HeadlinesBriefing favicon HeadlinesBriefing.com

Noreply Domains Expose Corporate Data Leaks

Hacker News •
×

401,796 messages sent to Cory Solovewicz’s domains since 2024 highlight a systemic issue. Solovewicz, a security researcher, owns noreply.us and noreply.net, which inadvertently collect sensitive data like injury reports, pizza orders, and test credentials. Companies misconfigure systems, sending emails to placeholder domains instead of valid addresses. Over 14,000 unique senders and 6,200 root domains contributed to this deluge. Solovewicz alerts organizations but faces limited cooperation.

The problem isn’t new; similar leaks occurred decades ago. Automated systems often route emails to noreply domains when accounts are deleted or addresses change. Solovewicz received 28,365 attachments, including CCTV stills from an AI firm monitoring workers. He emphasizes that this data could be exploited if mishandled. His Defcon talk revealed 7,136 domains scanned, with 328 having unmonitored inboxes.

Mike Sheward, another researcher, bought deleteduser.com and documented similar breaches. He received Viagra orders, vacation requests, and government meeting invites. Both researchers advocate for internal domains or .invalid addresses to prevent leaks. Many companies ignore warnings, leaving data vulnerable. Solovewicz’s work underscores the need for audits.

The scale suggests this is a widespread, avoidable crisis. While some fixes occur, most organizations lack urgency. Solovewicz now spends full-time addressing these issues, framing it as responsible disclosure. His goal: prevent malicious actors from exploiting leaked data.