LIVE · cybersecurity feed
Live wire
email securityhigh

Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All

Security researchers Cory Solovewicz and Mike Sheward have inadvertently created honeypots by purchasing domains like noreply.us and deleteduser.com. Organizations are mistakenly sending sensitive data, including personal information, company secrets, and system credentials, to these domains, believing they are unmonitored. Both researchers are now working to notify affected entities and raise awareness about this widespread misconfiguration, highlighting the potential for malicious actors to exploit such vulnerabilities.

zeroday.news ·

Two security researchers, working independently, have discovered that numerous organizations are inadvertently sending sensitive corporate and personal information to "no-reply" or "deleted user" email addresses. The researchers acquired several such domains and configured them to receive all incoming mail, revealing a widespread issue of system misconfigurations leading to data leakage.

Cory Solovewicz, a security researcher and consultant, purchased the domains noreply.us in 2020 and noreply.net in 2024. He initially intended to use noreply.us as a personal catch-all inbox but soon realized that automated systems were sending emails to addresses on these domains. Since December 2024, his noreply.net domain alone has received over 400,000 messages, with 28,365 containing attachments. The noreply.us domain has received 37,255 messages since its acquisition. In the month preceding his recent presentation at the Defcon security conference, Solovewicz's domains collectively received more than 11,000 messages. These emails originated from over 14,000 "from" addresses across 6,200 root domains.

The content of these emails has included injury reports from a city government, pizza order confirmations, account setup emails from a school platform, service orders for repairs, and test platform credentials. Solovewicz described his discovery as an "accidental honeypot," emphasizing that the messages are automated and not sent by human users. He expressed relief that he, rather than malicious actors, acquired these domains, and has been attempting to notify affected organizations to rectify their system errors.

Similarly, Mike Sheward, head of security at EV charging company Xeal, purchased the domain deleteduser.com for approximately $15 earlier this year. Within an hour, he began receiving emails from three different organizations. He has since accumulated thousands of unintended emails from at least 100 different organizations across multiple domains he now owns. Sheward's received emails include details of Viagra orders, requests for approval of work vacations or leaves of absence, hotel bookings with full names, and invitations to Zoom meetings from a UK government agency. He also noted receiving an invitation to a San Francisco company's summer BBQ addressed to "Dear Deleted User." A significant source of emails for Sheward is an AI company that uses object recognition to monitor worker safety at industrial sites in the Middle East, from which he has received thousands of CCTV stills.

Both researchers speculate that companies may be sending emails to these placeholder domains under the mistaken belief that they are unmonitored, or that they are transforming individual email addresses to such domains when an employee leaves or an account is deleted. The issue is not new, with similar observations dating back nearly two decades regarding @donotreply.com addresses.

Recognizing the potential for misuse by hackers, Solovewicz and Sheward have independently acquired more than 30 such domains to mitigate the risk. Solovewicz has also developed a probe to identify other potential placeholder domains configured to receive email, scanning 7,136 domains and finding 328 with catch-all inboxes. He warns that his findings may represent only a fraction of the problem.

While some organizations have quietly fixed their configurations after being notified, many have not responded, and the sheer volume of misdirected emails makes comprehensive notification a significant challenge. The researchers stress that organizations should not assume a domain is unmonitored and must audit their systems to prevent the leakage of customer, employee, and internal data.

email securitydata leakagemisconfigurationhoneypotvulnerability
ShareXLinkedInWhatsAppFacebook

More News

view all →
css attackshigh

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

New research reveals that sophisticated CSS-based attacks can bypass webmail security measures, enabling attackers to steal sensitive information like passwords and session tokens. These techniques exploit vulnerabilities in popular email services including Outlook, Gmail, and Yahoo Mail, potentially leading to account takeovers and data breaches. The findings highlight the need for stricter sanitization and isolation of email content.

breachcritical

Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

The RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and SharePoint data. The post Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data appeared first on SecurityWeek.

surveillance

Flock’s Plans for Rideshare Dashcams and Coaching Police, Revealed

Flock Safety, a company known for its public safety cameras, reportedly pitched a plan to utilize dashcams from rideshare and delivery vehicles to collect license plate data. This initiative, which did not proceed, would have involved a partnership with Nexar, a dashcam manufacturer, and potentially involved drivers without their knowledge. Separately, a former Flock employee alleged the company provided direct camera access to ICE and CBP through a pilot program, contradicting internal statements.

atlassianhigh

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Two security firms have identified vulnerabilities in Atlassian's Rovo assistant that could allow attackers to exfiltrate data from Jira and Confluence. One vulnerability, dubbed RovoBlast by Varonis Threat Labs, allowed attackers to trick Rovo into sending data to an external server via a malicious link. Atlassian has confirmed this issue is fixed server-side. The second vulnerability, found by PromptArmor, involved injecting malicious instructions into content Rovo processes, enabling data exfiltration without explicit user approval. The status of this second vulnerability remains unconfirmed after its initial disclosure.

breach

Unlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare Patients

Hackers stole personal, medical, and insurance data of 3.8 million people from Unlimited Technology Systems’ data center. Unlimited Technology Systems disclosed a data breach affecting more than 3.8 million people after hackers accessed one of its commercial data centers between October 5 and 10, 2025. Unlimited Technology Systems is a U.S.-based healthcare technology company headquartered […]

CVE-2023-38646critical

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Metabase has issued a critical alert regarding a zero-day vulnerability in its business intelligence software that has been actively exploited. The flaw allows unauthenticated attackers to inject SQL, leading to administrator access, credential theft, and data exfiltration. Metabase Cloud instances have been patched, and users of self-hosted versions are urged to update immediately.