HR EN DE
NEWS SPORT BIZNIS SCENA LIFESTYLE TECH

He Bought a Domain for $15 and Got Thousands of Business Secrets

Security researchers warn of a bizarre flaw: companies unknowingly send sensitive data to domains like noreply.net and deleteduser.com that anyone can buy.

Foto: Wikipedia (Email)
Summary
  • Researchers gained access to hundreds of thousands of confidential emails by purchasing domains like noreply.net and deleteduser.com.
  • The messages included employee data, government reports, hotel reservations, and thousands of CCTV images.
  • They discovered 7,136 domains configured to receive emails, 328 of which had catch-all mailboxes.
  • The researchers bought more than 30 domains to keep them away from potential criminals and intelligence agencies.

When a hacker wants to get their hands on a company's sensitive information, sometimes they don't need a sophisticated attack-they just need to buy the right domain name. Security experts Cory Soloweicz and Mike Sheward noticed an unusual phenomenon that causes companies to accidentally send confidential messages to domains that anyone can purchase and control.

The problem arises with simple addresses like noreply or deleteduser. Companies use these for non-existent user accounts, thinking that messages sent to them will simply be lost. However, if a company no longer owns the domain associated with such an address, someone else can buy it and start receiving all the messages that arrive there.

An Accidental Honeypot Full of Confidential Information

Soloweicz discovered that domains like noreply.net and noreply.us were receiving massive amounts of messages. According to an investigation by Wired, noreply.net received over 400,000 emails from late 2024 over a period of about a year and a half, including more than 28,000 attachments. "I created an accidental honeypot," Soloweicz told Wired. What started as a personal email experiment eventually grew into an effort to warn organizations that their own systems are leaking information.

Not all messages were sensitive, but among them were employee data, government injury reports, repair orders, school account information, and even login credentials. In some cases, companies appear to send automated messages to addresses like [email protected] under the assumption that the messages simply disappear. Soloweicz avoided publicly identifying affected companies and instead contacted them to warn them of the issue.

For $15, Thousands of CCTV Images

Another researcher, Mike Sheward, stumbled upon a nearly identical problem after paying about $15 for the domain deleteduser.com. Within just one hour, messages arrived from three different organizations. Since then, messages from at least 100 organizations have arrived at domains he controls. Among them were hotel reservations with guest names, vacation requests, Zoom meeting invitations from a UK government agency, and even medication order information.

A particularly concerning example involves an AI company that monitors industrial workers in the Middle East. Sheward claims its systems mistakenly sent him thousands of CCTV images. The obvious concern is that researchers aren't the only ones who can buy these domains. Criminals, extortionists, or foreign intelligence agencies could do the exact same thing.

The Problem Is Much Bigger Than You Think

The two researchers have so far purchased more than 30 domains in an effort to keep them out of the hands of malicious actors. Soloweicz also tested over 7,000 potential placeholder domains and found 328 configured with so-called catch-all mailboxes, suggesting the problem could be far larger than what they've uncovered so far. In total, they found 7,136 domains set up to receive email. This doesn't mean all 7,136 domains are actually leaking confidential information, but it does highlight how forgotten or poorly maintained email settings can be a security threat.

The frustrating part is that the problem is largely avoidable. Companies can use internal addresses or domains designed not to resolve, rather than assuming that a random "noreply" or "deleteduser" address leads nowhere. As Soloweicz told companies: "You need to fix your systems."

FAQ
How did this security flaw come about? +
Companies often use email addresses on domains like noreply.net for accounts that no longer exist, assuming the messages just disappear. The problem arises when someone buys that domain and starts receiving all the messages sent to it.
What are the most sensitive pieces of information leaked this way? +
Among the messages received were government injury reports, login credentials, hotel reservations with guest names, Zoom meeting invitations from a UK government agency, medication order information, and thousands of CCTV images.
How widespread is this problem? +
Researchers found 7,136 domains configured to receive emails, 328 of which had catch-all mailboxes that accept messages for various addresses. On just one domain, over 400,000 messages were collected in a year and a half.
How can companies protect themselves from such a flaw? +
Experts advise companies to use internal addresses or domains designed not to resolve, rather than relying on random "noreply" or "deleteduser" addresses and assuming they are safe.

Log in

You need to log in or register to comment.

Comments (0)
No comments yet. Be the first!
Search
Popular
Nedavno pretraživano
helsinški sporazum
liga prvaka
digitalni mediji
Login
Home
Prati nas na Googleu
Categories