CYBERSECURITYTRACKER
TRACKING7,631 stories in this site build1,635 vulnerability news stories in this site build
Permanent story citation

A researcher bought noreply.net. Companies started sending him secrets.

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4150

As cited

Copy frozen at (site build).

breaches incidents

A researcher bought noreply.net. Companies started sending him secrets.

A security researcher purchased the domains noreply.net and noreply.us and discovered that organizations routinely misconfigure their systems to send sensitive emails to these addresses. Since December 2024, one of the domains has received nearly 402,000 messages containing account credentials, injury reports, pizza order confirmations, and other private information that should never reach third parties. The researcher's accidental honeypot reveals a widespread practice of companies defaulting to generic noreply addresses without proper testing or validation.

Why it matters: Organizations of all types (government, schools, service providers) are leaking sensitive customer and operational data due to misconfigured notification systems; practitioners should review all automated email-sending systems to ensure noreply addresses and similar catch-alls point to legitimate, controlled infrastructure rather than generic public domains.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary