A researcher bought noreply.net. Companies started sending him secrets.
Summary
Ars Technica covers a Wired.com piece about Cory Solovewicz, a security researcher who bought noreply.net and noreply.us and began receiving a huge volume of misaddressed emails containing sensitive information. The emails result from misconfigured catch-all inboxes and placeholder domains, exposing private data from government, corporate, and personal accounts. The story highlights the broader privacy and security risks of poor email-domain hygiene and urges organizations to audit their systems and implement better domain management and email security practices.