As cited
Copy frozen at (site build).
breaches incidents
A researcher bought noreply.net. Companies started sending him secrets.
A security researcher purchased the domains noreply.net and noreply.us and discovered that organizations routinely misconfigure their systems to send sensitive emails to these addresses. Since December 2024, one of the domains has received nearly 402,000 messages containing account credentials, injury reports, pizza order confirmations, and other private information that should never reach third parties. The researcher's accidental honeypot reveals a widespread practice of companies defaulting to generic noreply addresses without proper testing or validation.
Why it matters: Organizations of all types (government, schools, service providers) are leaking sensitive customer and operational data due to misconfigured notification systems; practitioners should review all automated email-sending systems to ensure noreply addresses and similar catch-alls point to legitimate, controlled infrastructure rather than generic public domains.
- Source published
- First seen by Cybersecurity Tracker