Key facts
- Security researcher Cory Solovewicz owns noreply.net and noreply.us, which receive thousands of unsolicited emails daily.
- These emails contain sensitive corporate information, including employee data, test credentials, and private customer details.
- Companies are sending this data because they misconfigure their systems or use placeholder domains as digital trash cans.
- Solovewicz and another researcher, Mike Sheward, have purchased multiple domains to prevent malicious exploitation.
- Solovewicz's research identified hundreds of domains configured with catch-all inboxes that could be vulnerable.
- Both researchers are attempting to notify affected companies to fix their security misconfigurations.
Security researcher Cory Solovewicz has inadvertently created a large-scale data leak by purchasing the domains noreply.net and noreply.us. Companies and organizations are sending sensitive information, including personal data, company secrets, and test credentials, to these domains, apparently believing they are unmonitored.
Solovewicz, who bought noreply.us in 2020 and noreply.net in 2024, has received hundreds of thousands of messages across these domains. He describes the situation as an accidental honeypot, where systems are configured to send emails to these placeholder addresses, potentially when employees leave a company or accounts are deleted.
He presented his findings at the Defcon security conference, aiming to alert businesses to these critical misconfigurations. Solovewicz emphasized that while he is relieved the data fell into his hands rather than malicious actors, the scale of the problem is significant and avoidable. He has been notifying affected companies, but many have not responded.
Another researcher, Mike Sheward, head of security at Xeal, has experienced similar issues after purchasing the domain deleteduser.com. He has received thousands of unintended emails from numerous organizations, including sensitive data like Viagra orders, vacation approvals, and meeting invitations from a UK government agency. Sheward noted that cybersecurity and Microsoft partner companies are among those sending data to such domains.
Both researchers have independently purchased over 30 domains to prevent malicious actors from replicating this approach. Solovewicz's ongoing research has identified hundreds of other domains configured with catch-all inboxes, suggesting the problem is widespread and potentially just the 'tip of the iceberg.' They urge companies to audit their systems and fix these vulnerabilities to protect customer and employee data.
