This strange email vulnerability is exposing company secrets to anyone who acquires the appropriate domain.
Security researchers have found that companies are unintentionally sending sensitive emails to domains that outsiders can register.
You don't always have to infiltrate a company's systems to access its confidential information. Often, the company may just email that information directly to you. A recent report by Matt Burgess of WIRED has revealed an unusual email security flaw where companies are unknowingly sending sensitive data to domains that are accessible to outside parties. Security researchers Cory Solovevich and Mike Sheward discovered that seemingly innocuous addresses like noreply and deleteduser can serve as unexpected conduits for corporate information when the domains linked to them are not properly managed.
The "hack" involves acquiring the correct domain.
The alarming aspect of this situation is that it doesn’t involve advanced hacking techniques. Solovevich found that domains such as noreply.net and noreply.us were receiving large volumes of emails that companies likely believed would be lost in the digital void.
Instead, those emails ended up in an inbox he controlled. According to WIRED, noreply.net received over 400,000 emails in a year and a half, including more than 28,000 attachments. These emails varied from routine notifications to employee-related information and other sensitive business data.
Sheward experienced a similar situation after acquiring deleteduser.com, receiving thousands of unintentional emails that contained details like vacation requests, hotel reservations, employee names, and Zoom meeting invites. The root issue is quite straightforward. Companies sometimes assign placeholder addresses for accounts that have been deleted, assuming that no one can access them. However, if the associated domain is no longer managed by the organization and a third party registers it, those supposedly defunct emails can find a real recipient.
This issue extends far beyond a few stray emails.
The researchers discovered that the problem could be prevalent. Solovevich identified 7,136 domains set up to receive emails, including 328 with catch-all inboxes capable of accepting messages sent to various addresses within those domains. Although not all of these domains are actively leaking sensitive information, this situation underscores how forgotten email settings can become a security risk.
Fortunately, Solovevich and Sheward have been alerting affected organizations instead of merely exploiting the information they obtain. Solovevich has also acquired over 30 domains to prevent malicious actors from taking advantage of this issue.
The larger takeaway from WIRED’s investigation is almost embarrassingly straightforward: an email address is not a black hole just because a company believes it is. Organizations can invest millions to safeguard their networks from advanced attacks, but if sensitive emails continue to be sent to domains someone else can acquire, the easiest route to a company’s secrets may simply be acquiring the right piece of internet real estate.
Other articles
This strange email vulnerability is exposing company secrets to anyone who acquires the appropriate domain.
A strange email security vulnerability is leading companies to transmit sensitive information to domains that can be registered by unauthorized individuals, according to a recent report.
