1
1
Cory Solovewicz, a security researcher and consultant, has become an unwitting recipient of an extraordinary volume of sensitive information, far surpassing the typical influx of unwanted emails. Since December 2024, one of the domains he manages has alone registered an astonishing 401,796 messages, translating to an average of nearly 700 unsolicited pings every day. This deluge is not conventional spam but rather a steady stream of private data and company secrets inadvertently disclosed by various organizations.
Over the past few years, Solovewicz has accumulated a startling collection of records. These include detailed injury reports from a city government, confidential confirmations of individuals’ pizza orders, and critical account setup emails from a school platform, often containing credentials. "I get service orders for people that need repairs. I get lots of test platform credentials," Solovewicz recounted, highlighting the diverse and often highly personal nature of the information he receives.
The genesis of this digital flood dates back to Solovewicz’s acquisition of two specific domains: noreply.us in 2020 and noreply.net in 2024. His initial intent for noreply.us was to establish a catch-all email system—designed to receive any mail sent to an @ address on that domain—primarily to filter messages and enhance his personal privacy. However, what began as a personal project quickly transformed into an unforeseen security investigation. He soon realized that numerous external systems were erroneously directing mail to various @noreply.us addresses. "I created an accidental honeypot," Solovewicz revealed to WIRED. "I had no idea it was going to turn into this."
The core problem stems from a widespread misconception and misconfiguration within many organizations. Companies often configure their automated systems to send emails from addresses like [companyname]@noreply.net or similar variations, operating under the flawed assumption that these messages are either undeliverable or, if delivered, would remain unmonitored. Another common practice involves transforming a person’s individual email address to one of these placeholder-style domains when an employee departs or an account is deleted, rather than properly removing the address from active systems or ensuring messages are directed to a secure, unmonitored internal destination.
Solovewicz’s data provides a stark illustration of the immense scale of these misconfigurations. The noreply.net domain, acquired in 2024, is the largest he owns and has received approximately 400,000 messages over the year and a half he’s owned it, with 28,365 of those containing potentially sensitive attachments. The older noreply.us domain, purchased in 2020, has accumulated 37,255 messages over 2,345 days. In the month leading up to his recent presentation at the Defcon security conference, both domains combined registered more than 11,000 messages. This continuous stream of data originates from over 14,000 distinct "from" addresses, spanning more than 6,200 root domains. Solovewicz emphasizes that these messages are consistently automated system outputs, not human-generated communications, underscoring a systemic vulnerability.
What began as an unintended personal email project has evolved into a significant public service initiative. Solovewicz is now dedicated to raising awareness and warning businesses and other organizations about their misconfigured internal systems, which are inadvertently exposing sensitive information. At the Defcon security conference, he publicly presented his findings, underscoring the urgency of the problem. His primary relief, he states, is that he, a responsible security researcher, ended up with these domains, rather than malicious actors like criminal hackers or hostile nation-states who could exploit such a vast trove of data for nefarious purposes.
"I did not realize that this was going to be as big of a problem as it is," Solovewicz acknowledged, carefully refraining from publicly naming the specific entities impacted by these leaks. Instead, his focus has been on privately alerting affected companies to their vulnerabilities, encouraging them to rectify these errors and misconfigurations. "I just want companies and organizations to do the right thing and to be auditing their systems and fixing their stuff," he asserted, articulating his commitment to improving cybersecurity hygiene across the digital landscape.
The phenomenon of organizations misdirecting "no-reply" emails is not a novel issue. Nearly two decades ago, independent security journalist Brian Krebs, then writing for the Washington Post, brought attention to a similar problem, detailing how companies were sending millions of messages to @donotreply.com email addresses. Despite this historical precedent, the issue remains inherently avoidable. Solovewicz points out that companies have straightforward, secure alternatives. They could, for instance, utilize internal, non-routable domains for such automated communications or employ the .invalid domain, which is specifically designated by the Internet Engineering Task Force (IETF) as guaranteed not to exist, thus preventing any unintended external delivery.
Solovewicz is not alone in this voluntary and critical endeavor to safeguard corporate and personal data. Earlier this year, Mike Sheward, the head of security at EV charging company Xeal, embarked on a strikingly similar mission. For a modest investment of approximately $15, Sheward acquired the domain deleteduser.com. The immediate results were astonishing. "Within the first hour, there were three different organizations that had emailed stuff to @deleteduser.com," Sheward told WIRED, illustrating the pervasive nature of this oversight. His findings further suggest that many companies opt to simply re-route or alter email addresses for departed personnel or deleted accounts, rather than completely expunging them from their active systems.
Like Solovewicz, Sheward has witnessed an immense influx of unintended emails. He has received thousands of such messages, originating from at least 100 distinct organizations across the multiple placeholder domains he now owns. The data he has inadvertently collected is equally sensitive and diverse. It includes details of individuals’ Viagra orders, requests for approval of work vacations or leaves of absence, hotel bookings complete with full names and travel itineraries, and even invitations to confidential Zoom meetings from a UK government agency. "There’s a lot of cybersecurity companies and a few Microsoft partner companies as well," Sheward noted. He vividly recalls receiving an invitation to a San Francisco company’s summer BBQ, addressed impersonally to "Dear Deleted User," a stark illustration of the automated and unthinking nature of these misconfigurations.
One particularly concerning source of emails for Sheward is an AI company, which he chose not to name publicly. This firm utilizes object recognition technology to monitor workers at industrial sites in the Middle East, specifically to detect potential safety protocol violations. Sheward has received thousands of CCTV stills from this company, a profoundly intrusive and sensitive data leak. Reflecting on the gravity of his findings, Sheward articulated his role in an April Medium post: "I am being a good guardian of the internet dumpster—but if I had been a bad one, it’s not hard to see how this information that is willingly thrown at my face could be misused." This statement powerfully conveys the immense potential for harm if such data were to fall into malicious hands.
As both Solovewicz and Sheward independently grasped the staggering scale of these misplaced emails—and recognized the invaluable intelligence they represented for hackers and extortionists—they took proactive steps. Working separately, they collectively purchased more than 30 additional placeholder domains. Their aim was to pre-emptively acquire these common "no-reply" and "deleted-user" variations, thereby limiting the opportunities for malicious actors to exploit this systemic vulnerability by copying their approach.
During his Defcon presentation, Solovewicz further detailed his efforts to quantify the problem. He explained the development of a specialized probe designed to test whether other potential placeholder domains are configured to receive email. "I’ve scanned 7,136 domains, and 328 of them were identified as having catch-all inboxes configured," Solovewicz reported. His findings are a sobering indicator of a much larger, unaddressed issue. "I’m not sure I can say how large of a problem this is, but my concern is that what I ‘accidentally’ found when I registered my domain is just the tip of the iceberg," he cautioned, signaling that the extent of these misconfigurations is likely far greater than currently understood.
Both researchers confirmed that, whenever feasible, they have diligently notified companies whose systems are misconfigured and are inadvertently sending them emails. However, the results of these notifications have been decidedly mixed. While some