Security Researchers Intercept Hundreds of Thousands of Sensitive Corporate Emails Exposed by Misconfigured Placeholder DomainsSecurity
8 Aug 2026, 4:16 pm (1 day ago)· 1

Security Researchers Intercept Hundreds of Thousands of Sensitive Corporate Emails Exposed by Misconfigured Placeholder Domains

Cybersecurity researchers have revealed that system misconfigurations by major organizations are accidentally routing hundreds of thousands of confidential corporate files, employee logs, and credentials into unmonitored placeholder email domains.

Automated email infrastructure deployed across modern enterprise IT systems is quietly funneling massive volumes of sensitive corporate secrets, proprietary credentials, and personal customer data into the hands of independent cybersecurity researchers. Due to widespread system misconfigurations and lazy address offboarding procedures, corporate mail servers routinely send automated operational messages to standard placeholder email addresses under the mistaken belief that these destinations are unmonitored or inactive. A single cybersecurity researcher who purchased two common placeholder domains for routine personal privacy filtering has registered 401,796 unintended inbound messages since December 2024 alone, logging an average of 699.99 automated pings every day.

The Accidental Honeypot and Its Massive Data Stream

Security researcher and consultant Cory Solovewicz originally sought to enhance his personal privacy when he acquired two domain names that would unexpectedly transform into a massive repository of corporate leaks. Solovewicz purchased the domain noreply.us in 2020 and later added noreply.net to his portfolio in 2024. His initial objective was straightforward: configure noreply.us as a catch-all email handler to filter incoming messages and protect his primary address from unwanted communications. However, corporate automated systems across the globe were already hardcoded to dispatch automated notifications, system reports, and fallbacks to addresses residing on those exact domains.

Also read

Rather than serving as a quiet privacy shield, the domains began receiving a continuous avalanche of private documentation. Solovewicz noted that he had unwittingly established an accidental honeypot without ever intending to capture corporate communications. Over years of monitoring, the inbox filled with an extraordinary variety of sensitive files and internal communications. He has received official injury reports filed with a city government, order confirmation receipts from local pizza establishments, account setup emails containing user credentials for an educational platform, municipal service repair orders, and administrative access credentials for software testing environments.

The volume of data arriving at these domains highlights a systemic operational failure across IT departments globally. Solovewicz's largest domain, noreply.net, has captured 400,000 messages during the 1.5 years he has held ownership. Out of that total, 28,365 emails included file attachments containing documents, logs, or credentials. Meanwhile, his smaller domain, noreply.us, has accumulated 37,255 messages over 2,345 days since its acquisition in 2020. During the 30-day period immediately preceding his presentation at a major security conference, the two domains combined to receive more than 11,000 inbound emails. These messages originated from more than 14,000 distinct sender addresses linked to 6,200 unique root domains, driven entirely by automated server scripts rather than human users.

Why Enterprise Systems Leak Data to Placeholder Addresses

The root cause of this continuous data spill lies in how enterprise software engineers and system architects configure automated outbound messaging. Organizations frequently route automated notifications through default addresses ending in placeholder domains, assuming such domains cannot be registered or monitored by outside parties. Furthermore, when employees depart an organization or users delete their accounts, internal identity management systems often transform original user addresses into standardized placeholder formats containing terms like no-reply or deleted-user instead of removing the mail generation trigger entirely.

Cybersecurity experts emphasize that this vulnerability is entirely preventable using existing internet standards. Rather than routing traffic to publicly registerable domain extensions like.net or.us, organizations should direct non-monitored automated traffic through internal non-routable domains or use the reserved top-level domain.invalid, which is guaranteed by internet standards never to exist on the public domain name system. The failure to adopt these safe standards has persisted for decades. Nearly 20 years ago, independent security journalist Brian Krebs, then writing for the Washington Post, exposed how corporate mail servers were sending millions of misdirected messages to the domain donotreply.com.

The 15 Dollar Domain Exposing Sensitive Corporate Secrets

Solovewicz is not the only researcher uncovering the scale of this misconfiguration problem. Earlier this year, Mike Sheward, who serves as the head of security at the electric vehicle charging firm Xeal, invested approximately $15 to purchase the domain deleteduser.com. Sheward sought to test whether companies were routing offboarded user accounts into dummy email destinations. The results were instantaneous: within the very first hour after registration, three distinct corporate organizations delivered automated internal communications to addresses at deleteduser.com.

Over time, Sheward has acquired multiple placeholder domains and observed thousands of unintended messages arriving from at least 100 different organizations. The sensitive material delivered to his inboxes spans a broad range of personal and enterprise information. He has received customer order details for prescription medications including Viagra, internal managerial approvals for employee medical leaves and vacation requests, hotel booking confirmations containing complete customer names and travel dates, and official calendar invitations for Zoom meetings generated by a government agency in the United Kingdom. Sheward noted that the senders include prominent cybersecurity vendors and multiple Microsoft partner companies, while one San Francisco technology firm even sent an invitation to its summer barbecue addressed to "Dear Deleted User."

Industrial AI Monitoring Stills and Surveillance Exposures

Among the most concerning streams of misplaced data identified by Sheward is an ongoing leak originating from an artificial intelligence company. The firm specializes in deploying computer vision and object recognition technology to monitor industrial work sites located in the Middle East, checking whether site personnel comply with mandated safety protocols. Due to an internal mail misconfiguration, the AI system continuously dispatches automated alert emails containing raw closed-circuit television (CCTV) camera stills to Sheward's domain.

Sheward has amassed thousands of these industrial surveillance images directly from the firm. Reflecting on the severe privacy implications of these unintentional disclosures, Sheward remarked in an April blog post on Medium that he is acting as a good guardian of the internet's dumpster, but observed that a malicious actor receiving such streams could easily misuse the data willingly thrown at them.

Defcon Research Probes, Defensive Acquisitions, and Disclosures

To measure the broader landscape of placeholder email vulnerabilities, Solovewicz developed a specialized scanner probe to evaluate potential target domains across the web. Presenting his findings at the Defcon security conference, Solovewicz revealed that he scanned 7,136 domain names that fit typical placeholder naming patterns. The scanner identified 328 domains that were actively configured with catch-all inbox functionality, indicating that misdirected corporate email traffic is hitting hundreds of active endpoints across the internet. Solovewicz expressed concern that the data he accidentally discovered represents only the tip of a much larger problem.

Recognizing that unmonitored placeholder domains constitute a goldmine for malicious hackers, cybercriminals, and extortion groups, Solovewicz and Sheward have taken proactive defensive measures. Working independently, the two researchers have registered more than 30 placeholder domains to prevent hostile actors from acquiring them and harvesting incoming corporate data streams. Solovewicz noted that while he is relieved these specific domains ended up in responsible hands, the sheer volume of incoming leaks makes individual notification unsustainable.

Both researchers have attempted to alert affected organizations to their system misconfigurations, but the responses have been inconsistent. While a handful of companies quietly corrected their mail routing scripts upon notification, many others ignored the alerts entirely. Solovewicz warned that attempting to contact every affected entity manually would constitute a full-time job. He urged organizations to take responsibility for auditing their internal software infrastructure, eliminating hardcoded placeholder addresses, and preventing the ongoing exposure of employee, customer, and operational data.

Questions & Answers

How many unwanted emails has Cory Solovewicz received?
Cory Solovewicz has registered 401,796 messages on one of his domains since December 2024, averaging 699.99 pings per day.
Which domain did Mike Sheward purchase and what data did he receive?
Mike Sheward spent around $15 to buy deleteduser.com, receiving medical orders, leave approvals, hotel bookings, and thousands of industrial CCTV stills.
Why are companies making this mail configuration error?
Companies automate outbound mail using placeholder domains assuming they are unmonitored or non-existent, or convert offboarded user addresses into dummy domains.
What fix do security researchers recommend to avoid these data leaks?
Researchers suggest using internal domains or the reserved .invalid top-level domain, which is guaranteed not to exist on the internet.
What were the results of the probe presented at the Defcon conference?
Solovewicz scanned 7,136 potential placeholder domains and identified 328 configured with catch-all inboxes receiving misdirected emails.

Comments 0

No comments yet — be the first.

Citizen journalism

Become a TrendKia journalist

Voice of the people

Share news, photos and videos from your area with TrendKia and let your voice reach the nation. Every citizen a journalist.

Join now
CH 01 LIVE
TrendKia TV ON AIR