← All stories
● Covered by 2 sources · 2 reportsMedium impact1 negative1 neutral

Security Researcher Receives 400,000 Sensitive Emails Due to Misconfigured 'Noreply' Domains

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Cory Solovewicz received 401,796 emails since December 2024.
  • Emails contain private information and company secrets.
  • Solovewicz owns noreply.us (2020) and noreply.net (2024) domains.
  • Organizations misconfigure systems, sending data to these domains.
  • Received injury reports, pizza orders, and test platform credentials.

Inadvertent Data Leakage

Security researcher Cory Solovewicz has been receiving a large volume of sensitive emails due to a widespread misconfiguration by various organizations. Since December 2024, one of his domains has registered 401,796 messages, averaging nearly 700 emails per day. These messages are not typical spam but contain private information and company secrets.

Contents of the Emails

The emails received by Solovewicz include a range of sensitive data. Examples cited are injury reports from a city government, confirmation of pizza orders, account setup emails from a school platform, service orders for repairs, and test platform credentials. This indicates a broad spectrum of data being inadvertently exposed.

Origin of the Issue

The influx of emails stems from Solovewicz's ownership of the domains noreply.us and noreply.net, which he acquired in 2020 and 2024, respectively. Organizations are sending data to these domains, likely believing them to be unmonitored 'no-reply' addresses used for automated notifications. Solovewicz initially intended to use noreply.us as a catch-all email for privacy filtering but quickly observed the unintended data flow.

Implications for Data Security

This situation highlights a vulnerability where companies inadvertently leak data by sending it to placeholder email addresses. The risk is that if these 'noreply' domains are acquired by malicious actors, the sensitive information could be exploited. The continuous flow of data to Solovewicz's domains demonstrates a systemic issue in how some organizations configure their email systems for automated communications.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Security researcher Cory Solovewicz purchased the domains noreply.us and noreply.net, inadvertently creating a honeypot that receives hundreds of thousands of emails containing sensitive information from misconfigured company systems. This highlights a widespread security vulnerability where organizations send private data to unmonitored "noreply" addresses, risking exposure if these domains are acquired by malicious actors.

Security researcher Cory Solovewicz has received over 400,000 emails containing sensitive personal and company information since December 2024, due to organizations misconfiguring their internal systems to send data to his 'noreply.us' and 'noreply.net' domains. This highlights a widespread vulnerability where companies inadvertently leak data by sending it to placeholder email addresses they believe are unmonitored.