A Deposit That Was Never Coming: Inside a 56-Domain Lead-Gen Estate
A Deposit That Was Never Coming: Inside a 56-Domain Lead-Gen Estate
An email from a bank you have never heard of says a deposit is pending. Behind it sit 56 domains, one hosting account, and a single affiliate offer. "CenterNational" wants you to confirm your e-deposit. So does "LayComp", and "SayUnited", and "ChoseAmerican", and "NStarGroup". None of them is a bank. None of them is anything. The name in the From line is a word invented to match a domain the operator bought at auction, and the deposit it is writing to you about does not exist and never did. What does exist is a form at the end of the click, and a buyer waiting to pay for whatever you type into it.
Key Takeaways
- The lure is a fabricated institution rather than an impersonated one. There is no real bank to compare it against and no lookalike domain to spot, because the wordmark was invented to match a domain bought at auction rather than copied from a real brand.
- No credentials are harvested anywhere in the chain. The click is the product. It resolves to a one-button page advertising up to $40,000 and hands the visitor to an affiliate network with a per-domain tracking tag, which makes this lead generation wearing a phishing costume.
- The estate is bound by four independent infrastructure signals and by none of its email copy. The decisive one is a sequential click-ID space: identifiers are issued centrally, so the same six-character prefix appears on unrelated domains within the same day.
- Each apex runs two surfaces. The homepage is a complete lead-generation site with a real lending-network form embed and genuine advertising disclosures. The deceptive page sits elsewhere on the same domain and is reachable only through the email's tracking link. Checking the apex tells you nothing.
- The operator buys domain age selectively. The operator spends real money at auction only for the arm that has to look like an established institution, with registration dates reaching back to 1997. The arm that advertises loans openly runs on cheap registrations from 2019 onward.
- One of these domains carries a leftover comment from the site builder in its shipped HTML, describing what will happen "once the site is live on the network-approved domain". The facade is a template, deployed at volume.
Background
Consumer lending lead generation is a real and large industry. Somebody fills in a form asking to borrow $2,000, and that record is auctioned in real time to lenders, banks, and other brokers through what the trade calls a ping tree. The lead is worth money whether or not a loan is ever made, which puts steady pressure on the front of the pipeline to produce form-fills by whatever means work.
Regulators have been pulling on that thread for a decade. In September 2017 the Consumer Financial Protection Bureau settled with Zero Parallel LLC, a Glendale lead aggregator, over selling loan applicant leads to lenders it knew would issue loans void under state law; the company paid $100,000 and its owner paid $250,000. In January 2022 the Federal Trade Commission announced a $1.5 million penalty against ITMedia Solutions over hundreds of sites that collected Social Security and bank account numbers under the pretext of matching consumers to lenders, then sold the data predominantly to marketing companies.
The operation described here sits at the very front of that pipeline and solves the acquisition problem in a specific way. It does not build a quote site and wait. It starts from a list, invents a bank, and tells the people on that list that money is already waiting for them.
A few pieces of infrastructure recur below and are worth defining first.
Ping trees auction a single consumer lead down a ranked list of buyers in real time. The first buyer to accept at their bid price gets the record, which is why a lead's value depends on how complete and how fresh it is.
Per-tenant tracking domains are ordinary marketing practice. A tracking platform has each customer point a subdomain such as go.<customer-domain> or trk.<customer-domain> at the platform, so clicks appear to originate from the customer's own brand. It helps deliverability, and it also means every click can be logged and rewritten by a host the customer controls.
Expired domain acquisition is a market. Domains that lapse are auctioned, and buyers pay for the reputation, backlinks and age the previous owner accumulated. Google formalised the abuse case in a March 2024 spam policy covering "expired domain abuse", where a lapsed domain is repurposed to exploit trust it did not earn.
Discovery and Infrastructure
The estate presents as a set of unremarkable American-sounding company domains. Each one sends mail, each one hosts a website, and each one carries a tracking host on a short subdomain.
| Apex | Tracking host | Sending identity |
|---|---|---|
centernational[.]com |
cent.centernational[.]com |
CenterNational |
laycomp[.]com |
lay.laycomp[.]com |
LayComp |
sayunited[.]com |
unit.sayunited[.]com |
SayUnited |
robinunited[.]com |
robin.robinunited[.]com |
RobinUnited |
yearlater[.]com |
year.yearlater[.]com |
YearLater |
choseamerican[.]com |
cam.choseamerican[.]com |
ChoseAmerican |
nstargroup[.]com |
star.nstargroup[.]com |
NStarGroup |
uniquelyliving[.]com |
uni.uniquelyliving[.]com |
UniquelyLiving |
Every message passes SPF, DKIM and DMARC, because the operator owns the domains and configured the DNS properly. Authentication here is working exactly as designed and tells you nothing about whether the sender is honest.
What binds these domains is not visible in the mail. Request the root of any tracking host and it answers with a version banner:
{"applicationName":"EmailElement.Tracking.Api","applicationVersion":"1.0.0.0"}
The same application, the same version, on every one. EmailElement is a real commercial email marketing platform, so this identifies the tooling rather than incriminating it, and whether these are self-managed deployments or per-tenant instances of the vendor's service cannot be determined from outside. Either reading points the same direction: one account or one install, serving domains that otherwise present as unrelated companies.
The second signal is in the page tier. Every apex page carries the same hosting telemetry in its footer, naming one shared hosting account and one server. Dozens of nominally separate companies turn out to share a single control panel login.
The third signal is the one that settles it. Every click path has the shape /f/lk followed by 32 base36 characters, and those identifiers are issued sequentially by whatever is generating them. That means the leading characters encode roughly when the link was minted, and links minted around the same moment share a prefix regardless of which domain they were destined for.
| Click-ID prefix | Date | Distinct apexes carrying it |
|---|---|---|
lk77gc31… |
2026-08-10 | 6 |
lk77m1kh… |
2026-08-08 | 6 |
lk77kjod… |
2026-08-07 | 6 |
lk6fhoh5… |
2026-07-04 | 3 |
lk6r7sg3… |
2026-07-15 | 3 |
Grouping by that prefix turns a pile of similar-looking domains into a measured estate. Across a ten-week window, 56 apexes drew from the same identifier sequence.
The fourth signal is the destination. Every landing page ends at the same affiliate offer, on the same network, with the same campaign identifier. The only thing that varies is a sub1= parameter carrying the name of whichever domain delivered the visitor, so the operator can see which of its costumes converts best.
How It Works
The email arrives with the recipient's first name in the subject and a bank-sounding wordmark in the From display. The subject asserts a financial event: a deposit is pending, is ready, needs confirmation, can be accessed. Later messages in the run date-stamp the claim, which manufactures urgency out of nothing at all.
The link goes to the tracking host on the sender's own domain, which logs the click and forwards with a 302. The visitor lands on a page on the apex, and here is where the deception becomes concrete:
Loan Request Notice
[logo image]
Your loan request is ready for you.
Your loan request is prepared and waiting for your confirmation.
Confirm it now to continue.
Amount available up to $40,000 [Ready]
[ Confirm Your Loan ]
The framing does a specific job. The visitor never requested a loan, but the page tells them their request is "ready" and "waiting for your confirmation", converting a cold recipient into someone who believes they are resuming something they started. The $40,000 figure and the Ready badge do the rest.
That page is not the apex homepage. The homepage of the same domain is a full lead-generation site with a nationwide-lender pitch, an FAQ, a rates and fees page, a real lending-network form embed and a properly worded advertising disclosure explaining that the operator is a for-profit advertising network paid referral fees. Anyone who looks up the domain sees that site. The page the email actually points at is a separate file, and it makes none of the same disclosures.
The logo on the deceptive page is hotlinked from a legitimate financial comparison site, loaded live from that company's image CDN. The company has no involvement in any of this and appears to be unaware its brand asset is being served into a scam funnel.
Clicking through hands the visitor to the affiliate network, and from there into the lending ping tree, where their details are auctioned.
Sample Lures
All recipient identifiers are redacted. Bracketed placeholders mark where personal data appeared in the original messages.
Fabricated bank asserting a pending deposit:
From: "CenterNational" <[firstname]@centernational[.]com>
Subject: Your e-deposit status update, [recipient first name]
Account Update
Hi [recipient first name],
We just completed the review for your pending e-deposit. Your next
step is still pending. Confirm your details to release it.
[ View your e-deposit ]
hxxps://cent.centernational[.]com/f/lk[32-char identifier]
The same template, date-stamped to manufacture freshness:
From: "CenterNational" <[firstname]@centernational[.]com>
Subject: Confirm your August 5th deposit [recipient first name]
A second wordmark on the same platform, same pretext, different domain:
From: "LayComp" <[firstname]@laycomp[.]com>
Subject: Action required: confirm your deposit [recipient first name]
Account Update
Hi [recipient first name],
Your deposit can be accessed once you verify your status.
[ Verify deposit status ]
hxxps://lay.laycomp[.]com/f/lk[32-char identifier]
The role-account variant, which drops name rotation but keeps the pretext:
From: "UnifiedIndustry" <info@unifiedindustry[.]com>
Subject: [recipient first name], your e-Deposit status is ready
hxxps://go.unifiedindustry[.]com/f/lk[32-char identifier]
Technical Analysis
Two arms, one platform
The estate runs two sending styles off the same click-ID sequence. One rotates dozens of first-name mailboxes per domain behind a fabricated bank wordmark. The other uses a single role account and advertises loans openly. They are not separate operations: their click identifiers interleave, with a single July prefix appearing on two fabricated-bank domains and one openly loan-branded domain on the same day.
| Arm | Sending identity | Mailbox convention | Pretext |
|---|---|---|---|
| Fabricated institution | Coined bank wordmark matching the apex | Dozens of rotating first-name localparts | "Your pending e-deposit needs confirming" |
| Overt lending | Company name matching the apex | One role account (info@, services@, support@) |
e-Deposit and funding-status subjects |
Rotation is the evasion mechanism in the first arm. Spreading a send across dozens of addresses keeps the volume behind any single sender low enough to stay unremarkable, and the pool is deep: one domain alone cycles through 31 distinct first-name mailboxes.
Registration cohorts, and where the money goes
Registrar and creation-date data splits the two arms cleanly, and the split is the most interesting thing in the dataset. Aged domains cost real money at auction. The operator spends it in exactly one place.
| Arm | Registrar profile | Creation dates | Examples |
|---|---|---|---|
| Fabricated institution | GoDaddy, acquired at auction | 1997 to 2021 | nstargroup[.]com (1997), sayunited[.]com and laycomp[.]com (2000), centernational[.]com (2002), igsnational[.]com (2008), theunigroup[.]com (2010) |
| Overt lending | Namecheap, Amazon, Cloudflare | 2019 to 2026 | volkerfunding[.]com (2019), honestfunds365[.]com (2020), lend-afriend[.]com (2023), tadahloans[.]com (2024), badcreditlending[.]net (2025), perryfunds[.]com and inversafunds[.]com (2026) |
The logic is straightforward once you see it. A domain claiming to be a decades-old bank has to survive the most casual sanity check, and a 1997 registration date is the cheapest way to buy that. A domain that says plainly it will match you with lenders is making no such claim about its own history, so that arm runs on registrations bought this year. The 2026 entries also show the estate is still being extended.
The practical consequence for defenders is a trap worth naming: domain age is an arm signature here, not a platform signature. Testing estate membership by "is it an aged GoDaddy domain" would confirm the fabricated-bank arm and miss the newer half entirely.
Subdomain grammar
Tracking hosts follow a compressed-abbreviation convention derived from the apex, which produces a recognizable but deliberately unmemorable set.
| Pattern | Examples |
|---|---|
| Truncation of the apex | cent.centernational, lay.laycomp, uni.uniquelyliving, year.yearlater |
| Initialism of the apex | cam.choseamerican, igsn.igsnational, tct.thecashtree |
| Semantic fragment | unit.sayunited, star.nstargroup, robin.robinunited |
| Generic tracker label | go., trk. on later additions |
The drift toward generic go. and trk. labels on the newest domains is worth noting, because those labels are indistinguishable from the per-tenant tracking hosts that legitimate newsletters and retailers use. The subdomain prefix on its own is not an indicator and never was.
Layer separation
The two surfaces on each domain sit on different infrastructure, which is why examining one tells you nothing about the other.
| Surface | Hosting | Content |
|---|---|---|
Tracking host (<label>.<apex>) |
Cloudflare-fronted | Click logger, 302 forwarder, version banner at root |
| Apex pages | One shared hosting account across the whole estate | Facade lead-gen site plus the separate deceptive interstitial |
A reputation check on the apex finds a compliant lending site. A reputation check on the tracking host finds a redirector. Only following the actual link in the actual email connects them, and that is the point of the arrangement.
What does not bind the estate
Worth stating explicitly, because each of these was checked and discarded. Registrar does not bind it, since four registrars are in play. Creation date does not bind it, spanning 1997 to 2026. Hosting does not bind the tracking tier, which sits behind a CDN. Email authentication does not bind it, because every domain authenticates cleanly and independently. The email copy is the weakest signal of all: the deposit-confirmation phrasing is generic enough that convergence proves nothing, and treating it as attribution is how unrelated actors get merged into one imaginary operator.
Two things bind it. The click-ID sequence, and the shared page-tier hosting account. Everything else in this report was found by following those.
Detection Observations
Behavioral signals that separate this traffic from legitimate lending mail:
- A financial-event assertion with no prior relationship. The message states that a specific deposit exists and is pending. Legitimate lead-generation mail advertises an opportunity. It does not claim an account event has already happened.
- The sender wordmark matches the apex wordmark, and no financial institution by that name exists in any regulatory register. The pairing itself is the signal.
- Dozens of human first names used as mailbox localparts on one domain, each carrying low volume, is a sending pattern with essentially no legitimate analogue at this ratio.
- The link target and the disclosure surface are different pages on the same domain. Where a homepage carries advertising disclosures but the emailed link points at a separate page making none, the domain is worth treating as one unit of analysis rather than two.
- A shared sequential identifier space across unrelated domains. Where a click-tracking identifier is minted centrally, prefix collisions across supposedly unrelated senders on the same day are strong evidence of a common account, and this generalises well beyond one operator.
- Brand imagery hotlinked live from a company with no relationship to the sender. For the company whose CDN is serving it, that is also a detectable abuse of its own assets.
Indicators of Compromise
Representative subset, defanged. Full indicator sets are shared through established channels.
Sender domains
| Domain |
|---|
centernational[.]com |
laycomp[.]com |
sayunited[.]com |
robinunited[.]com |
yearlater[.]com |
choseamerican[.]com |
nstargroup[.]com |
uniquelyliving[.]com |
igsnational[.]com |
unifiedindustry[.]com |
uprofessional[.]com |
opportunityadvisers[.]com |
theunigroup[.]com |
sayamerican[.]com |
thecashtree[.]com |
Tracking hosts
| Host |
|---|
cent.centernational[.]com |
lay.laycomp[.]com |
unit.sayunited[.]com |
robin.robinunited[.]com |
year.yearlater[.]com |
cam.choseamerican[.]com |
star.nstargroup[.]com |
uni.uniquelyliving[.]com |
igsn.igsnational[.]com |
go.unifiedindustry[.]com |
trk.uprofessional[.]com |
trk.opportunityadvisers[.]com |
go.theunigroup[.]com |
go.sayamerican[.]com |
tct.thecashtree[.]com |
Sender addresses
| Address |
|---|
amelia@centernational[.]com |
sebastian@centernational[.]com |
natalie@centernational[.]com |
scarlett@laycomp[.]com |
emersyn@laycomp[.]com |
zachary@laycomp[.]com |
ezekiel@sayunited[.]com |
thaddeus@sayunited[.]com |
landon@yearlater[.]com |
beatrice@choseamerican[.]com |
info@unifiedindustry[.]com |
services@uprofessional[.]com |
| … (representative subset; 250+ verified-malicious sender addresses) |
Structural indicators
| Indicator | Value |
|---|---|
| Tracking application banner | EmailElement.Tracking.Api version 1.0.0.0 at host root |
| Click path shape | /f/lk + 32 base36 characters |
| Landing page filenames | view-more-info.html, amount-info.html, pending-amount-details.html |
| Affiliate tag convention | ?sub1=<apex-without-tld> |
MITRE Fight Fraud Framework Mapping
Mapping aligns to the MITRE Fight Fraud Framework (F3) v1.1, https://ctid.mitre.org/fraud. F3 is scoped largely to post-access fraud behavior, so a pre-access lead-acquisition operation maps only partially; unmapped stages are noted rather than forced.
| F3 Tactic | Technique | ID |
|---|---|---|
| Resource Development (TA0042) | Acquire Infrastructure: Domains | T1583.001 |
| Resource Development (TA0042) | Create Fake Materials: Fake Website | F1020.002 |
| Initial Access (TA0001) | Phishing | T1660 |
| Stealth (TA0005) | Impersonate Official | F1032 |
| Reconnaissance (TA0043) | Gather Customer Information | F1029 |
Monetization via lead resale into an affiliate auction has no discrete F3 technique, and no row is offered for it. The framework's coverage of this stage is partial by design, as noted above.
F1032 is applied here to a fabricated financial institution rather than an impersonated real one, which stretches the technique's usual reading. It is included because the observed behavior is presenting as a financial authority the recipient is expected to trust; readers mapping strictly may prefer to treat that row as behavioral.
Conclusion
The interesting thing about this operation is not that it is sophisticated, because it is not. The emails are plain, the landing page is one button, and the whole estate runs off a single hosting login. What makes it durable is that it is built to survive the checks people actually perform. Look up the domain and you find a compliant lending site with real disclosures. Check authentication and everything passes. Search for the bank and there is no real brand to compare against, because the bank was invented to match a domain that came up at auction.
The thing that broke it open was an incrementing number. The operator centralised click-ID generation across every domain it owned, which meant links minted the same day carried the same prefix no matter which costume they shipped under. That single implementation detail converted a set of plausibly-unrelated companies into one measured estate of 56 domains, and it is worth remembering the next time a group of domains looks related but nothing in the registration or hosting data will say so.
Two practical notes for anyone chasing something similar. Attribute on the parts of the infrastructure the operator had to centralise to run the business, not on the copy, which converges by accident. And when a domain has more than one surface, decide which one you are judging, because here the honest page and the dishonest page live on the same host and only one of them is ever linked.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.