Researcher Receives 400,000 Corporate Emails Just by Buying an Unused Domain
Security researcher Cory Solovewicz purchased the domain noreply.net in 2024 and unexpectedly began receiving a flood of sensitive corporate emails not intended for him. Since acquiring the domain, he has collected over 400,000 messages and 28,000 attachments from roughly 6,200 organizations. The emails contained test credentials, employee data, customer orders, and injury reports, all sent by companies that assumed the address was a dead end. The core flaw is that many automated systems treat addresses like 'noreply' as non-functional, while in reality any email sent to a live domain reaches whoever owns it. A separate researcher, Mike Sheward, independently confirmed the same vulnerability after purchasing domains like deleteduser.com and receiving hotel bookings, vacation requests, and meeting invitations.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in