Researchers Intercept Corporate Data Leaks via Purchased 'No Reply' Domains
Since late 2024, automated systems from thousands of organisations have sent sensitive personal and business data to domains such as noreply.net and deleteduser.com, prompting urgent calls for better system auditing.

Security researchers Cory Solovewicz and Mike Sheward have exposed a significant vulnerability in corporate communication systems, where organisations inadvertently send sensitive data to generic, unmonitored email domains. By purchasing placeholder addresses such as noreply.net, noreply.us, and deleteduser.com, the researchers have intercepted hundreds of thousands of automated messages containing personal and corporate information. The initiative, detailed in a report from WIRED, highlights how widespread system misconfigurations are leaking customer and employee data.
Solovewicz, a security researcher and consultant, has received 401,796 messages on noreply.net since December 2024, averaging nearly 700 pings per day. The data includes injury reports from city governments, pizza order confirmations, and account setup credentials from school platforms. He purchased noreply.net in 2024 and noreply.us in 2020, originally intending to use the latter as a privacy filter. Instead, he created an accidental honeypot, noting that many companies send emails to these addresses believing they are unmonitored or will bounce.
Mike Sheward, head of security at EV charging company Xeal, purchased the domain deleteduser.com for approximately $15 earlier this year. Within the first hour, he received emails from at least three organisations, and has since intercepted thousands of messages from over 100 different entities. The data received by Sheward includes vacation approvals, hotel bookings with full names, and Zoom meeting invitations from a UK government agency. He also reported receiving CCTV stills from an AI company monitoring industrial sites in the Middle East for safety protocol violations.
The scale of the issue is substantial, with emails originating from more than 14,000 from addresses across 6,200 root domains. In the month prior to Solovewicz presenting his findings at the Defcon security conference, the combined domains received more than 11,000 messages. Solovewicz has scanned 7,136 potential placeholder domains and identified 328 with catch-all inboxes configured, suggesting the problem extends far beyond the specific domains he owns.
Both researchers have purchased more than 30 domains in total to prevent malicious actors from exploiting these misconfigurations. They are actively alerting affected organisations to fix their systems, warning that the data could be easily harvested by hackers or extortionists. While some companies have quietly corrected their errors, many have not responded, underscoring the need for rigorous internal auditing to prevent the leakage of sensitive information.
