Coles and Telstra loyalty point phishing scams are circulating. Here's how to spot one

how to, coles and telstra loyalty point phishing scams are circulating. here's how to spot one

This is just one variation of a recent Coles loyalty point scam text. (Supplied)

Ever received a text asking you to click on a link to stop your loyalty or reward points expiring?

It's likely to be a scam.

The Australian Communications and Media Authority (AMCA) has reported a sharp rise in shopping points and rewards-based SMS scams, and is warning customers to be vigilant.

Here are some of the brands that have been impersonated, and the steps to follow when trying to spot a scam.

Which companies have been impersonated?

The AMCA said scammers had been impersonating well-known brands including:

  • Coles
  • Telstra
  • Optus
  • Woolworths

Data analysts at Australia and New Zealand's national identity and cyber support service IDCARE detected a spike in these scams in May.

"This was particularly evident with IDCARE clients engaging with Coles impersonation loyalty messages," IDCARE's Kathy Sundstrom says.

"Where we normally see a few, there was a sharp increase. But it's still relatively smaller volumes when compared to other scams."

Last year, the Australian Competition and Consumer Commission (ACCC) also warned customers holding loyalty points with major businesses to beware of a new phishing scam.

How does a loyalty point phishing scam work?

Scammers send victims a message, telling them to click on a link to redeem their points before they expire.

The link then takes you to a website designed to look just like the company you have points with.

Here, you're prompted to enter your login or financial details.

From there, the cyber-criminal will use this information — such as passwords, credit card or banking details — to carry out fraudulent activities.

The companies named in the AMCA's warning have a list of active or recent scams on their websites. You can find them here:

    Why do scammers use loyalty point programs to target customers?

    Tyler McGee, from online protection company McAfee, says psychology plays a large role in why scams work.

    "Scammers can appeal to your sense of trust by using well-known names, or your fear of missing out by creating a sense of urgency," Mr McGee says.

    "Loyalty programs can embody both those emotions.

    "By using them as a tactic, they can gather your personal and credit card information, both of which are valuable."

    Ms Sundstrom says scammers are known for investing time in studying what makes Australians "tick".

    "They research what we like, how organisations communicate with us, and they are masters at trying to mimic the kind of messaging we would expect to see," she says.

    "They send messages out en masse because there is a strong likelihood it will connect with someone who may be interested or concerned enough about their loyalty program to not look too closely for the red flags in the messaging and click on a link."

    According to Finder, 91 per cent of Australians are members of at least one loyalty program.

    And this popularity hasn't escaped the attention of scammers.

    How can I spot a scam text message?

    The Australian Cyber Security Centre says there are a few dead giveaways.

    Scam text messages with links are a very common tool used in phishing scams.

    Any text asking you to follow a link should be treated with caution.

    While the link leads to a web address that may contain the name of the impersonated company, the URL will likely have some inaccuracies such as:

    • Misspellings
    • Unusual words
    • Random letters or numbers
    • A different domain, e.g. ".net" instead of ".com" or "Am0z0n.com" vs "amazon.com".

    [facebook post telstra]

    Are you told you have a limited time to respond?

    Scammers will try to rush you by saying that points are about to expire, and you need to act urgently by clicking on a link before time runs out.

    You may also be driven to click on a link due to a fear of missing out on a good deal.

    Is the message claiming to be from someone official, like your bank, a government department, a utility company, your doctor or a solicitor?

    Criminals pretend to be important people or organisations to trick you into doing what they want.

    Last month, Coles confirmed the "3022 points" text message was a phishing scam and was not sent by the supermarket giant.

    "Coles will never request personal or banking details in unsolicited communications, and legitimate businesses or government agencies will never request payment in gift cards," the statement read.

    How can I protect myself from loyalty point scams?

    Here's what Scamwatch recommends you do:

    • Delete or ignore any message regarding a loyalty program that contains a link
    • Don't click on a link included in a text message
    • Never provide any personal or financial details if the sender is unknown or suspicious
    • Use the reward program's app or website to independently check on the status of your points

    Mr McGee says if it's too good to be true, it probably is.

    "Don't let what seems like a good deal turn into a disaster," he says.

    Essentially, the best way to protect yourself is to be a cautious customer.

    "Expect that every message you receive out of the blue is a scam, until you've checked that it isn't," Ms Sundstrom says.

    "It's not too hard to verify messages by checking if the organisation is offering the promotion on their website.

    "You can even do a quick Google search, using the wording in the text and asking 'Is this a scam?'"

    What should I do if I've been scammed?

    If you think you've been scammed, contact your bank immediately and report it to Scamwatch and ReportCyber.

    You should also report the event to the specific organisation involved. For example, Telstra customers are able to dob in scam texts via an online form.

    If it looks like a scammer is impersonating an Australian business, contact the fair trading organisation in your state or territory.

    Visit IDCARE for advice on securing your accounts online.

    How many scams have been reported in Australia?

    According to Scamwatch, over 95,000 scams have been reported in 2024 so far.

    Of those, 39,380 reports were to do with phishing scams, leading to the loss of more than $4.6 million.

    [datawrapper]Have you been targeted by or fallen victim to a scam? Tell us your story

    OTHER NEWS

    12 minutes ago

    Julie Goodwin looks very different as troubled MasterChef star gets glamorous makeover ahead of Dancing With The Stars debut

    16 minutes ago

    TFSA Total Returns: 2 Top Dividend Stocks With High Yields and Huge Upside Potential

    16 minutes ago

    Noida International Airport to launch flight services by April next year amid construction delays

    16 minutes ago

    King Charles makes big royal change after years of controversy

    16 minutes ago

    England v Slovenia player ratings Euro 2024: Gallagher 4, Foden 7; Drkusic 8, Sesko 5

    16 minutes ago

    Rockets Agree to Huge Trade With Nets, Now Focused on Adding Superstar in New Deal

    20 minutes ago

    FDA warns top U.S. bakery not to claim foods contain allergens when they don't

    20 minutes ago

    Sora Cafe: Dunsborough gets new foreshore eatery on Geographe Road

    20 minutes ago

    Ex-Pakistan captain Inzamam-ul-Haq alleges India tampered with the ball - 'Umpires ko aankhein khuli rakhni chahiye'

    20 minutes ago

    Fisher Investments to Spin Off 401(k) Business, Which Will Be Led by Founder Ken Fisher’s Son

    20 minutes ago

    UAE throw support behind Afghanistan in bid for T20 World Cup glory

    20 minutes ago

    Move over Acela Corridor: It's Cleveland that suddenly has the best record in baseball

    20 minutes ago

    No time for Stanley Cup hangover as NHL off-season is already here

    20 minutes ago

    Exclusive: AP launching nonprofit group to raise at least $100M for local news

    20 minutes ago

    Fans throw their support behind Hugh Jackman after his split with Deborra-Lee Furness ahead of Deadpool & Wolverine release: 'I hope on the inside your life is as wonderful'

    20 minutes ago

    EVs: Try before you buy? It's possible

    20 minutes ago

    Video: Sophia Bush and girlfriend Ashlyn Harris have the look of love at the Woolf Works premiere in NYC

    20 minutes ago

    Read the leaked email Seven West Media CEO Jeff Howard sent to staff announcing major restructure that will see 150 jobs go

    24 minutes ago

    Malaysian singer Shila Amzah reveals her 4-year-old son has autism

    25 minutes ago

    Almost half of Britons on antidepressants can quit now, study finds

    25 minutes ago

    Glastonbury 2024 live updates: Worthy Farm gates to open as festival gets underway

    25 minutes ago

    The new Volkswagen Golf R is here, and it's now more powerful than before

    25 minutes ago

    Saints chasing AFL balance on return from bye

    25 minutes ago

    B.C. bids farewell to dry conditions as pattern flip brings rain, storm risk

    25 minutes ago

    Spurs Could Pursue Maxey in Free Agency

    25 minutes ago

    Will Knicks Make Deals for 3 Centers? New York Tracker

    25 minutes ago

    Today's best photos: From T20 cricket fans to missing hiker found

    25 minutes ago

    Age of rage vs. free speech: We've been here before and here's what happened

    25 minutes ago

    16 Nobel Prize-winning economists say Trump policies will fuel inflation

    25 minutes ago

    Fed’s Cook says rate cut will be appropriate ‘at some point’ but gives no time estimate

    25 minutes ago

    England 0-0 Slovenia: Player ratings as Three Lions limp to top spot in Group C

    25 minutes ago

    Read the leaked email Seven West Media CEO Jeff Howard sent to staff announcing major restructure that will see 150 jobs go

    29 minutes ago

    Suspected Houthi attacks target a ship in Gulf of Aden and Israeli port city of Eilat

    33 minutes ago

    Video: What's the point of a holiday? Fitness influencer Steph Claire Smith works out everyday during her Fijian family island getaway

    34 minutes ago

    Singapore factory output beats forecasts with 2.9% rise in May on electronics rebound

    34 minutes ago

    Australian captain Mitch Marsh flags injection of new T20 players after missing World Cup semi-finals

    34 minutes ago

    England fans turn on Gareth Southgate as Euro 2024 dream threatened with early end

    34 minutes ago

    Rockets’ wild trade with Nets is all about trying to get Kevin Durant or Devin Booker

    34 minutes ago

    Richard Osman 'risks costing BBC's The Wheel millions' after breaking vital show rule

    34 minutes ago

    Celtics' Brad Stevens envisions minor tweaks for title defense