AUTO-UPDATED

Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All

Security researcher Cory Solovewicz is warning businesses about data leaks after his ownership of "noreply" domains revealed hundreds of thousands of misdirected, sensitive corporate and personal emails.

Key Points

  • Security researcher Cory Solovewicz owns the domains noreply.us and noreply.net, which have collectively received over 400,000 automated messages since 2020.
  • The intercepted emails contain sensitive data, including injury reports, test credentials, pizza orders, and internal company secrets.
  • Solovewicz and researcher Mike Sheward have purchased over 30 domains to prevent malicious actors from accessing misdirected corporate communications.
  • Analysis of 7,136 domains revealed that 328 are configured as catch-all inboxes, suggesting a widespread systemic failure in how organizations handle automated email routing.
  • Experts recommend that companies use internal domains or the ".invalid" top-level domain to ensure automated messages are never sent to the public internet.

Why it Matters

This issue highlights a significant vulnerability where companies inadvertently expose private customer and employee data due to poor internal system configurations. If these domains were controlled by malicious actors rather than ethical researchers, the intercepted information could be exploited for identity theft, corporate espionage, or large-scale extortion.
Wired Published by Matt Burgess
Read original