Daily Guardian UAEDaily Guardian UAE
  • Home
  • UAE
  • What’s On
  • Business
  • World
  • Entertainment
  • Lifestyle
  • Sports
  • Technology
  • Travel
  • Web Stories
  • More
    • Editor’s Picks
    • Press Release
What's On

Apple is testing continuous heart rate tracking for future Apple Watches

August 30, 2026

The robo pizza chefs aren’t doing okay

August 30, 2026

Stung by OpenAI pulling GPT models from Cursor? Anthropic offers a timely lifeline with higher Claude limits

August 30, 2026

Apple apparently tested a stylus for the foldable iPhone, then nixed the idea

August 30, 2026

Anbernic’s RG 55G1 is a $150 Switch Lite lookalike built for retro gaming

August 30, 2026
Facebook X (Twitter) Instagram
Finance Pro
Facebook X (Twitter) Instagram
Daily Guardian UAE
Subscribe
  • Home
  • UAE
  • What’s On
  • Business
  • World
  • Entertainment
  • Lifestyle
  • Sports
  • Technology
  • Travel
  • Web Stories
  • More
    • Editor’s Picks
    • Press Release
Daily Guardian UAEDaily Guardian UAE
Home » This bizarre email flaw is leaking corporate secrets to anyone who buys the right domain
Technology

This bizarre email flaw is leaking corporate secrets to anyone who buys the right domain

By dailyguardian.aeAugust 9, 20263 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

You don’t always need to hack into a company’s systems to get its secrets. Sometimes, the company will simply email them to you. A new report by WIRED’s Matt Burgess has uncovered a bizarre email security problem in which companies are inadvertently sending sensitive information to domains that can be registered and controlled by outsiders. Security researchers Cory Solovevich and Mike Sheward discovered that seemingly harmless addresses such as noreply and deleteduser can become unexpected gateways to corporate information when the domains behind them aren’t properly controlled.

The “hack” is buying the right domain

The worrying part is that this doesn’t require sophisticated hacking. Solovevich discovered that domains such as noreply.net and noreply.us were receiving huge volumes of emails that companies presumably thought would disappear into the void.

Instead, those messages landed in an inbox he controlled. WIRED reports that noreply.net received more than 400,000 messages over a year and a half, including more than 28,000 attachments. The emails ranged from ordinary notifications to employee information and other sensitive business data.

Sheward encountered a similar problem after purchasing deleteduser.com, receiving thousands of unintended emails containing information such as work vacation requests, hotel bookings, employee names and Zoom meeting invitations. The underlying problem is fairly simple. Companies sometimes use placeholder addresses for accounts that no longer exist, assuming nobody can access the destination. But if the associated domain is no longer controlled by the organization and someone else registers it, those supposedly dead-end emails can suddenly have a very real recipient.

This goes way beyond a few stray emails

The researchers found that the problem could be widespread. Solovevich identified 7,136 domains configured to receive email, including 328 with catch-all inboxes capable of accepting messages sent to different addresses within those domains. That doesn’t mean all of these domains are actively leaking sensitive information, but it highlights how easily forgotten email configurations can become a security problem.

Typing on a Macbook

Fortunately, Solovevich and Sheward have been notifying affected organizations rather than simply exploiting the information they receive. Solovevich has also purchased more than 30 domains to prevent malicious actors from taking advantage of the same issue.

The bigger lesson from WIRED’s investigation is almost embarrassingly simple: an email address isn’t a black hole just because a company thinks it is. Organizations can spend millions protecting their networks from sophisticated attacks, but if sensitive emails are still being sent to domains someone else can buy, sometimes the easiest way into a company’s secrets is simply owning the right piece of internet real estate.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Keep Reading

Apple is testing continuous heart rate tracking for future Apple Watches

The robo pizza chefs aren’t doing okay

Stung by OpenAI pulling GPT models from Cursor? Anthropic offers a timely lifeline with higher Claude limits

Apple apparently tested a stylus for the foldable iPhone, then nixed the idea

Anbernic’s RG 55G1 is a $150 Switch Lite lookalike built for retro gaming

The HiLight Studio app reveals what Google hides about the Pixel 11 Pro’s RGB light, but it’s not for everyone

Chinese DRAM maker is putting its latest LPDDR6 memory inside Xiaomi’s next foldable phone

You no longer need a subscription to try Google’s Dreambeans app

AI is taking a bigger role in short dramas, and actors are paying the price

Editors Picks

The robo pizza chefs aren’t doing okay

August 30, 2026

Stung by OpenAI pulling GPT models from Cursor? Anthropic offers a timely lifeline with higher Claude limits

August 30, 2026

Apple apparently tested a stylus for the foldable iPhone, then nixed the idea

August 30, 2026

Anbernic’s RG 55G1 is a $150 Switch Lite lookalike built for retro gaming

August 30, 2026

Subscribe to News

Get the latest UAE news and updates directly to your inbox.

Latest Posts

The HiLight Studio app reveals what Google hides about the Pixel 11 Pro’s RGB light, but it’s not for everyone

August 30, 2026

Chinese DRAM maker is putting its latest LPDDR6 memory inside Xiaomi’s next foldable phone

August 30, 2026

You no longer need a subscription to try Google’s Dreambeans app

August 30, 2026
Facebook X (Twitter) Pinterest TikTok Instagram
© 2026 Daily Guardian UAE. All Rights Reserved.
  • Privacy Policy
  • Terms
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.