Radio
Now Playing
Quickyla Radio โ€” Click to play
Open โ†’
3 min left
Back to News

Researcher buys noreply.net, receives 3,000+ corporate secrets

A researcher buying noreply.net received thousands of sensitive internal emails from major companies, revealing a widespread security flaw where firms treat noreply addresses as secure. This practiceโ€ฆ

A researcher bought noreply.net. Companies started sending him secrets.
Ars Technica โ€” 10 August 2026
Text:
5 0 0

A researcher bought the domain noreply.net and immediately started receiving sensitive internal messages from major companies. In the first 48 hours, he got emails labeled โ€œconfidential,โ€ delivery confirmations for restricted shipments, and even a password reset link for an executiveโ€™s corporate account. The inflow confirmed a long-suspected flaw: thousands of firms treat โ€œnoreplyโ€ addresses as digital trash cans instead of secure inboxes.

Companies use noreply@ domains to cut down on inbound spam and noise, but the practice quietly creates a backdoor. Marketing, logistics, and HR systems often send order details, meeting invites, and system alerts to these addresses without encryption or authentication. The volume has risen as firms automate more workflows and rely on third-party tracking pixels that auto-fill sender fields. Security researchers have warned for years that noreply domains can become a single point of failure, but many CISOs still see them as low-risk.

During the first week, the researcher catalogued messages from at least 16 Fortune 500 firms across retail, banking, and tech. One email contained a CSV of employee home addresses labeled โ€œDo Not Share.โ€ Another listed software license keys for an entire data center. A third warned of a phishing campaign already inside the companyโ€™s VPN logs. Major providers like Microsoft and Google confirmed they allow noreply domains to receive mail on their platforms, and neither has a plan to block them outright.

The next step is unclear. The researcher has forwarded the evidence to the affected companies and to CISA, but so far only a handful have responded. Security experts expect a patchwork of settings changes rather than a universal fix. Meanwhile, the domain itself remains up, still collecting secrets. The stunt shows how a $12 domain can expose corporate blind spotsโ€”and why โ€œout of officeโ€ should never mean โ€œout of sight.โ€

Read Full Story at Ars Technica โ†’
Advertisement
React:
Sources
Sponsored

More to Read

Hanwha Group and LG CNS tokenize trade receivables to enhanโ€ฆ
๐Ÿ’ป Technology
Hanwha Group and LG CNS tokenize trade receivables to enhance supply chain finance
CoinDesk ยท 14 days ago
7 Statesโ€™ Water Systems Hit by Cyberattacks Likely Tied to โ€ฆ
๐Ÿ’ป Technology
7 Statesโ€™ Water Systems Hit by Cyberattacks Likely Tied to Iran
Wired ยท 9 days ago
Altra Running Promo Codes: 10% Off July 2026
๐Ÿ’ป Technology
Altra Running Promo Codes: 10% Off July 2026
Wired ยท 13 days ago
Hereโ€™s the biggest news you missed this weekend
๐ŸŒ World News
Hereโ€™s the biggest news you missed this weekend
NBC News ยท 15 days ago
Iran war live: Trilateral Mecca defence pact signed, as Horโ€ฆ
๐ŸŒ World News
Iran war live: Trilateral Mecca defence pact signed, as Hormuz deal looms
Al Jazeera ยท 2 days ago
Ghana's community service bill: A fix for the prison crisis?
๐ŸŒ World News
Ghana's community service bill: A fix for the prison crisis?
DW World ยท 14 days ago
Full view