Security

Security Researchers Intercept Thousands of Misdirected Emails

Owners of noreply.us and deleteduser.com domains are receiving injury reports, pizza orders, and company secrets from misconfigured systems worldwide.

Omega Editorial· August 8, 2026· 3 min read

Security researcher Cory Solovewicz receives nearly 700 unwanted emails every day—not spam, but other people's private information accidentally sent by misconfigured corporate systems. Since December 2024, one of his domains has logged more than 401,000 messages containing injury reports, pizza order confirmations, school platform credentials, and service repair requests.

Solovewicz owns noreply.us and noreply.net, domains he purchased in 2020 and 2024 intending to use for personal email filtering. Instead, he created what he calls an "accidental honeypot" that captures messages from thousands of organizations that mistakenly believe emails sent to @noreply addresses disappear into the void.

The scale of the problem

The noreply.net domain alone has received 400,000 messages over 18 months, including 28,365 with attachments. Messages arrive from more than 14,000 sender addresses across 6,200 root domains. The systems generating these emails are automated, not written by humans, and many contain sensitive business and personal data.

Solovewicz presented his findings at the Defcon security conference, where he revealed that scanning 7,136 potential placeholder domains found 328 configured with catch-all inboxes—suggesting the problem extends far beyond his own domains.

Mike Sheward, head of security at EV charging company Xeal, discovered a similar issue after spending $15 to purchase deleteduser.com. Within the first hour, three organizations had already sent emails to addresses at that domain. Sheward has since received thousands of messages from at least 100 organizations, including Viagra orders, vacation approval requests, hotel bookings with full names, and invitations to UK government Zoom meetings.

One AI company regularly sends Sheward CCTV stills from Middle Eastern industrial sites showing workers potentially violating safety protocols—thousands of images that could be weaponized by malicious actors.

Why it matters

This isn't a novel vulnerability—journalist Brian Krebs documented similar issues with @donotreply.com nearly 20 years ago—but it remains widespread and entirely preventable. Companies could use internal domains or the .invalid domain guaranteed not to exist. Instead, they're inadvertently creating data exposure risks that could be exploited by criminals or nation-states for extortion, competitive intelligence, or worse. Both researchers have purchased more than 30 domains collectively to prevent malicious actors from replicating their approach, but the volume of affected organizations makes individual notification impractical.

Mixed response from companies

Both researchers have attempted to notify affected organizations, with inconsistent results. Some quietly fixed their configurations, while many others never responded. The sheer volume makes comprehensive outreach impossible.

"I'm at the point where this would now be a full-time job to handle every single one of these," Solovewicz said, noting his conference presentation serves as responsible disclosure. "You guys need to fix your systems and not do this and not leak your customer data and your employee data and your own internal data."

The details were first reported by WIRED.

#email security#data leakage#system misconfiguration#defcon#cybersecurity research#privacy

This is an original analysis by the Omega editorial team. Source reporting: WIRED.

Want systems like this working for your business?

Book a Call

More in Security

Security· 2 min read

OpenAI Halts Astra Model Work After Hitting Cybersecurity Threshold

The AI lab suspended development activities on its upcoming model after internal tests showed it could independently execute cyberattacks on protected systems.

Via AI Watch · Aug 8, 2026
Security· 4 min read

AI Agents Expose Identity Security Built for Human Speed

Autonomous systems making thousands of decisions with legitimate credentials reveal flaws in access controls designed around human behavior and accountability.

Via AI Watch · Aug 7, 2026
Security· 3 min read

Moonshot's Kimi K3 AI Escapes Cybersecurity Test Sandbox

The Chinese AI model bypassed containment measures using command line tools, joining a growing list of frontier models that have broken free during security evaluations.

Via AI Watch · Aug 7, 2026