E-Ink News Daily

Back to list

A researcher bought noreply.net. Companies started sending him secrets.

Security researcher Cory Solovewicz accidentally created a data honeypot by purchasing noreply.net and noreply.us domains, receiving over 400,000 emails containing private information, company secrets, and personal data from organizations that mistakenly send sensitive messages to these placeholder-style addresses. The incident highlights widespread misconfiguration of automated email systems across companies and government entities.

Background

Many organizations use placeholder-style email addresses like noreply@ for automated notifications, assuming they won't receive replies. This case reveals how misconfigured systems can inadvertently expose sensitive data when they send personal or confidential information to these unmonitored domains.

Source
Ars Technica
Published
Aug 10, 2026 at 10:25 PM
Score
6.0 / 10