Email security

Security researchers accidentally receive sensitive data through misconfigured email domains

Scam fraud security warning crime internet technology phishing online alert digital risk protection threat background with danger message spam cyber concept hacking attack email sms caution symbol

Security researchers are inadvertently receiving large volumes of sensitive personal and corporate data due to misconfigured email systems, according to a recent report by Ars Technica. Cory Solovewicz, a security researcher, discovered this issue when he registered the domains noreply.us and noreply.net, which have since become unintentional repositories for private information from numerous organizations.

Companies are sending sensitive data, including injury reports, pizza orders, and test credentials, to domains like @noreply.us and @noreply.net, believing these addresses are inactive or unmonitored. Solovewicz has received hundreds of thousands of emails containing private information since acquiring these domains. This practice creates an accidental honeypot, exposing data that could be exploited by malicious actors. The problem is not new, with similar issues reported nearly 20 years ago.

Researchers like Solovewicz and Mike Sheward, who purchased the domain deleteduser.com, are now attempting to notify affected companies and encourage system audits and fixes. Solovewicz estimates that thousands of domains may be similarly configured, suggesting this is a widespread and potentially significant cybersecurity vulnerability. Both researchers have purchased additional domains to mitigate the risk of malicious actors exploiting this misconfiguration.

Source: Ars Technica

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds