READ. SCROLL. LISTEN.

Unbiased headlines. Facts, not spin.

Every story is an unbiased news briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

One Man Bought noreply.net. Now He Gets 700 Companies' Secrets a Day.

One Man Bought noreply.net. Now He Gets 700 Companies' Secrets a Day.
Security researcher Cory Solovewicz bought the domains noreply.us and noreply.net and accidentally became a magnet for other people's private data. Companies keep sending real customer records, credentials, and internal files to placeholder addresses they assumed went nowhere. It's a plain case of sloppy IT hygiene at scale, and Solovewicz says he's been quietly warning the affected organizations instead of exploiting what he found.

Cory Solovewicz bought a domain name. Now he gets other people's secrets by the thousands.

The security researcher and consultant purchased noreply.us in 2020 and noreply.net in 2024, according to Ars Technica. He figured he'd use them as personal catch-all inboxes, a common privacy trick where any email sent to any address at that domain lands in one place.

What he got instead was a firehose of other people's business.

Since December 2024, noreply.net alone has logged 401,796 messages, Solovewicz calculated, an average of nearly 700 emails a day. The older domain, noreply.us, has pulled in 37,255 messages over the roughly six and a half years he's owned it. Combined, the two domains took in more than 11,000 messages in the month before he presented his findings at the Defcon security conference.

This isn't spam. It's real, sensitive material that companies never meant to send to a stranger.

Solovewicz says he's received injury reports from a city government, pizza order confirmations, account setup emails from a school platform, service repair orders, and test-environment login credentials. Of the noreply.net messages, 28,365 came with attachments, according to Ars Technica's reporting. The mail arrived from more than 14,000 different sender addresses.

The mechanics here are simple in the most dangerous way possible. Companies build internal systems that need a placeholder "sender" or "no reply" address for automated notifications, account changes, or system alerts. Someone configures that placeholder as something like companyname@noreply.net, assuming the domain either doesn't exist or that nobody is watching it.

It exists. Somebody is watching it. That somebody is Cory Solovewicz.

There's a second failure mode too. Some of these systems appear to reroute a person's actual account traffic to a noreply-style address after that person leaves a company or deletes an account, rather than properly disabling the mail flow. That's not a placeholder mistake. That's an organization actively piping live personal data to an address it does not control.

Either way, the root problem is the same: nobody checked whether the domain was actually theirs, actually dead, or actually safe to use as a dumping ground. It's the digital equivalent of writing your safe combination on a sticky note and taping it to a mailbox you don't own.

Solovewicz told Ars Technica and Wired, which also covered his research, that he's not publicly naming the companies involved. Instead he's been reaching out directly to affected organizations, encouraging them to audit their systems and fix the misconfiguration. "I just want companies and organizations to do the right thing and to be auditing their systems and fixing their stuff," he said.

That restraint matters, because the alternative is genuinely alarming. Domain names expire. They get sold. They get parked, dropped, and rebought constantly. If a company builds a system that quietly assumes a specific domain will never be registered by anyone, that assumption eventually breaks. When it does, whoever owns the domain next inherits everything flowing through it.

Solovewicz landed in that seat by accident, as a researcher with no apparent interest in exploiting what fell into his lap. Ars Technica notes he called it "an accidental honeypot" and said he's relieved it was him and not "criminal hackers or nation states" who ended up owning noreply.net and noreply.us. A less scrupulous buyer, or a foreign intelligence service scooping up expired or mismanaged domains specifically to harvest this kind of leakage, would have had access to the exact same firehose of injury reports, credentials, and internal records, with zero obligation to tell anyone.

The actual security lesson is a boring one that gets ignored constantly. Don't hardcode outbound mail to a domain you don't own and control. Don't recycle a placeholder address scheme across an entire organization without confirming it points somewhere safe. Audit where your automated systems are actually sending data, not where you assume they're sending it.

None of this required a sophisticated attack. No one broke into a network, cracked a password, or exploited a zero-day. A researcher bought a domain name and waited. The companies did the rest themselves.

It remains unclear how many of the organizations Solovewicz has contacted have actually fixed their systems, or whether any regulators have taken interest in the specific instances involving government injury reports or school platforms. Ars Technica's report does not name a single affected company, government body, or school, and Solovewicz has said he intends to keep it that way. Whether that discretion holds if the volume of leaked data keeps growing at roughly 700 messages a day is an open question nobody involved has answered yet.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
Ars TechnicaA researcher bought noreply.net. Companies started sending him secrets.