READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Security Researcher Bought "noreply" Domains, Got 400,000+ Emails Full of Companies' Secrets

Security Researcher Bought "noreply" Domains, Got 400,000+ Emails Full of Companies' Secrets
Cory Solovewicz bought the domains noreply.us and noreply.net thinking they'd be junk-mail filters. Instead companies keep sending him injury reports, test credentials, and other people's private data because their systems are misconfigured. He's now warning businesses at Defcon that this is a much bigger problem than anyone realized.

A security researcher who bought two throwaway-sounding web domains has stumbled into one of the more embarrassing corporate data leaks in recent memory, and it's been happening for years without anyone noticing.

Cory Solovewicz purchased noreply.us in 2020 and noreply.net in 2024, according to Wired. His original plan was simple: use them as catch-all inboxes to filter his own spam and protect his privacy. Catch-all addresses receive mail sent to any username at that domain.

What he got instead was a firehose of other people's private information.

Since December 2024, one of his domains has logged 401,796 messages, an average of roughly 700 emails a day, Wired reported. The noreply.net domain alone has pulled in 400,000 messages over a year and a half, with 28,365 of those carrying attachments. The older noreply.us domain has collected 37,255 messages over more than 2,300 days.

Why This Is Happening

Companies routinely set up automated systems to send email from addresses like companyname@noreply.net, assuming the messages are one-way notifications that go nowhere and get seen by nobody. That assumption is wrong when an actual person owns the domain.

Solovewicz told Wired it's also possible that some systems are misrouting mail meant for a specific employee or customer to a generic noreply-style address, particularly after someone leaves a company or deletes an account. Either way, the sensitive stuff piles up in one stranger's inbox.

The scope of what's landed there is striking. Solovewicz says he's received injury reports from a city government, confirmation emails for people's pizza orders, account setup messages from a school platform, service repair orders, and a large volume of test-platform login credentials, according to Wired. He calls it "an accidental honeypot."

What He's Doing About It

Solovewicz presented his findings at the Defcon security conference, one of the world's largest hacker gatherings, this week. He is not publicly naming the companies or organizations whose data ended up in his inbox.

Instead, he's been contacting affected businesses directly to alert them to the misconfiguration so they can fix it. "I just want companies and organizations to do the right thing and to be auditing their systems and fixing their stuff," he told Wired.

He also made a point of framing his own ownership of these domains as a lucky break rather than a triumph. "I did not realize that this was going to be as big of a problem as it is," Solovewicz said, adding that he's relieved he ended up holding the domains instead of "criminal hackers or nation states who could use the data maliciously."

Solovewicz's concern is well-founded. If a security consultant can accidentally collect 400,000-plus misdirected emails just by buying a domain name, there's nothing stopping a foreign intelligence service or a ransomware crew from doing the exact same thing on purpose. Domain registration is cheap and largely first-come, first-served. Nobody has to hack anything to pull this off.

The Bigger Problem

This isn't a hacking story in the traditional sense. Nobody broke into a network or exploited a software vulnerability. The failure here is basic configuration hygiene: companies building automated email systems without verifying where the mail actually ends up, and without auditing third-party platforms that generate these notifications on their behalf.

The consequences are significant. City governments leaking injury reports and schools leaking account credentials are exactly the kind of exposures that regulators and privacy advocates on both sides of the aisle have spent years demanding companies prevent. This isn't a partisan issue. It's a competence issue, and it's been going on, by Solovewicz's own numbers, since at least 2020.

Wired's reporting does not name a single one of the impacted organizations, which is Solovewicz's choice and arguably the responsible one, since publicizing specific victims before they've patched the problem could invite bad actors to go hunt for the same exposure elsewhere. But it also means the public has no way to independently verify which institutions, government or private, are still sending sensitive data into a stranger's inbox today.

No breach notification, congressional inquiry, or regulatory action has been announced in connection with Solovewicz's findings as of this writing. The unresolved question is how many other "noreply" and similar placeholder domains are sitting unregistered or in the hands of people with far less scrupulous intentions than a security researcher who decided to spend his time filing warnings instead of selling data.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
WiredSensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All