
Researcher Buys Noreply.net, Saves Secrets from Hackers
A security researcher accidentally created a safety net for the internet by purchasing common "no-reply" email domains. He's now protecting thousands of people's private data that companies are accidentally sending into the void.
Imagine buying a domain name for personal use and suddenly becoming the accidental guardian of other people's pizza orders, medical reports, and company secrets.
That's exactly what happened to security researcher Cory Solovewicz when he purchased noreply.net in 2024 and noreply.us in 2020. Since December alone, he's received over 400,000 misdirected emails containing sensitive information that companies thought they were sending to nowhere.
The emails aren't spam. They're automated messages from major corporations and government agencies that misconfigured their systems, accidentally routing private data to addresses they assumed didn't exist. Solovewicz has received injury reports from city governments, service repair orders, school platform credentials, and countless personal details that could be gold for hackers.
"I created an accidental honeypot," Solovewicz told reporters. "I had no idea it was going to turn into this."
Instead of exploiting the data, Solovewicz has made it his mission to alert every affected organization about their security gaps. He's not naming companies publicly but works behind the scenes to help them fix their systems before malicious actors discover the same vulnerability.

The problem is widespread and preventable. Companies often use placeholder email addresses like noreply@companyname.com without realizing someone could own those domains. When Solovewicz scanned similar domains, he found 328 others configured to receive email, representing thousands of potential data leaks.
Fellow researcher Mike Sheward discovered the same issue after spending just $15 on deleteduser.com. Within an hour, three different organizations sent him sensitive information. He's since received Zoom invitations from UK government agencies, hotel bookings with full names, and even thousands of security camera images from an AI safety company monitoring Middle Eastern industrial sites.
The Bright Side
Both researchers could have sold this data or used it maliciously. Instead, they've purchased over 30 similar domains between them, creating a safety net to protect information that companies are carelessly throwing into the digital void. They're also building tools to help organizations identify these vulnerabilities before bad actors exploit them.
Solovewicz presented his findings at the Defcon security conference, not to shame companies but to inspire better practices. He's relieved these domains ended up in his hands rather than with criminals or hostile nations who could weaponize the information.
The fix is simple: companies can use internal domains or the .invalid domain that's guaranteed not to exist. It just requires attention and proper system audits.
These researchers turned an accidental discovery into a force for good, protecting thousands of people's privacy simply because they chose to be guardians instead of opportunists.
More Images



Based on reporting by Ars Technica
This story was written by BrightWire based on verified news reports.
Spread the positivity!
Share this good news with someone who needs it


