Daily Guardian UAEDaily Guardian UAE
  • Home
  • UAE
  • What’s On
  • Business
  • World
  • Entertainment
  • Lifestyle
  • Sports
  • Technology
  • Travel
  • Web Stories
  • More
    • Editor’s Picks
    • Press Release
What's On

Logitech’s PRO X2 SUPERSTRIKE HITS differently — and it made me rethink clicking

August 10, 2026

Microsoft accidentally gave Windows 11 users another OneDrive app, and you can’t easily remove it

August 9, 2026

This bizarre email flaw is leaking corporate secrets to anyone who buys the right domain

August 9, 2026

The Lofree Flow 2 made me feel like a faster typist, but it also tested my patience

August 9, 2026

Dubai’s 55th Blood Donation Camp: A Celebration of Community Spirit

August 9, 2026
Facebook X (Twitter) Instagram
Finance Pro
Facebook X (Twitter) Instagram
Daily Guardian UAE
Subscribe
  • Home
  • UAE
  • What’s On
  • Business
  • World
  • Entertainment
  • Lifestyle
  • Sports
  • Technology
  • Travel
  • Web Stories
  • More
    • Editor’s Picks
    • Press Release
Daily Guardian UAEDaily Guardian UAE
Home » This bizarre email flaw is leaking corporate secrets to anyone who buys the right domain
Technology

This bizarre email flaw is leaking corporate secrets to anyone who buys the right domain

By dailyguardian.aeAugust 9, 20263 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

You don’t always need to hack into a company’s systems to get its secrets. Sometimes, the company will simply email them to you. A new report by WIRED’s Matt Burgess has uncovered a bizarre email security problem in which companies are inadvertently sending sensitive information to domains that can be registered and controlled by outsiders. Security researchers Cory Solovevich and Mike Sheward discovered that seemingly harmless addresses such as noreply and deleteduser can become unexpected gateways to corporate information when the domains behind them aren’t properly controlled.

The “hack” is buying the right domain

The worrying part is that this doesn’t require sophisticated hacking. Solovevich discovered that domains such as noreply.net and noreply.us were receiving huge volumes of emails that companies presumably thought would disappear into the void.

Instead, those messages landed in an inbox he controlled. WIRED reports that noreply.net received more than 400,000 messages over a year and a half, including more than 28,000 attachments. The emails ranged from ordinary notifications to employee information and other sensitive business data.

Sheward encountered a similar problem after purchasing deleteduser.com, receiving thousands of unintended emails containing information such as work vacation requests, hotel bookings, employee names and Zoom meeting invitations. The underlying problem is fairly simple. Companies sometimes use placeholder addresses for accounts that no longer exist, assuming nobody can access the destination. But if the associated domain is no longer controlled by the organization and someone else registers it, those supposedly dead-end emails can suddenly have a very real recipient.

This goes way beyond a few stray emails

The researchers found that the problem could be widespread. Solovevich identified 7,136 domains configured to receive email, including 328 with catch-all inboxes capable of accepting messages sent to different addresses within those domains. That doesn’t mean all of these domains are actively leaking sensitive information, but it highlights how easily forgotten email configurations can become a security problem.

Typing on a Macbook

Fortunately, Solovevich and Sheward have been notifying affected organizations rather than simply exploiting the information they receive. Solovevich has also purchased more than 30 domains to prevent malicious actors from taking advantage of the same issue.

The bigger lesson from WIRED’s investigation is almost embarrassingly simple: an email address isn’t a black hole just because a company thinks it is. Organizations can spend millions protecting their networks from sophisticated attacks, but if sensitive emails are still being sent to domains someone else can buy, sometimes the easiest way into a company’s secrets is simply owning the right piece of internet real estate.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Keep Reading

Logitech’s PRO X2 SUPERSTRIKE HITS differently — and it made me rethink clicking

Microsoft accidentally gave Windows 11 users another OneDrive app, and you can’t easily remove it

The Lofree Flow 2 made me feel like a faster typist, but it also tested my patience

Apple might finally bring the ceramic Apple Watch back, and I’ve been waiting for it

Apple already planning a third-generation model for 2027

420 UK children reported explicit deepfakes of themselves in six months. The problem is getting worse

Apple is testing Chinese DRAM even after CXMT refused to cut prices

My smart home experiment has reached its natural limit

Apple just patched a Mac security flaw. You should probably update today

Editors Picks

Microsoft accidentally gave Windows 11 users another OneDrive app, and you can’t easily remove it

August 9, 2026

This bizarre email flaw is leaking corporate secrets to anyone who buys the right domain

August 9, 2026

The Lofree Flow 2 made me feel like a faster typist, but it also tested my patience

August 9, 2026

Dubai’s 55th Blood Donation Camp: A Celebration of Community Spirit

August 9, 2026

Subscribe to News

Get the latest UAE news and updates directly to your inbox.

Latest Posts

Apple might finally bring the ceramic Apple Watch back, and I’ve been waiting for it

August 9, 2026

OMODA 4 Sets New Benchmark for AI Mobility with Next-Generation Super AI Cockpit

August 9, 2026

Apple already planning a third-generation model for 2027

August 9, 2026
Facebook X (Twitter) Pinterest TikTok Instagram
© 2026 Daily Guardian UAE. All Rights Reserved.
  • Privacy Policy
  • Terms
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.