Security Researcher Uncovers Vast Data Leaks Via Misconfigured 'No Reply' Emails
Security researcher Cory Solovewicz has inadvertently created a massive data honeypot by owning the domains noreply.us and noreply.net. Since December 2024 alone, his domains have captured over 401,000 misdirected messages containing sensitive private data and corporate secrets, highlighting widespread vulnerabilities in automated organizational notification systems.
Key points
- Security researcher and consultant Cory Solovewicz owns the domains noreply.us and noreply.net, which he purchased in 2020 and 2024 respectively.
- Since December 2024, one of his domains has registered 401,796 misdirected messages, averaging approximately 699.99 pings per day.
- The intercepted messages include sensitive private information such as municipal injury reports, school platform account credentials, pizza orders, and repair service orders.
- Organizations frequently send automated messages to unmonitored addresses like companyname@noreply.net under the false assumption that these communications are entirely discarded.
Security researcher Cory Solovewicz has inadvertently exposed a widespread flaw in corporate email handling after acquiring domains traditionally associated with automated outbound messaging. By owning noreply.us and noreply.net, Solovewicz established an accidental honeypot that intercepts hundreds of thousands of sensitive communications intended to vanish into unmonitored inboxes.
Since December 2024, a single domain under his control has amassed 401,796 messages, translating to an average of roughly 700 pings daily. Rather than standard spam or newsletters, these communications frequently contain highly confidential data. The captured files and alerts range from municipal injury reports and repair service orders to private test platform credentials and personal purchase verifications.
The influx stems from organizational systems and automated platforms misconfiguring or failing to properly restrict their outbound notification channels. Many businesses dispatch messages to variations like companyname@noreply.net under the flawed assumption that inbound traffic to those addresses is functionally impossible or ignored by mail servers, creating an ongoing risk for accidental corporate and consumer data exposure.
Sources
The WireByte editorial team synthesises technology news from multiple primary sources, verifies the facts, and links every source. Articles are produced with AI assistance and reviewed under our editorial policy.