📣 Send us your press release
Site updates every 15 minutes
Technology

Researcher Receives Company Secrets After Buying noreply.net Domain

Security researcher Cory Solovewicz has received a large volume of sensitive company information after purchasing the noreply.net domain. Organizations are inadvertently sending confidential data to the address.

10 August 2026
Researcher Receives Company Secrets After Buying noreply.net Domain

Security researcher Cory Solovewicz has inadvertently become the recipient of a significant amount of sensitive corporate data and personal information after acquiring the noreply.net domain. Since December 2024, the domain has registered over 400,000 messages, averaging nearly 700 per day, many containing confidential details.

Solovewicz, who also works as a consultant, purchased the noreply.net domain in 2024 and previously acquired noreply.us in 2020. His initial intention was to use these domains as catch-all addresses for filtering and privacy enhancement. However, he quickly discovered that various companies and organizations were sending mail to these domains without proper validation, effectively creating what he described as an "accidental honeypot."

The messages Solovewicz has received include injury reports from a city government, order confirmations for items like pizza, and account setup emails from educational platforms. He also noted receiving service orders for repairs and test platform credentials, highlighting a widespread issue with how systems handle non-existent or unmonitored email addresses.

This situation underscores a broader cybersecurity concern regarding the misconfiguration of automated email systems and the handling of sensitive data. It suggests that many organizations fail to properly validate recipient addresses or implement security measures to prevent accidental disclosure of private information when using generic or unmonitored domains.

Original source: arstechnica.com