Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Sensitive Information Continues to Find Its Way to Unsuspecting Researchers: A Growing Concern for Corporate Data Security


Researchers Cory Solovewicz and Mike Sheward have been unwittingly receiving thousands of unwanted emails from companies sending sensitive information to placeholder domains like "noreply.us" and "noreply.net". As they work to alert affected organizations, these security experts urge companies to audit their systems and adopt better communication protocols to prevent data breaches.

  • Companies are sending sensitive information to seemingly innocuous email addresses like "noreply.us" and "noreply.net".
  • Security researchers Cory Solovewicz and Mike Sheward have been receiving thousands of unwanted emails due to misconfigured systems.
  • The problem is not new, but experts are urging organizations to fix their mistakes and adopt better communication protocols.
  • Using internal domains or the invalid domain "@x" can prevent email addresses from being monitored.
  • Malicious actors could exploit these misconfigured systems if left unchecked.



  • In an era where data security has become a top priority, a peculiar phenomenon has emerged, leaving many organizations and researchers alike questioning their internal systems and communication protocols. It appears that companies are inadvertently sending sensitive information to seemingly innocuous email addresses, such as those registered with domain names like "noreply.us" and "noreply.net". These domains have been bought by security researchers Cory Solovewicz and Mike Sheward, who have been unwittingly receiving a deluge of corporate secrets, injury reports, and even confidential account information.

    Solovewicz, a security researcher and consultant, initially purchased the noreply.us domain in 2020 as part of an experiment to filter messages and enhance his privacy. However, he soon discovered that other systems were sending mail to @noreply.us addresses, creating an "accidental honeypot" that has been racking up thousands of unwanted emails. The researcher, who also owns the noreply.net domain, estimates that this particular domain has received over 400,000 messages since its purchase in 2024, with some containing attachments.

    Similarly, Sheward, the head of security at EV charging company Xeal, bought the deleteduser.com domain for a mere $15 and was immediately bombarded with emails from at least 100 different organizations. These messages included people's Viagra orders, hotel bookings, and invitations to Zoom meetings from a UK government agency. The researcher has been alerted to the issue, warning companies that their internal systems may be misconfigured to send sensitive information to these placeholder domains.

    The problem is not a new one; independent security journalist Brian Krebs wrote about similar issues almost 20 years ago. However, it's essential to note that this phenomenon is avoidable, and experts are urging organizations to fix their mistakes and adopt better communication protocols. Companies can use internal domains or the invalid domain "@x" to prevent their email addresses from being monitored.

    Both Solovewicz and Sheward have been working independently to alert affected companies and encourage them to audit their systems and rectify any misconfigurations. While some organizations have responded positively, many others have not replied, leaving the researchers with a daunting task of handling every single case. Solovewicz emphasizes that people should not assume a domain is unmonitored and that it's his responsibility as a security researcher to disclose these issues.

    The scope of this problem raises concerns about data protection and cybersecurity. If left unchecked, these misconfigured email systems could become a goldmine for malicious actors, including hackers and extortionists. As Solovewicz aptly put it, "I'm not sure I can say how large of a problem this is, but my concern is that what I 'accidentally' found when I registered my domain is just the tip of the iceberg."

    In response to this growing concern, both researchers have taken steps to expand their efforts by purchasing additional domains. Solovewicz has built a probe to test if other possible placeholder domains may be configured to receive email and has scanned over 7,000 domains for potential vulnerabilities. Sheward, on the other hand, has been actively notifying companies about their misconfigured systems and encouraging them to rectify the issue.

    As data security continues to evolve, it's essential for organizations to take proactive measures to protect their sensitive information. Solovewicz and Sheward's work serves as a stark reminder that even seemingly innocuous email addresses can hold unexpected surprises. It's time for companies to prioritize their internal systems and communication protocols to prevent such incidents in the future.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Sensitive-Information-Continues-to-Find-Its-Way-to-Unsuspecting-Researchers-A-Growing-Concern-for-Corporate-Data-Security-ehn.shtml

  • https://www.wired.com/story/sensitive-info-goes-into-no-reply-emails-constantly-this-guy-sees-it-all/


  • Published: Sat Aug 8 06:29:26 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us