Security researcher Cory Solovewicz has been receiving a large volume of sensitive emails due to a widespread misconfiguration by various organizations. Since December 2024, one of his domains has registered 401,796 messages, averaging nearly 700 emails per day. These messages are not typical spam but contain private information and company secrets.
The emails received by Solovewicz include a range of sensitive data. Examples cited are injury reports from a city government, confirmation of pizza orders, account setup emails from a school platform, service orders for repairs, and test platform credentials. This indicates a broad spectrum of data being inadvertently exposed.
The influx of emails stems from Solovewicz's ownership of the domains noreply.us and noreply.net, which he acquired in 2020 and 2024, respectively. Organizations are sending data to these domains, likely believing them to be unmonitored 'no-reply' addresses used for automated notifications. Solovewicz initially intended to use noreply.us as a catch-all email for privacy filtering but quickly observed the unintended data flow.
This situation highlights a vulnerability where companies inadvertently leak data by sending it to placeholder email addresses. The risk is that if these 'noreply' domains are acquired by malicious actors, the sensitive information could be exploited. The continuous flow of data to Solovewicz's domains demonstrates a systemic issue in how some organizations configure their email systems for automated communications.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Security researcher Cory Solovewicz purchased the domains noreply.us and noreply.net, inadvertently creating a honeypot that receives hundreds of thousands of emails containing sensitive information from misconfigured company systems. This highlights a widespread security vulnerability where organizations send private data to unmonitored "noreply" addresses, risking exposure if these domains are acquired by malicious actors.
Security researcher Cory Solovewicz has received over 400,000 emails containing sensitive personal and company information since December 2024, due to organizations misconfiguring their internal systems to send data to his 'noreply.us' and 'noreply.net' domains. This highlights a widespread vulnerability where companies inadvertently leak data by sending it to placeholder email addresses they believe are unmonitored.