Skip to main content
  1. Home
  2. Emerging Tech
  3. News

This bizarre email flaw is leaking corporate secrets to anyone who buys the right domain

Security researchers discovered companies are accidentally sending sensitive emails to domains that outsiders can register.

Add as a preferred source on Google
Maill app icon notifications
CHUTTERSNAP / Unsplash

You don’t always need to hack into a company’s systems to get its secrets. Sometimes, the company will simply email them to you. A new report by WIRED’s Matt Burgess has uncovered a bizarre email security problem in which companies are inadvertently sending sensitive information to domains that can be registered and controlled by outsiders. Security researchers Cory Solovevich and Mike Sheward discovered that seemingly harmless addresses such as noreply and deleteduser can become unexpected gateways to corporate information when the domains behind them aren’t properly controlled.

The “hack” is buying the right domain

The worrying part is that this doesn’t require sophisticated hacking. Solovevich discovered that domains such as noreply.net and noreply.us were receiving huge volumes of emails that companies presumably thought would disappear into the void.

Instead, those messages landed in an inbox he controlled. WIRED reports that noreply.net received more than 400,000 messages over a year and a half, including more than 28,000 attachments. The emails ranged from ordinary notifications to employee information and other sensitive business data.

Recommended Videos

Sheward encountered a similar problem after purchasing deleteduser.com, receiving thousands of unintended emails containing information such as work vacation requests, hotel bookings, employee names and Zoom meeting invitations. The underlying problem is fairly simple. Companies sometimes use placeholder addresses for accounts that no longer exist, assuming nobody can access the destination. But if the associated domain is no longer controlled by the organization and someone else registers it, those supposedly dead-end emails can suddenly have a very real recipient.

This goes way beyond a few stray emails

The researchers found that the problem could be widespread. Solovevich identified 7,136 domains configured to receive email, including 328 with catch-all inboxes capable of accepting messages sent to different addresses within those domains. That doesn’t mean all of these domains are actively leaking sensitive information, but it highlights how easily forgotten email configurations can become a security problem.

Fortunately, Solovevich and Sheward have been notifying affected organizations rather than simply exploiting the information they receive. Solovevich has also purchased more than 30 domains to prevent malicious actors from taking advantage of the same issue.

The bigger lesson from WIRED’s investigation is almost embarrassingly simple: an email address isn’t a black hole just because a company thinks it is. Organizations can spend millions protecting their networks from sophisticated attacks, but if sensitive emails are still being sent to domains someone else can buy, sometimes the easiest way into a company’s secrets is simply owning the right piece of internet real estate.

Varun Mirchandani
Varun is an experienced technology journalist and editor with over eight years in consumer tech media. His work spans…
The best tech of IFA 2026: a repairable laptop, liquid-cooled power bank, AI toothbrush, and more
From an AI toothbrush to a liquid-cooled battery, this is the best tech of IFA 2026
Best Of IFA 2026

IFA Berlin brought innovation from across the globe into one giant exhibition, and we got the chance to experience the new-gen "tech" firsthand. Walking through Messe Berlin, we saw a laptop designed to be repaired at home to a power bank with visible liquid coolant, an AI-powered toothbrush with a camera inside your mouth, and a robot vacuum carrying another.

The variety is what makes IFA one of the best tech shows. IFA 2026 runs from September 4 through 8, and we've spent our time in Berlin chasing down the products that caught our eyes. Some of these are clever ideas that may change how we use tech every day, while others solve a problem that I didn't realize existed.

Read more
OpenAI admits it needs to rethink what happens when AI goes rogue
As increasingly capable AI agents move beyond controlled tests, OpenAI is confronting a difficult question: When does strange model behavior become an incident the public deserves to know about?
OpenAI logo on blurred background

OpenAI has spent plenty of time explaining how it plans to stop increasingly capable AI agents from doing things they shouldn't. Now, the company says it needs to get better at telling everyone when those things have already happened. The admission follows reports of another previously undisclosed incident involving OpenAI's AI agents, this time affecting a German-language programming wiki. According to Reuters, agents made more than 15,000 unauthorized edits to DseWiki, using the site to communicate and share ways to bypass restrictions, cheat on tasks, and avoid detection.

OpenAI has now acknowledged what it calls the "wiki incident" and says the episode exposed a larger problem with how AI companies disclose unexpected model behavior. The company says it is developing a framework for deciding when and how to make incidents involving misaligned AI public.

Read more
AI has a safety problem nobody is ready for
AI safety efforts are ramping up, but their protections don’t work equally well everywhere. In developing countries, language gaps and cultural blind spots can turn everyday AI mistakes into serious real-world consequences.
Logo, Hockey, Ice Hockey

AI companies are spending an enormous amount of time worrying about what happens when their models become too capable. OpenAI even took the unusual step of temporarily pausing training on a model last month over safety concerns, as the industry grapples with risks ranging from autonomous behavior to increasingly sophisticated cyber capabilities.

But there’s another AI safety problem that is much easier to overlook: the protections already being built into these systems don’t necessarily work equally well for everyone. A new report from Rest of World highlights how AI safety efforts remain heavily centered around the needs of wealthier, English-speaking countries. That can leave people in parts of Asia, Africa, and other developing regions dealing with problems as basic and potentially dangerous as a chatbot misunderstanding their language.

Read more