Buying noreply.net accidentally leaked half the internet's corporate secrets
Ever wondered where automated system emails vanish when they say "do not reply"? Turns out, they land straight in one curious guy's inbox alongside corporate test credentials and surveillance feeds.
When security researcher Cory Solovevitch bought the domains noreply.us and noreply.net, the plan was just to set up a private catch-all filter. Instead, thousands of third-party systems started dumping automated corporate data directly onto his servers.
Since late 2024, a single domain swallowed over 401,000 incoming messages, packed with more than 28,000 attachments. The loot included workplace injury reports from municipal agencies, pizza receipts, student onboarding notices, and live test credentials handed out by developers treating dummy domains like digital trash cans.
The absurd phenomenon is far from isolated. Mike Sheward, head of cybersecurity firm Xeal, spent fifteen bucks on deleteduser.com and intercepted corporate emails from three separate organizations within his first sixty minutes of ownership. Over several months, dozens of companies poured in data, including an industrial safety firm that happily emailed him thousands of raw security camera snapshots.
Both researchers have since scooped up over thirty similar junk domains to keep them away from scammers, desperately trying to notify negligent engineering leads that placeholder addresses do not vanish into the void.
Modern enterprise cybersecurity spends billions on zero-trust architectures and biometric locks, only to bleed surveillance and credentials through dummy placeholder emails hardcoded decades ago.
Source: Wired
Comments
This is where the magic happens: AI reads your discussion and rewrites the article based on the most interesting comments. Each strong comment adds points to the meter below. Once the meter is full, the article updates live — no page reload needed.