This strange email vulnerability is exposing company secrets to anyone who acquires the appropriate domain.

This strange email vulnerability is exposing company secrets to anyone who acquires the appropriate domain.

      Security researchers have found that companies are unintentionally sending sensitive emails to domains that outsiders can register.

      You don't always have to infiltrate a company's systems to access its confidential information. Often, the company may just email that information directly to you. A recent report by Matt Burgess of WIRED has revealed an unusual email security flaw where companies are unknowingly sending sensitive data to domains that are accessible to outside parties. Security researchers Cory Solovevich and Mike Sheward discovered that seemingly innocuous addresses like noreply and deleteduser can serve as unexpected conduits for corporate information when the domains linked to them are not properly managed.

      The "hack" involves acquiring the correct domain.

      The alarming aspect of this situation is that it doesn’t involve advanced hacking techniques. Solovevich found that domains such as noreply.net and noreply.us were receiving large volumes of emails that companies likely believed would be lost in the digital void.

      Instead, those emails ended up in an inbox he controlled. According to WIRED, noreply.net received over 400,000 emails in a year and a half, including more than 28,000 attachments. These emails varied from routine notifications to employee-related information and other sensitive business data.

      Sheward experienced a similar situation after acquiring deleteduser.com, receiving thousands of unintentional emails that contained details like vacation requests, hotel reservations, employee names, and Zoom meeting invites. The root issue is quite straightforward. Companies sometimes assign placeholder addresses for accounts that have been deleted, assuming that no one can access them. However, if the associated domain is no longer managed by the organization and a third party registers it, those supposedly defunct emails can find a real recipient.

      This issue extends far beyond a few stray emails.

      The researchers discovered that the problem could be prevalent. Solovevich identified 7,136 domains set up to receive emails, including 328 with catch-all inboxes capable of accepting messages sent to various addresses within those domains. Although not all of these domains are actively leaking sensitive information, this situation underscores how forgotten email settings can become a security risk.

      Fortunately, Solovevich and Sheward have been alerting affected organizations instead of merely exploiting the information they obtain. Solovevich has also acquired over 30 domains to prevent malicious actors from taking advantage of this issue.

      The larger takeaway from WIRED’s investigation is almost embarrassingly straightforward: an email address is not a black hole just because a company believes it is. Organizations can invest millions to safeguard their networks from advanced attacks, but if sensitive emails continue to be sent to domains someone else can acquire, the easiest route to a company’s secrets may simply be acquiring the right piece of internet real estate.

This strange email vulnerability is exposing company secrets to anyone who acquires the appropriate domain. This strange email vulnerability is exposing company secrets to anyone who acquires the appropriate domain. This strange email vulnerability is exposing company secrets to anyone who acquires the appropriate domain. This strange email vulnerability is exposing company secrets to anyone who acquires the appropriate domain. This strange email vulnerability is exposing company secrets to anyone who acquires the appropriate domain. This strange email vulnerability is exposing company secrets to anyone who acquires the appropriate domain. This strange email vulnerability is exposing company secrets to anyone who acquires the appropriate domain.

Other articles

In a span of six months, 420 children in the UK reported explicit deepfakes featuring themselves. The issue is escalating. In a span of six months, 420 children in the UK reported explicit deepfakes featuring themselves. The issue is escalating. In a span of six months, children in the UK reported 420 instances of explicit deepfakes, exceeding the total reported in the previous year, as AI has made the creation of abusive images more accessible. I’m already encompassed by AI. I don't require ChatGPT to be right next to my bed. I’m already encompassed by AI. I don't require ChatGPT to be right next to my bed. I enjoy using ChatGPT on my phone and laptop, but allowing an AI companion to have constant access to my home requires a higher level of trust. Apple may be on the verge of reintroducing the ceramic Apple Watch, and I have eagerly anticipated this moment. Apple may be on the verge of reintroducing the ceramic Apple Watch, and I have eagerly anticipated this moment. Apple's ceramic Watch was its highest-end choice, and the anticipated return of this model along with the enhancements in Series 12 performance is well overdue. OpenAI is temporarily halting its AI model after it exhibited risky and uncontrollable behaviors. OpenAI is temporarily halting its AI model after it exhibited risky and uncontrollable behaviors. OpenAI is temporarily halting certain efforts on Astra after tests revealed that the AI could recognize and take advantage of software vulnerabilities autonomously. Apple may be considering a circular display as it prepares for a refresh of its smartwatch. Apple may be considering a circular display as it prepares for a refresh of its smartwatch. In 2017, we discovered an Apple patent for a smartwatch featuring a round display. It appears that Apple is now contemplating a redesign. The payouts for creators on X are being updated, with original content becoming the new form of currency. The payouts for creators on X are being updated, with original content becoming the new form of currency. X is discontinuing its Revenue Sharing program and introducing Original Content Rewards, reallocating funds to prioritize original posts, videos, photos, and substantial commentary.

This strange email vulnerability is exposing company secrets to anyone who acquires the appropriate domain.

A strange email security vulnerability is leading companies to transmit sensitive information to domains that can be registered by unauthorized individuals, according to a recent report.