{"id":420187,"date":"2026-09-28T18:14:36","date_gmt":"2026-09-28T18:14:36","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=420187"},"modified":"2026-09-28T18:14:36","modified_gmt":"2026-09-28T18:14:36","slug":"fake-loyalty-points-texts-card-theft-error-screen","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/fake-loyalty-points-texts-card-theft-error-screen\/","title":{"rendered":"Fake Loyalty Points Texts Hide a Card-Theft Page Behind an Error Screen"},"content":{"rendered":"<p>Your phone lights up with a text saying loyalty points are ready to redeem. The message sounds routine, and the promised reward looks close enough to tap.<\/p><div id=\"mwtad4100989985\" class=\"gas_fallback-ad_309684--placement_406659\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>One loyalty points text scam makes that ordinary moment unusually hard to investigate. What a curious visitor sees can differ from what the intended recipient sees.<\/p>\n<figure><img src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/error-sms.jpg\" class=\"wp-image-420188 skip-lazy\" width=\"336\" height=\"342\" decoding=\"async\" loading=\"eager\" fetchpriority=\"high\" alt=\"Authentic Group-IB capture of a Spanish-language loyalty-points phishing text promising a reward\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/error-sms.jpg 336w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/error-sms-295x300.jpg 295w\" sizes=\"(max-width: 336px) 100vw, 336px\" \/><\/figure>\n<div id=\"mwtad1313169363\" class=\"gas_fallback-ad_309746-ad_309685-placement_406660\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>A reward text is the opening move<\/h3>\n<p>The captured Spanish-language message says the recipient has accumulated 7,018 points and can exchange them for a gift. It includes a shortened link.<\/p><div id=\"mwtad3087343357\" class=\"gas_fallback-ad_381396-ad_309685-placement_406667\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>Nothing in that message proves the recipient actually belongs to a rewards program. The number and apparent urgency are part of the sender&#8217;s pitch.<\/p>\n<p>The same operation has copied telecommunications providers, banks, and consumer rewards brands. The logo or institution changes, but the request to follow a text link remains.<\/p>\n<p>That is why this is not an article about one unhappy customer or one legitimate company. It concerns a documented, repeatable card-theft operation.<\/p><div id=\"mwtad6991170\" class=\"gas_fallback-ad_309686-ad_309685-placement_406668\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<h3>Researchers found a broad, organized network<\/h3>\n<p><a href=\"https:\/\/www.group-ib.com\/blog\/error-524-decoy-smishing\/\" target=\"_blank\" rel=\"noopener\">Group-IB&#8217;s June 2026 investigation<\/a> identified 4,389 phishing-domain instances connected with this campaign, spanning 72 countries and 267 impersonated brands.<\/p>\n<p>Those figures describe observed infrastructure and brand abuse. They do not mean 4,389 victims, or prove that every domain successfully stole a card.<\/p>\n<p>The strongest concentration was in Latin America, particularly Mexico, Chile, and Colombia. Researchers also found domains aimed at European, Asian, and North American audiences.<\/p><div id=\"mwtad1536354497\" class=\"gas_fallback-ad_381401-ad_309685-placement_406669\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>These geographic details matter because a message may arrive in Spanish or reference a local provider, while the underlying phishing machinery is reusable elsewhere.<\/p>\n<h3>The page changes according to who opens it<\/h3>\n<p>A qualifying visitor can see a rewards page and eventually a payment form. An analyst or visitor outside the target profile may see a timeout page instead.<\/p>\n<div id=\"mwtad3810368130\" class=\"gas_fallback-ad_381404-ad_309685-placement_406670\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>The false timeout imitates a Cloudflare-style error. It is a decoy, not proof that Cloudflare runs the phishing site or has suffered a breach.<\/p>\n<ul>\n<li>The text claims points or a reward associated with a familiar brand.<\/li>\n<li>A short link moves the reader to a domain controlled by the campaign.<\/li>\n<li>Device and location checks decide whether to display the fraudulent offer.<\/li>\n<li>The reward story can end with a small delivery charge and a card form.<\/li>\n<li>Visitors outside the target group may see a fake error instead.<\/li>\n<\/ul>\n<p>The practical conclusion is simple: do not judge an unsolicited rewards link by its logo, a tiny shipping fee, or what the page shows on someone else&#8217;s computer.<\/p>\n<div id=\"mwtad3385875358\" class=\"gas_fallback-ad_309747-ad_309685-placement_406661\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Why the Text Feels More Personal Than It Is<\/h2>\n<p>A points balance gives the message the appearance of account data. In the captured example, the figure is precise enough to look retrieved from a database.<\/p>\n<div id=\"mwtad4191325615\" class=\"mwtadp5 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"8560433799\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>It may not be. A bulk phishing message can include a plausible number without knowing whether the recipient has any account with the named provider.<\/p>\n<p>Short links add another layer. They conceal the eventual destination until the redirect completes, making a glance at the text less informative.<\/p>\n<p>Even a full URL containing a recognizable brand word would not establish ownership. Criminal operators routinely register addresses that borrow brand terms.<\/p>\n<div id=\"mwtad2973215131\" class=\"mwtadp6 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"4034304343\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>A real loyalty offer should be visible after you open the provider&#8217;s app or website independently. The SMS is not the place to prove its own claim.<\/p>\n<p>That independent check also protects you when a message arrives in a thread that has carried legitimate alerts. Sender IDs and message threads are not guarantees.<\/p>\n<p>The campaign uses reward language because it gives a reason to enter both personal details and a payment card. The promised item supplies the excuse.<\/p>\n<p>In one captured page, the supposed cost is only a small delivery amount. That modest price can make a card request seem proportionate.<\/p>\n<p>The risk is not limited to the amount displayed. The form asks for card details that can be used beyond the advertised delivery charge.<\/p>\n<p>Group-IB captured card fields and described real-time data collection. That is direct evidence of the theft mechanism, not merely a suspicious-looking promotion.<\/p>\n<div id=\"mwtad661316407\" class=\"gas_fallback-ad_309748-ad_309685-placement_406662\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the Loyalty Points Text Scam Works<\/h2>\n<h3>Step 1: A brand-shaped reward arrives by SMS<\/h3>\n<p>The operator sends a message that resembles a telecom, bank, or rewards notice. It may mention expiring points, a gift, or a benefit waiting for collection.<\/p>\n<p>Recipients are expected to supply their own context. Someone who uses that provider may assume the balance is genuine and overlook the unexpected link.<\/p>\n<p>The captured SMS does not explain why the points exist. Its job is to make the reader curious enough to leave the messaging app.<\/p>\n<p>Sometimes the message includes a recognizable shortened-link service. That service did not create the scam; it simply hides the final destination from quick inspection.<\/p>\n<h3>Step 2: The link selects the visitor<\/h3>\n<p>The landing system checks factors such as device type and location. A mobile visitor in a target region may receive the full fraudulent offer.<\/p>\n<p>A desktop browser, automated scanner, or visitor outside the chosen country can receive a different response. This makes quick verification unreliable.<\/p>\n<p>Group-IB found decoy pages imitating web-service timeout errors. The campaign is known for an Error 524-style screen, although a captured variant displays a different number.<\/p>\n<p>The number itself is not the warning. The important fact is that the operator uses an error-looking page to hide the card-theft page from scrutiny.<\/p>\n<p>If a friend opens your link and sees an error, that does not mean your earlier screen was safe. The site may be serving different content deliberately.<\/p>\n<h3>Step 3: A familiar-looking page asks for identity details<\/h3>\n<p>On a targeted device, the site may show a brand-colored rewards page and a form for a phone number or national identifier.<\/p>\n<p>The user interface borrows the language of checking a balance. It encourages a small first disclosure before presenting the more consequential payment step.<\/p>\n<p>These pages are not account portals belonging to the impersonated brands. They are fraudulent pages that copy enough visual cues to create confidence.<\/p>\n<p>Some versions show a generous prize. Others emphasize a specific product or a limited-time discount. The template can change without changing the objective.<\/p>\n<p>Do not test the form with your real details to see what happens next. Even a preliminary lookup box can collect information useful in later fraud.<\/p>\n<h3>Step 4: A small charge leads to the card form<\/h3>\n<p>After the reward is supposedly confirmed, the page can request a delivery or processing payment. One captured form displayed a low amount in local currency.<\/p>\n<p>That figure is bait. The form requests the cardholder name, card number, expiration date, and security code, which are worth far more than the stated fee.<\/p>\n<p>The fact that a page displays familiar payment-card logos proves nothing about its legitimacy. Those images are easy to copy.<\/p>\n<p>Likewise, a padlock indicates an encrypted connection to the website you reached. It does not verify that the website represents the named brand.<\/p>\n<figure><img src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" class=\"wp-image-420189 lazyload\" width=\"1249\" height=\"1004\" decoding=\"async\" loading=\"lazy\" alt=\"Authentic Group-IB capture of a phishing checkout requesting card number, expiration and security code for a supposed reward delivery\" title=\"\" sizes=\"auto, (max-width: 1249px) 100vw, 1249px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/error-card.png\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/error-card.png 1249w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/error-card-300x241.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/error-card-1024x823.png 1024w\"><\/figure>\n<p>This captured card page is the point where the reward story becomes a payment-data theft attempt. The screenshot comes from Group-IB&#8217;s investigation.<\/p>\n<h3>Step 5: The operator can use the data quickly<\/h3>\n<p>Group-IB describes real-time transmission from the phishing pages to the campaign&#8217;s infrastructure. The visitor may not see any sign that information has left.<\/p>\n<p>A failed transaction or spinning page should not reassure you. The fields may have been collected when you pressed submit, before any confirmation appeared.<\/p>\n<p>The operator can rotate domains, logos, and texts after a page is reported. Searching for one exact URL may miss the next active version.<\/p>\n<p>Nor does a dead site erase card details already submitted. Recovery should start with the card issuer rather than another attempt to reopen the link.<\/p>\n<div id=\"mwtad285658770\" class=\"gas_fallback-ad_318930-ad_309685-placement_406663\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What the Error Page Really Means<\/h2>\n<p>Readers may hear that this is an \u201cError 524 scam\u201d and imagine the timeout is the part that steals money. It is not.<\/p>\n<p>The fake error is camouflage. The theft opportunity is the targeted reward and payment journey shown to qualifying visitors.<\/p>\n<p>A genuine website can of course experience a real timeout. An error page alone is not evidence of fraud, and no single error code proves intent.<\/p>\n<p>Here, the conclusion comes from the combined research: clustered phishing domains, captured reward texts, copied brands, card forms, and visitor-dependent decoys.<\/p>\n<p>That distinction prevents an easy mistake. A person should not report Cloudflare as the merchant that requested card data simply because its design was imitated.<\/p>\n<p>If you are gathering evidence for a bank or provider, save the original message, the link, page address, screenshots, and any transaction notice.<\/p>\n<p>Do not keep revisiting the fraudulent site to see whether the error disappears. Each visit can reveal more about your device and location to its operator.<\/p>\n<div id=\"mwtad18997513\" class=\"gas_fallback-ad_381388-ad_309685-placement_406705\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3191649120\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How to Check a Real Rewards Offer Without Following the Text<\/h2>\n<p>Start with an app you installed before the message arrived. Sign in normally and look for the same points balance or reward in your account.<\/p>\n<p>If you do not use the app, type the provider&#8217;s known address yourself. Avoid a sponsored search result when you are trying to verify a suspicious offer.<\/p>\n<p>Compare the offer&#8217;s terms, expiry, and redemption path. A genuine program should not require you to use an unrelated short link sent by SMS.<\/p>\n<p>If nothing appears in your account, treat the text as unverified. Contact the provider through the number printed on a card or its official site.<\/p>\n<p>Do not call a phone number supplied by the suspicious message or page. That merely returns you to the same operator if the number is part of the trap.<\/p>\n<p>People sometimes ask whether the low fee makes the offer believable. A small fee is exactly how a full card form can be made to feel ordinary.<\/p>\n<p>Also check for a follow-up request to install an app, approve notifications, or enter a one-time code. Those are separate risks, not routine redemption steps.<\/p>\n<p>Group-IB&#8217;s captured version centered on personal and card data. We are not claiming that every linked site in this network also installs malware.<\/p>\n<div id=\"mwtad3567306380\" class=\"gas_fallback-ad_381392-ad_309685-placement_406664\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What to Do if You Have Fallen Victim to This Scam<\/h2>\n<ol>\n<li><strong>If you entered a card, contact its issuer now.<\/strong> Use the number on the physical card or in your banking app. Request a replacement and discuss fraud monitoring.<\/li>\n<li><strong>Review pending and posted activity.<\/strong> Ask the issuer how to dispute unauthorized charges and whether any card-on-file tokens should be replaced or blocked.<\/li>\n<li><strong>If you entered a password, change it from the real site.<\/strong> Change reused passwords too, enable stronger sign-in protection, and review active sessions.<\/li>\n<li><strong>If you disclosed an ID number or personal details, document them.<\/strong> Ask the relevant provider or local identity-protection service what monitoring is appropriate in your country.<\/li>\n<li><strong>Preserve the message and page details.<\/strong> Screenshots, the shortened link, final visible URL, time, and any charge help your bank and the impersonated brand investigate.<\/li>\n<li><strong>Report the text.<\/strong> Use your phone&#8217;s spam control, your carrier&#8217;s reporting channel, and the real brand&#8217;s fraud contact page when available.<\/li>\n<li><strong>Check the device if anything was downloaded or permissions changed.<\/strong> Malwarebytes can scan suspicious software; AdGuard can reduce exposure to malicious ads and domains. Neither reverses a card disclosure.<\/li>\n<li><strong>Ignore recovery offers.<\/strong> Anyone claiming they can retrieve stolen card data for an upfront fee is adding another problem, not fixing this one.<\/li>\n<\/ol>\n<p>If you clicked but entered nothing, close the page and clear any notification permission you granted. A click alone is different from handing over card details.<\/p>\n<p>If the site charged you a small fee, do not wait for a larger charge before calling your issuer. The visible price was not a reliable limit.<\/p>\n<p>Tell the bank that the payment followed an unsolicited rewards text. That context helps it assess the merchant, card exposure, and dispute route.<\/p>\n<div id=\"mwtad756104728\" class=\"gas_fallback-ad_381392-ad_309685-placement_406665\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Frequently Asked Questions<\/h2>\n<h3>Is the loyalty-points text from my phone company or bank?<\/h3>\n<p>Do not decide from the sender name. Open your provider&#8217;s existing app or known website and check the reward independently.<\/p>\n<h3>Why did my friend see only a timeout page?<\/h3>\n<p>This campaign can show a decoy to visitors outside its chosen device or location profile. Two people may see different pages from the same link.<\/p>\n<h3>Does an Error 524 page mean Cloudflare is involved in the fraud?<\/h3>\n<p>No. Researchers found a fake timeout design used as camouflage. The brand shown on a decoy page is not evidence that the real company runs it.<\/p>\n<h3>Can a small shipping charge still put my card at risk?<\/h3>\n<p>Yes. The captured checkout requested full card details. The small displayed fee does not restrict how stolen details might be used later.<\/p>\n<h3>Does an expired phishing link mean my submitted details are safe?<\/h3>\n<p>No. A domain can be disabled after data was already transmitted. If you entered card information, contact the issuer even if the page no longer loads.<\/p>\n<h3>What if I only opened the message and never tapped its link?<\/h3>\n<p>Reading the text does not give the sender your card number. Mark it as spam, verify any claimed reward independently, and do not engage.<\/p>\n<h2>The Bottom Line<\/h2>\n<p>The loyalty points text scam is not a misunderstood promotion. Researchers captured the texts, the reward pages, and the forms built to collect card data.<\/p>\n<p>Its cleverest trick is showing the wrong visitors an error while selected recipients see a prize. Your safest check stays outside the text link, inside the real account.<\/p>\n<div id=\"mwtad1347849525\" class=\"gas_fallback-ad_176819-ad_309685-placement_406666\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8386082122\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Your phone lights up with a text saying loyalty points are ready to redeem. The message sounds routine, and the promised reward looks close enough to tap. One loyalty points text scam makes that ordinary &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"Fake Loyalty Points Texts Hide a Card-Theft Page Behind an Error Screen\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/fake-loyalty-points-texts-card-theft-error-screen\/#more-420187\" aria-label=\"Read more about Fake Loyalty Points Texts Hide a Card-Theft Page Behind an Error Screen\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":420188,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-420187","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/420187","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=420187"}],"version-history":[{"count":1,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/420187\/revisions"}],"predecessor-version":[{"id":420190,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/420187\/revisions\/420190"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/420188"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=420187"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=420187"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=420187"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}