The 'Accidental Honeypot': Researchers Uncover Widespread Data Leaks Via Misconfigured 'No-Reply' Domains
Security researchers have inadvertently become custodians of vast amounts of sensitive data, revealing a critical and widespread vulnerability in how organizations handle automated emails. By registering common placeholder domains like 'noreply.us' and 'deleteduser.com,' they've exposed a deluge of private information and company secrets, highlighting systemic misconfigurations across industries.
What started as a personal privacy project has blossomed into a significant cybersecurity revelation. Security researcher **Cory Solovewicz** found himself the recipient of hundreds of thousands of unsolicited emails containing sensitive data after acquiring the domains **noreply.us** and **noreply.net**.
### An Unintended Data Deluge
Since December 2024, one of Solovewicz's domains has registered over 401,796 messages, averaging nearly 700 emails daily. This isn't typical spam; it's a stream of inadvertently shared private information and corporate secrets. Solovewicz has received everything from city government injury reports and pizza order confirmations to school platform credentials and service orders for repairs. "I created an accidental honeypot," Solovewicz told WIRED, "I had no idea it was going to turn into this."
Companies and organizations are mistakenly sending emails to these placeholder domains, believing them to be unmonitored or non-existent. This often occurs when systems are configured to send automated messages to generic 'no-reply' addresses or when employee email addresses are transformed into such placeholders after an account is deleted or an individual leaves the company.
### The Scale of the Problem
**Noreply.net**, the larger of Solovewicz's domains, has received 400,000 messages in 18 months, with 28,365 containing attachments. **Noreply.us**, acquired in 2020, has received 37,255 messages. Collectively, these domains received over 11,000 messages in the month leading up to Solovewicz's presentation at the **Defcon** security conference. These emails originated from over 14,000 "from" addresses across 6,200 root domains, all automated system messages.
### Not an Isolated Incident
This issue, while avoidable, is not new. Nearly two decades ago, **Brian Krebs** highlighted similar problems with companies sending millions of messages to **donotreply.com** emails. Researchers suggest using internal domains or the standardized **.invalid** domain to prevent such leaks.
Solovewicz is not alone in this endeavor. **Mike Sheward**, Head of Security at EV charging company **Xeal**, experienced a similar phenomenon after purchasing **deleteduser.com** for $15. "Within the first hour, there were three different organizations that had emailed stuff to @deleteduser.com," Sheward recounted. He, too, has received thousands of unintended emails from over 100 organizations, including Viagra orders, work vacation requests, hotel bookings with full names, and even Zoom invitations from a UK government agency.
One particularly alarming instance involved an AI company using object recognition in the Middle East, which sent Sheward thousands of **CCTV** stills. As Sheward noted in a Medium post, "I am being a good guardian of the internet dumpsterβbut if I had been a bad one, itβs not hard to see how this information that is willingly thrown at my face could be misused."
### Proactive Measures and Challenges
Recognizing the potential for malicious exploitation, both Solovewicz and Sheward have independently acquired over 30 domains to mitigate the risk of hostile actors replicating their findings. Solovewicz's research included probing 7,136 potential placeholder domains, identifying 328 with catch-all inboxes. "Iβm not sure I can say how large of a problem this is, but my concern is that what I βaccidentallyβ found when I registered my domain is just the tip of the iceberg,"
While they have attempted to notify affected companies, the response has been mixed. Some organizations have quietly resolved the issues, but many others have not responded, underscoring the immense challenge of addressing the problem at scale. Solovewicz emphasizes that the volume of data makes comprehensive notification a full-time job and stresses the importance of responsible disclosure. "You guys need to fix your systems and not do this and not leak your customer data and your employee data and your own internal data."