All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Researcher's "noreply" domains reveal corporate data leaks

Created at 10 Aug · 2:31 PM1 source↑ Market-relevant
IN SHORT

A security researcher bought domains like noreply.net and noreply.us, inadvertently creating a honeypot for sensitive corporate information. Companies are sending private data, test credentials, and internal documents to these unmonitored addresses, highlighting significant security misconfigurations.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

401,796messages received by noreply.net since December 2024
699.99average pings per day to noreply.net
2020year Solovewicz purchased noreply.us
2024year Solovewicz purchased noreply.net
400,000messages received by noreply.net over 1.5 years
28,365noreply.net messages with attachments
37,255messages sent to noreply.us since 2020
11,000combined messages received in the month before Defcon talk
14,000unique 'from' addresses sending emails
6,200root domains sending emails
15dollars spent by Mike Sheward on deleteduser.com
30domains purchased by both researchers combined
7,136domains scanned by Solovewicz
328domains identified with catch-all inboxes

Who's Involved

Cory Solovewicz
Security researcher and owner of noreply.net and noreply.us
Mike Sheward
Head of security at EV charging company Xeal and owner of deleteduser.com
Brian Krebs
Independent security journalist who previously reported on similar issues
Researcher's "noreply" domains reveal corporate data leaks

↳ Why This Matters

This situation highlights a widespread and critical cybersecurity vulnerability where companies are inadvertently leaking sensitive data by sending it to unmonitored 'noreply' or placeholder email addresses. The findings underscore the urgent need for organizations to audit their email systems and data handling practices to prevent potential misuse by malicious actors.

Key facts

  • Security researcher Cory Solovewicz owns noreply.net and noreply.us, which receive thousands of unsolicited emails daily.
  • These emails contain sensitive corporate information, including employee data, test credentials, and private customer details.
  • Companies are sending this data because they misconfigure their systems or use placeholder domains as digital trash cans.
  • Solovewicz and another researcher, Mike Sheward, have purchased multiple domains to prevent malicious exploitation.
  • Solovewicz's research identified hundreds of domains configured with catch-all inboxes that could be vulnerable.
  • Both researchers are attempting to notify affected companies to fix their security misconfigurations.

Security researcher Cory Solovewicz has inadvertently created a large-scale data leak by purchasing the domains noreply.net and noreply.us. Companies and organizations are sending sensitive information, including personal data, company secrets, and test credentials, to these domains, apparently believing they are unmonitored.

Solovewicz, who bought noreply.us in 2020 and noreply.net in 2024, has received hundreds of thousands of messages across these domains. He describes the situation as an accidental honeypot, where systems are configured to send emails to these placeholder addresses, potentially when employees leave a company or accounts are deleted.

He presented his findings at the Defcon security conference, aiming to alert businesses to these critical misconfigurations. Solovewicz emphasized that while he is relieved the data fell into his hands rather than malicious actors, the scale of the problem is significant and avoidable. He has been notifying affected companies, but many have not responded.

Another researcher, Mike Sheward, head of security at Xeal, has experienced similar issues after purchasing the domain deleteduser.com. He has received thousands of unintended emails from numerous organizations, including sensitive data like Viagra orders, vacation approvals, and meeting invitations from a UK government agency. Sheward noted that cybersecurity and Microsoft partner companies are among those sending data to such domains.

Both researchers have independently purchased over 30 domains to prevent malicious actors from replicating this approach. Solovewicz's ongoing research has identified hundreds of other domains configured with catch-all inboxes, suggesting the problem is widespread and potentially just the 'tip of the iceberg.' They urge companies to audit their systems and fix these vulnerabilities to protect customer and employee data.

Frequently asked questions

In this context, a honeypot is a security mechanism created by Solovewicz by registering domains like noreply.net. Companies inadvertently sending sensitive data to these domains are essentially 'trapped,' allowing the researcher to discover and report on their security flaws.

Companies may be using these domains as a default or 'catch-all' for emails that are not intended for direct human interaction, or when employee accounts are deleted. They likely assume these addresses are unmonitored and therefore safe for sending automated or less critical communications.

The leaked data includes injury reports from city governments, pizza orders, account setup emails from school platforms, service orders for repairs, test platform credentials, Viagra orders, work vacation approvals, hotel bookings, and meeting invitations from government agencies.

If this sensitive information falls into the wrong hands, it could be used for identity theft, corporate espionage, extortion, or other malicious activities, leading to significant financial and reputational damage for the affected organizations and individuals.

What Happens Next

01Affected companies are expected to audit their systems and fix misconfigured email practices.
02Solovewicz plans to continue his research into other potentially vulnerable placeholder domains.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

Researcher Cory Solovewicz purchased noreply.us in 2020 and noreply.net in 2024.
Companies began sending unsolicited emails containing private information and company secrets to these domains.
Solovewicz discovered he had created an accidental honeypot, receiving thousands of messages daily.
He presented his findings at the Defcon security conference, warning businesses of misconfigured systems.
Another researcher, Mike Sheward, bought deleteduser.com and experienced similar data leaks from organizations.
Both researchers have purchased additional domains to prevent malicious actors from exploiting the issue.
Solovewicz scanned thousands of domains and found many configured with catch-all inboxes.
They are notifying affected companies, but responses have been mixed.

Sources

T1
A researcher bought noreply.net. Companies started sending him secretsvar abtest_2166777 = new ABTest(2166777, 'impression');Ars Technica

Related Stories

Klaviyo data leak: Passwords shared with advertisers due to website bug
10 Aug · 2:36 PM
Companies Pour Billions into AI, Seeking Tangible Returns
10 Aug · 12:06 PM
UK manufacturers face rising hacking risk as survey shows 30% were hit last year
10 Aug · 5:16 AM
Waymo's rapid expansion is accompanied by an increase in operational glitches
10 Aug · 2:06 PM
China's Long March 7A rocket explodes shortly after launch
10 Aug · 3:11 PM