Security researcher Cory Solovewicz is warning businesses about data leaks after his ownership of "noreply" domains revealed hundreds of thousands of misdirected, sensitive corporate and personal emails.
Key Points
- Security researcher Cory Solovewicz owns the domains noreply.us and noreply.net, which have collectively received over 400,000 automated messages since 2020.
- The intercepted emails contain sensitive data, including injury reports, test credentials, pizza orders, and internal company secrets.
- Solovewicz and researcher Mike Sheward have purchased over 30 domains to prevent malicious actors from accessing misdirected corporate communications.
- Analysis of 7,136 domains revealed that 328 are configured as catch-all inboxes, suggesting a widespread systemic failure in how organizations handle automated email routing.
- Experts recommend that companies use internal domains or the ".invalid" top-level domain to ensure automated messages are never sent to the public internet.