Hackers Can Read Your 'No Reply' Emails—This Guy Bought the Domains to Prove It

Sensitive Info Goes into 'No Reply' Emails Constantly. This Guy Sees It All

Hackers Can Read Your 'No Reply' Emails—This Guy Bought the Domains to Prove It

Security researcher Cory Solowewicz bought the domains noreply.us and noreply.net as a privacy experiment, only to discover that hundreds of companies were inadvertently sending sensitive emails—including injury reports, pizza orders, and test credentials—to these addresses. He and fellow researcher Mike Sheward, who purchased deleteduser.com, have received hundreds of thousands of messages, exposing a systemic flaw in how companies handle email addresses for departed users. They've been notifying affected organizations and warn that the problem is far larger than they can handle alone.

I created an accidental honeypot. I had no idea it was going to turn into this.

More from this day

2026-08-08