Tech

Researchers Intercept Corporate Data Leaks via Purchased 'No Reply' Domains

Since late 2024, automated systems from thousands of organisations have sent sensitive personal and business data to domains such as noreply.net and deleteduser.com, prompting urgent calls for better system auditing.

Author
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: WIRED · original
Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All
Security experts Cory Solovewicz and Mike Sheward have turned generic email addresses into accidental honeypots, revealing widespread corporate misconfigurations.

Security researchers Cory Solovewicz and Mike Sheward have exposed a significant vulnerability in corporate communication systems, where organisations inadvertently send sensitive data to generic, unmonitored email domains. By purchasing placeholder addresses such as noreply.net, noreply.us, and deleteduser.com, the researchers have intercepted hundreds of thousands of automated messages containing personal and corporate information. The initiative, detailed in a report from WIRED, highlights how widespread system misconfigurations are leaking customer and employee data.

Solovewicz, a security researcher and consultant, has received 401,796 messages on noreply.net since December 2024, averaging nearly 700 pings per day. The data includes injury reports from city governments, pizza order confirmations, and account setup credentials from school platforms. He purchased noreply.net in 2024 and noreply.us in 2020, originally intending to use the latter as a privacy filter. Instead, he created an accidental honeypot, noting that many companies send emails to these addresses believing they are unmonitored or will bounce.

Mike Sheward, head of security at EV charging company Xeal, purchased the domain deleteduser.com for approximately $15 earlier this year. Within the first hour, he received emails from at least three organisations, and has since intercepted thousands of messages from over 100 different entities. The data received by Sheward includes vacation approvals, hotel bookings with full names, and Zoom meeting invitations from a UK government agency. He also reported receiving CCTV stills from an AI company monitoring industrial sites in the Middle East for safety protocol violations.

The scale of the issue is substantial, with emails originating from more than 14,000 from addresses across 6,200 root domains. In the month prior to Solovewicz presenting his findings at the Defcon security conference, the combined domains received more than 11,000 messages. Solovewicz has scanned 7,136 potential placeholder domains and identified 328 with catch-all inboxes configured, suggesting the problem extends far beyond the specific domains he owns.

Both researchers have purchased more than 30 domains in total to prevent malicious actors from exploiting these misconfigurations. They are actively alerting affected organisations to fix their systems, warning that the data could be easily harvested by hackers or extortionists. While some companies have quietly corrected their errors, many have not responded, underscoring the need for rigorous internal auditing to prevent the leakage of sensitive information.

Continue reading

More from Tech

Read next: Open-source tool claims 97 per cent token savings for AI agents
Read next: Valvoline Unveils August 2026 Promotional Offers for Service and Retail Buyers
Read next: Developer Antirez releases native MiniMax H3 inference engine for Apple Silicon