Researcher buys noreply.net, receives company secrets

▼ Summary
– Security researcher Cory Solovewicz has received over 401,796 emails since December 2024 at domains he owns, averaging 699.99 messages per day.
– The emails contain other people’s private information and company secrets, including injury reports, pizza orders, and test platform credentials, rather than typical spam.
– Solovewicz owns the domains noreply.us and noreply.net, which he purchased in 2020 and 2024, and set up as a catch-all email to filter messages, creating an “accidental honeypot.”
– Companies send sensitive data to @noreply.us or @noreply.net addresses, often believing the emails go nowhere or can’t be monitored, possibly after transforming a person’s email when they leave or delete an account.
– Solovewicz, who presented at the Defcon security conference, is working to warn organizations about their misconfigured systems and is relieved the domains weren’t acquired by criminals or nation states.
Cory Solovewicz gets more junk mail than you can imagine. Actually, that’s an understatement. Since December 2024, one of the email domains he controls has absorbed 401,796 incoming messages. That works out to roughly 700 pings every single day, by his own tally.
But this isn’t your typical flood of spam, promotional blasts, or expired coupon offers. What’s landing in Soloweicz’s inbox is far more sensitive: private records, internal credentials, and outright corporate secrets. Over the past few years, he has received injury reports from a municipal government, pizza order confirmations, and account activation notices from a school platform. “I get service orders for people that need repairs. I get lots of test platform credentials,” says Soloweicz, who works as a security researcher and consultant.
The reason for this torrent is simple: Soloweicz owns the domains noreply.us and noreply.net, which he bought in 2020 and 2024. His original plan was to use noreply.us as a catch-all inbox, meaning any email sent to any address ending in that domain would land in his lap. The goal was to filter messages and boost his own privacy. Instead, he stumbled onto something much bigger. Other systems were actively sending mail to @noreply.us addresses. “I created an accidental honeypot,” Soloweicz told WIRED. “I had no idea it was going to turn into this.”
How does this happen? Companies often fire off messages to addresses like [companyname]@noreply.net, assuming those messages go nowhere or can’t be monitored. In other cases, organizations may reroute a former employee’s email to a placeholder domain after they leave or delete their account, without realizing those messages are still being delivered.
What began as a personal email experiment has morphed into a broad campaign to alert businesses and institutions that their internal systems are misconfigured and leaking sensitive data. Soloweicz, who presented his findings at the Defcon security conference yesterday, says he’s ultimately relieved the domains ended up in his hands rather than those of criminal hackers or hostile nation states. In the wrong hands, that data could be weaponized. For now, it’s a warning sign that too many organizations are blindly trusting the “noreply” label.
(Source: Ars Technica)




