A researcher bought noreply.net. Companies started sending him secrets.

Security researcher Cory Solovewicz purchased 'noreply' domains and discovered that companies frequently send sensitive private data to these addresses by mistake. This highlights a significant security oversight where organizations treat 'no-reply' email addresses as digital trash cans without considering data privacy risks.
Why it matters
It exposes a common but dangerous cybersecurity vulnerability that leads to the accidental exposure of personal and corporate information.
No reply at all A researcher bought noreply.net. Companies started sending him secrets. Companies treat some email domains as digital trash cans, despite the risks.
17 Credit: Richard Drury via Getty Credit: Richard Drury via Getty Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav Cory Solovewicz receives more unwanted emails than you. Seriously—it’s a lot more. Since December 2024, one of the domains at which the security researcher receives email has registered 401,796 messages—by his calculations that’s an average of 699.99 pings per day.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in