Security Researcher Accidentally Receives 400K Sensitive Corporate Emails via 'noreply' Domains

Original: Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All

Why This Matters

Highlights a widespread, underappreciated misconfiguration risk affecting thousands of organizations across industries.

Security researcher Cory Solovewicz purchased noreply.net and noreply.us domains and inadvertently received over 400,000 emails containing sensitive corporate and personal data from more than 6,200 organizations since 2020, presenting findings at DEF CON on August 7, 2026.

Cory Solovewicz, a security researcher and consultant, purchased the domain noreply.us in 2020 and noreply.net in 2024, originally intending to use them as catch-all email addresses for personal privacy. He quickly discovered that automated systems from hundreds of companies were sending messages to addresses on these domains, believing the emails would go unmonitored or nowhere at all.

As of his DEF CON presentation, noreply.net alone had received 401,796 messages — averaging roughly 700 per day — including 28,365 with attachments. The noreply.us domain received 37,255 messages over approximately 2,345 days. Combined, both domains received more than 11,000 messages in the month prior to his talk. Emails originated from over 14,000 unique sender addresses across 6,200 root domains.

The sensitive data received includes injury reports from a city government, pizza order confirmations, school platform account credentials, service orders, and internal test platform credentials. Solovewicz described the situation as an 'accidental honeypot,' noting the data was sent by automated company systems rather than individuals.

He has been proactively notifying affected organizations of their misconfigurations and is not publicly naming impacted entities. Solovewicz emphasized relief that these domains were not acquired by malicious actors or nation-state threat groups.

Source

wired.com — Read original →