By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Researcher's noreply.net Domain Becomes Accidental Data Honeypot

Security researcher Cory Solovewicz has inadvertently become the recipient of a vast amount of sensitive data from numerous organizations due to his ownership of the noreply.net domain. Since December 2024, the domain has registered 401,796 messages, averaging nearly 700 per day. This influx consists not of typical spam, but of private information and company secrets inadvertently sent by various entities. Solovewicz, who also owns noreply.us, purchased noreply.net in 2024 and noreply.us in 2020. Initially, he intended to use noreply.us as a catch-all email address to filter messages and enhance his personal privacy. However, he soon discovered that other systems were sending mail to addresses within the @noreply.us domain. This led him to describe the situation as creating an "accidental honeypot," a development he did not anticipate. The types of sensitive information received include injury reports from a city government, confirmation emails for pizza orders, account setup notifications from educational platforms, service orders for repairs, and numerous test platform credentials. These incidents highlight a significant security vulnerability where organizations are failing to properly manage their email sending systems, leading to the leakage of confidential data to unintended recipients. The sheer volume and nature of the data suggest a widespread issue with how companies handle outgoing communications, particularly those intended for automated or non-personal delivery. Solovewicz's experience underscores the critical need for robust email security practices and diligent management of domain registrations, especially those that might be perceived as generic or automated. The researcher's accidental acquisition of this data trove serves as a stark warning about the potential consequences of misconfigured email systems and the importance of verifying recipient addresses before transmitting sensitive information. The ongoing receipt of such data indicates that the problem persists, with organizations continuing to send confidential details to an address that should not be receiving them. This situation raises questions about the internal security protocols of the organizations involved and their awareness of where their data is being routed. The researcher's role has shifted from passive recipient to an unintentional guardian of potentially compromised information, facing the challenge of how to responsibly handle the data without further exacerbating security risks.
Original source — read the full reporting at the publisher:
Read on Ars TechnicaGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.