Security researchers are inadvertently receiving large volumes of sensitive personal and corporate data due to misconfigured email systems, according to a recent report by Ars Technica. Cory Solovewicz, a security researcher, discovered this issue when he registered the domains noreply.us and noreply.net, which have since become unintentional repositories for private information from numerous organizations.Companies are sending sensitive data, including injury reports, pizza orders, and test credentials, to domains like @noreply.us and @noreply.net, believing these addresses are inactive or unmonitored. Solovewicz has received hundreds of thousands of emails containing private information since acquiring these domains. This practice creates an accidental honeypot, exposing data that could be exploited by malicious actors. The problem is not new, with similar issues reported nearly 20 years ago.Researchers like Solovewicz and Mike Sheward, who purchased the domain deleteduser.com, are now attempting to notify affected companies and encourage system audits and fixes. Solovewicz estimates that thousands of domains may be similarly configured, suggesting this is a widespread and potentially significant cybersecurity vulnerability. Both researchers have purchased additional domains to mitigate the risk of malicious actors exploiting this misconfiguration.Ars Technica
Source: Email security
Security researchers accidentally receive sensitive data through misconfigured email domains
(Adobe Stock)
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
