. Criminals often test exposed credentials against email, shopping, social-media, and other financial accounts.<\/p>\n<h3>How can I report a fake CommBank rewards text?<\/h3>\n<p>If you did not click, CommBank asks recipients to send a copy or screenshot to hoax@cba.com.au, then block and delete the message. If you interacted with it, use the app or call the verified bank number first.<\/p>\n<p>You can also report the campaign to Scamwatch. Reports help banks, telecommunications providers, hosting companies, and authorities connect multiple messages to the same infrastructure.<\/p>\n<h2>The Bottom Line<\/h2>\n<p>The CommBank points text scam turns a modest reward into a banking emergency. A familiar sender name, a precise balance, and a countdown create the feeling that tapping is the careful choice, while the hidden destination is built to capture credentials and card data.<\/p>\n<p>Ignore the route supplied by the message. Open CommBank through the official app or a directly typed address, check the real program notice there, and contact the bank independently if anything does not match. Real rewards can wait long enough to be verified.<\/p>\n<div id=\"mwtad952205692\" class=\"gas_fallback-ad_406037-ad_309691-placement_406063\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3077074880\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>A CommBank points text says your rewards expire today. See how the fake login steals credentials, how to verify it, and what to do after clicking.<\/p>\n","protected":false},"author":51,"featured_media":406497,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-406500","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/406500","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=406500"}],"version-history":[{"count":2,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/406500\/revisions"}],"predecessor-version":[{"id":406502,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/406500\/revisions\/406502"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/406497"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=406500"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=406500"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=406500"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}