Security researcher Cory Solovewicz accidentally created a data honeypot by purchasing noreply.net and noreply.us domains, receiving over 400,000 emails containing private information, company secrets, and personal data from organizations that mistakenly send sensitive messages to these placeholder-style addresses. The incident highlights widespread misconfiguration of automated email systems across companies and government entities.
Background
Many organizations use placeholder-style email addresses like noreply@ for automated notifications, assuming they won't receive replies. This case reveals how misconfigured systems can inadvertently expose sensitive data when they send personal or confidential information to these unmonitored domains.
- Source
- Ars Technica
- Published
- Aug 10, 2026 at 10:25 PM
- Score
- 6.0 / 10