The LUMEN Fake-Delivery Network: Fabricated Brand, Real Card Harvest
The LUMEN Fake-Delivery Network: Fabricated Brand, Real Card Harvest
Since January 2026, one operator has run a fabricated "LUMEN" delivery brand, emailing fake shipment alerts that funnel victims to a card-harvesting store. The messages arrive fully authenticated, address the recipient by first name, quote a full postal address and a made-up order number, and warn that a package is stuck behind "road restrictions" or "customs verification." Every click routes through an operator-owned tracking subdomain into a fake Shopify storefront whose checkout asks for a small redelivery fee and then pockets the card. Over roughly five months the operator has sent hundreds of these alerts, rebuilding its sending and store infrastructure twice across two registrars and two email providers, while keeping the same brand, the same lure template, and the same personalized contact list.
Key Takeaways
- One operator ran two full infrastructure generations under a single fabricated LUMEN delivery persona, rotating registrars, email providers, and store domains while reusing the same lure template and the same contact list.
- The fake store is a stock Shopify build, and its logo asset path
/cdn/shop/files/lumen.pngis referenced identically from both store generations, which makes it the most durable cross-generation correlator. - Messages pass SPF, DKIM, and DMARC on operator-owned sending domains, so authentication alone tells a defender nothing.
- A ProtonMail-backed reply mailbox at
help@thesupportcare[.]comsits behind every sending subdomain, separating the human-facing inbox from the bulk-send tiers. - Recipient personalization (first name, full postal address, and a fabricated order number) points to a purchased or breached list that survived every infrastructure change.
Background
Package-delivery lures were the most-reported text scam of 2024 according to the FTC, and the email variant follows the same script: a message claims a delivery problem, then pushes the recipient to a lookalike carrier or store site that collects card data under a small fee. The pretext works because most people have an order in flight at any given time, the manufactured friction (a final attempt, a customs hold, a blocked road) creates urgency, and a small charge draws far less scrutiny than a large one. This operator sharpens the effect with recipient personalization: a first name in the subject line and a full postal address in the body read as authentic carrier data.
The operator does not impersonate a real carrier or retailer. "LUMEN" (and the earlier "AURORA SALE") is a brand it invented, which sidesteps the trademark-abuse signals a squatted brand would trip while still sounding like a real e-commerce name. There is no legitimate LUMEN merchant in this product space, and independent trust scanners rate the store domain at roughly one percent, with public complaints quoting the exact delivery-failure lure.
A few pieces of infrastructure recur in this campaign and are worth naming for defenders who do not see them daily:
- Amazon SES and Elastic Email are legitimate bulk-email services. Mail routed through them inherits trusted sending IPs and authenticates cleanly, so a reputation filter cannot block the source without harming every other tenant. The operator's own sending domain, not the provider, is the actionable indicator.
- Shopify hosts the fake store. Every Shopify storefront serves static assets from the platform CDN under the path
<domain>/cdn/shop/files/..., so a logo reference likehxxps://lumenpick[.]com/cdn/shop/files/lumen.pngreveals that the "brand" is a spun-up Shopify store, cheap to stand up and easy to rotate. - Tracking-redirect subdomains such as
tracking.thesupportcare[.]commimic the click-analytics hosts that real senders use. The operator runs its own, hides the real destination in a?url=or base64 parameter, and can swap the target without touching the email. - Full SPF, DKIM, and DMARC PASS is not exculpatory. Authentication proves only that the message was authorized by whoever controls the sending domain. An attacker who registers a throwaway domain will publish valid records and pass every check.
Discovery and Infrastructure
The campaign surfaced from a routine review of authenticated delivery mail that read as scam-like. Expanding on the shared sending apex pulled in a trio of sibling subdomains, and a lure-template and CTA-shape sweep then surfaced an older generation on a second apex. The two generations share a brand, a lure, and a reply mailbox, but sit on entirely separate registration and sending stacks, which is the signature of a deliberately disposable model.
| Indicator | Role | Notes |
|---|---|---|
thesupportcare[.]com |
Email and tracking apex (gen-2) | Tucows, registered 2026-03-09, WHOIS redacted |
lumenpick[.]com |
Fake Shopify store, payment funnel (gen-2) | Tucows, registered 2026-03-24, web-confirmed fake store |
checkoutonlinedeal[.]com |
Email and tracking apex (gen-1) | Namecheap, registered 2025-01-18, aged-stash apex |
lumensale[.]com |
Fake Shopify store (gen-1) | Namecheap, registered 2026-02-11, same logo asset |
How It Works
The contact chain is short and consistent across both generations. The operator sends from an authenticated subdomain using a display name of LUMEN or LUMEN SALE. The subject carries the recipient's first name and a delivery-status claim, and the body repeats the first name, the full postal address, a fabricated alphanumeric order number, and a small dollar total in the $25 to $63 range. The lure walks a real carrier lifecycle, from "order prepared" through "in transit" to "out for delivery," and then introduces a friction event: a road restriction, a customs check, blocked building access, or a package left with a neighbor.
Each call to action points at an operator-owned tracking host rather than the store directly. That host issues a redirect (a nested ?url= chain or a base64-encoded parameter) into the fake Shopify store, where a checkout page requests a modest redelivery, customs, or processing fee. Paying it exposes the card and books a real charge for goods that never arrive. A separate "support reply" variant poses as a response to the victim's own support request and links to an order-confirmation funnel, which lends the exchange a veneer of ongoing correspondence.
Sample Lures
All samples below are attacker-side content only. Every recipient identifier has been replaced with a placeholder, and all domains are defanged.
Gen-2 delivery-friction lure (Amazon SES tier into the LUMEN store):
From: "LUMEN" <info@mail.thesupportcare[.]com>
Reply-To: help@thesupportcare[.]com
Subject: [recipient first name], delivery attempted - road restrictions
Road restrictions due to a local event. Your package is being held at the
depot and will be re-dispatched shortly. Your order shipping status has
been updated:
Order Number: [order #]
Total: USD 25.97
Delivery Address: [recipient street address]
[logo: hxxps://lumenpick[.]com/cdn/shop/files/lumen.png]
Resolve delivery: hxxps://tracking.thesupportcare[.]com/api/t/<uuid>/click?url=hxxps://pay.lumenpick[.]com
Gen-1 "delivered to a neighbor" variant (Elastic Email tier):
From: "LUMEN" <cart@mail.checkoutonlinedeal[.]com>
Return-Path: <bounce@bounces.elasticemail[.]net>
Subject: [recipient first name], your order has been delivered to a neighbor
Track your delivery:
hxxp://tracking.mail.checkoutonlinedeal[.]com/tracking/click?...
Fake support-reply posture:
From: "The Support Care" <info@em.thesupportcare[.]com>
Subject: Re: [recipient first name], your support request for your order [order #] from LUMEN
Confirm your order:
hxxp://order.thesupportcare[.]com/confirmation/[recipient email]
Technical Analysis
A Two-Generation, Two-Registrar, Two-ESP Model
The operator runs the same operation on two independent infrastructure stacks. Generation one lives on Namecheap and sends only through Elastic Email. Generation two moves to Tucows and adds Amazon SES alongside continued Elastic Email use, spreading delivery across two providers. Each generation pairs one email-and-tracking apex with one fake Shopify store, and the store rotates with the generation: lumensale[.]com gave way to lumenpick[.]com, both serving the identical logo asset.
| Apex | Registrar | Created | Cohort | Gen | Role |
|---|---|---|---|---|---|
checkoutonlinedeal[.]com |
Namecheap | 2025-01-18 | Aged stash | 1 | Email and tracking apex |
lumensale[.]com |
Namecheap | 2026-02-11 | Purpose-built 2026 | 1 | Fake Shopify store |
thesupportcare[.]com |
Tucows | 2026-03-09 | Purpose-built 2026 | 2 | Email and tracking apex |
lumenpick[.]com |
Tucows | 2026-03-24 | Purpose-built 2026 | 2 | Fake Shopify store |
Subdomain Grammar and Sending Tiers
The subdomain layout follows a strict role-then-tier-then-apex grammar. A function token (mail, m1, em, tracking, order, pay, checkout) prefixes the apex, and where the operator wants to separate ESP tiers it stacks a second token, as in tracking.m1. and tracking.mail.. Each ESP tier carries its own bounce fingerprint: the SES tier uses a send.mail. return-path, the Elastic Email tiers use m1. and mt76.em. MTAs.
| Host | Role | Tier | Gen |
|---|---|---|---|
mail.thesupportcare[.]com |
Sending subdomain | Amazon SES (send.mail.) |
2 |
m1.thesupportcare[.]com |
Sending subdomain | Elastic Email (m1.) |
2 |
em.thesupportcare[.]com |
Sending subdomain | Elastic Email (mt76.em.) |
2 |
tracking.thesupportcare[.]com |
Click tracker | /api/t/<uuid>/click?url= |
2 |
tracking.m1.thesupportcare[.]com |
Click tracker | /tracking/click?d=<base64> |
2 |
order.thesupportcare[.]com |
Order-confirmation funnel | /confirmation/<recipient> |
2 |
pay.lumenpick[.]com |
Checkout, card capture | Payment endpoint | 2 |
checkout.lumenpick[.]com |
Checkout | Payment funnel | 2 |
mail.checkoutonlinedeal[.]com |
Sending subdomain | Elastic Email | 1 |
tracking.mail.checkoutonlinedeal[.]com |
Click tracker | /tracking/click?... |
1 |
The Shopify Logo Path as a Cross-Generation Fingerprint
The strongest thread tying the two generations together is not a domain, it is an asset path. Both lumenpick[.]com and lumensale[.]com reference the same logo at /cdn/shop/files/lumen.png. That path only exists because both stores are stock Shopify builds carrying the same brand image, and it appears inside the email body as the rendered logo, which makes it observable at the message layer without visiting the store. A defender who keys on the /cdn/shop/files/<brand>.png reference in a delivery-themed message catches the operator across store rotations that a domain blocklist would miss.
Click-Tracker Redirect Grammar
The tracking layer uses two interchangeable redirect grammars. The first nests the real destination in a plaintext ?url= parameter, sometimes chaining one tracking host to another before landing on pay.lumenpick[.]com. The second base64-encodes the destination in a ?d= parameter. Both live on an operator-owned tracking.<domain> host that resembles ordinary email click-analytics, and both let the operator retarget the redirect without editing the email that has already shipped. Per-recipient UUIDs in the first grammar also let the operator confirm who clicked.
Registration Cohorts and Aged-Domain Staging
Three of the four apexes form a tight purpose-built 2026 batch: lumensale[.]com in February, thesupportcare[.]com on March 9, and lumenpick[.]com on March 24, each registered weeks before it went live. The outlier is checkoutonlinedeal[.]com, registered on 2025-01-18, roughly a year before the campaign began, an aged-stash apex held in reserve. Registrar cleanly tracks generation: both Namecheap apexes are generation one, both Tucows apexes are generation two, and all four carry privacy-shielded WHOIS. The naming vocabulary is theme rotation rather than typosquatting: the mail apexes use commerce-neutral tokens (*deal, *care, support*) that read as plausible mailbox names, while the stores cycle one brand root through interchangeable verb suffixes (lumen plus pick or sale).
The Reply-Mailbox Split
The bulk-send subdomains are wired for volume, but the human-facing reply address is not. Every message routes replies to help@thesupportcare[.]com, and that apex publishes an SPF record that includes _spf.protonmail.ch, a ProtonMail domain-verification record, and a DMARC policy of p=quarantine. The operator keeps its readable inbox on a privacy-focused consumer mail provider while blasting outbound lures through commercial ESPs, a split that separates the mailbox a victim might reply to from the throwaway sending tiers.
Detection Observations
The campaign's traffic separates from legitimate delivery mail on a handful of behavioral signals rather than on any single indicator:
- A delivery-themed message whose rendered logo loads from a Shopify
/cdn/shop/files/<brand>.pngpath, for a brand with no real merchant presence, is a strong fake-store tell. - Calls to action that route through a
tracking.<domain>host and hide the destination in a?url=or base64 parameter, on a domain registered within the last few months, combine two weak signals into one strong one. - Carrier-lifecycle subject grammar (the progression through prepared, in transit, out for delivery, and a friction event) paired with recipient PII personalization is distinctive when the sending domain belongs to no known carrier or retailer.
- A centralized reply-to mailbox that is unrelated to the sending subdomains, especially one on a consumer privacy-mail provider, is an operator convenience that shows up consistently across otherwise-rotated infrastructure.
- Full email authentication on a young, brand-neutral domain is expected here and should carry no reassurance on its own.
Indicators of Compromise
All indicators below are defanged. Recipient data has been removed.
Senders
| Value | Role | Notes |
|---|---|---|
info@mail.thesupportcare[.]com |
Sender | Gen-2, Amazon SES tier |
info@m1.thesupportcare[.]com |
Sender | Gen-2, Elastic Email tier |
info@em.thesupportcare[.]com |
Sender | Gen-2, support-reply posture |
cart@mail.checkoutonlinedeal[.]com |
Sender | Gen-1, Elastic Email |
Domains
| Value | Role | Notes |
|---|---|---|
thesupportcare[.]com |
Email and tracking apex | Tucows, 2026-03-09 |
checkoutonlinedeal[.]com |
Email and tracking apex | Namecheap, 2025-01-18 |
lumenpick[.]com |
Fake store, payment funnel | Tucows, 2026-03-24 |
lumensale[.]com |
Fake store | Namecheap, 2026-02-11 |
Hosts
| Value | Role | Notes |
|---|---|---|
mail.thesupportcare[.]com |
Sending subdomain | SES send.mail. |
m1.thesupportcare[.]com |
Sending subdomain | Elastic Email |
em.thesupportcare[.]com |
Sending subdomain | Elastic Email mt76.em. |
tracking.thesupportcare[.]com |
Click tracker | /api/t/<uuid>/click?url= |
tracking.m1.thesupportcare[.]com |
Click tracker | /tracking/click?d=<base64> |
order.thesupportcare[.]com |
Order-confirmation funnel | /confirmation/<recipient> |
pay.lumenpick[.]com |
Checkout, card capture | Payment endpoint |
checkout.lumenpick[.]com |
Checkout | Payment funnel |
tracking.mail.checkoutonlinedeal[.]com |
Click tracker | Gen-1 |
URLs
| Value | Role | Notes |
|---|---|---|
hxxps://tracking.thesupportcare[.]com/api/t/<uuid>/click?url= |
CTA redirect | Nested ?url= chain |
hxxps://tracking.thesupportcare[.]com/tracking/<order> |
CTA redirect | Order-keyed tracker |
hxxp://tracking.m1.thesupportcare[.]com/tracking/click?d=<base64> |
CTA redirect | Base64 destination |
hxxp://order.thesupportcare[.]com/confirmation/<recipient> |
Funnel | Support-reply variant |
hxxps://lumenpick[.]com/cdn/shop/files/lumen.png |
Logo asset | Cross-generation fingerprint |
MITRE Fight Fraud Framework Mapping
The mapping below aligns to the MITRE Center for Threat-Informed Defense fraud matrix (https://ctid.mitre.org/fraud). That matrix now ships as the Fight Fraud Framework, whose tactic names differ from earlier drafts, so this table uses the current tactic vocabulary and cites ATT&CK technique identifiers only where a technique applies with confidence. Verify any specific fraud-technique identifier against the live matrix before reuse.
| Tactic | Observed behavior | Reference |
|---|---|---|
| Reconnaissance | Gather victim identity information (first name, full postal address) | ATT&CK T1589 |
| Resource Development | Acquire infrastructure: throwaway domains, Shopify store, ESP accounts | ATT&CK T1583, T1585 |
| Initial Access | Phishing via fake delivery-notification email | ATT&CK T1566 |
| Initial Access | Impersonation of a delivery brand and support persona | ATT&CK T1656 |
| Stealth | Authenticated sending domains and tracking-redirect obfuscation | Behavioral |
| Execution | Fake checkout captures payment-card data | Behavioral |
| Monetization | Fraudulent redelivery-fee charge and card resale | Behavioral |
Conclusion
The LUMEN operator treats infrastructure as disposable and brand as durable. Domains, registrars, and email providers all changed across two generations, yet the fabricated brand, the carrier-lifecycle lure, the Shopify logo asset, and the personalized contact list stayed constant. That is where defenders should watch: the message-layer fingerprints that survive rotation, particularly the Shopify CDN logo path and the tracking-redirect grammar, will identify the next store apex faster than waiting for a fresh domain to earn a bad reputation. Expect another lumen-rooted store and a matching sending tier to follow the ones burned here.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.