< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

Email security flaw leaks corporate secrets via abandoned domains

Security researchers Cory Solovevich and Mike Sheward have identified a significant email security vulnerability where companies inadvertently leak sensitive information to domains controlled by outsiders.

The flaw occurs when organizations use placeholder email addresses, such as "noreply" or "deleteduser," for accounts that no longer exist. If the organization fails to maintain control over the associated domain, an external party can register that domain and receive all incoming emails intended for those addresses.

In one instance, the domain noreply.net received over 400,000 messages and 28,000 attachments over an 18-month period, containing employee data and sensitive business information. Similarly, the registration of deleteduser.com allowed for the interception of thousands of emails, including hotel bookings, vacation requests, and Zoom meeting invitations. Researchers identified 7,136 domains configured to receive email, highlighting a widespread risk of forgotten email configurations.

Entities

Cory Solovevich · Mike Sheward · Wired