This strange email vulnerability is exposing corporate secrets to anyone who acquires the correct domain.
Security researchers have found that companies are unintentionally sending sensitive emails to domains that can be registered by outsiders.
You don't always need to breach a company's systems to access its secrets. Sometimes, companies will just send them to you via email. A recent report by Matt Burgess from WIRED has revealed an unusual email security issue where companies mistakenly send sensitive information to domains that can be controlled by third parties. Security researchers Cory Solovevich and Mike Sheward found that seemingly harmless addresses like noreply and deleteduser can unintentionally become gateways to corporate data if the domains are not properly managed.
The “hack” involves acquiring the right domain.
What is concerning is that this doesn't require advanced hacking skills. Solovevich found that domains like noreply.net and noreply.us were receiving large volumes of emails that companies likely assumed would be untraceable.
Instead, these messages were landing in an inbox he controlled. According to WIRED, noreply.net received over 400,000 messages within a year and a half, including more than 28,000 attachments. The emails varied from routine notifications to employee details and other confidential business information.
Sheward faced a similar situation after acquiring deleteduser.com, where he received thousands of unintended emails with content such as vacation requests, hotel reservations, employee names, and Zoom invitations. The core issue is relatively straightforward. Companies sometimes use temporary email addresses for accounts that no longer exist, thinking that no one can access those addresses. However, if the domain linked to that address is no longer controlled by the organization and is registered by someone else, those emails that were meant to be lost can suddenly reach a very real recipient.
This situation is more than just a few misplaced emails.
The researchers discovered that the issue could be extensive. Solovevich identified 7,136 domains set up to receive emails, including 328 with catch-all inboxes able to accept messages sent to different addresses within those domains. While not all these domains are necessarily leaking sensitive information, it underscores how easily overlooked email configurations can pose a security risk.
Fortunately, Solovevich and Sheward are informing affected organizations instead of exploiting the information they obtain. Solovevich has also purchased over 30 domains to stop malicious actors from taking advantage of this vulnerability.
The broader takeaway from WIRED's investigation is quite straightforward: an email address is not a void just because a company believes it to be. Organizations may invest millions in safeguarding their networks against sophisticated attacks, but if sensitive emails are still directed to domains that can be bought by others, sometimes the simplest way to access a company's secrets is by owning the right piece of digital property.
Other articles
This strange email vulnerability is exposing corporate secrets to anyone who acquires the correct domain.
According to a recent report, a strange email security vulnerability is leading companies to transmit sensitive information to domains that can be registered by outsiders.
