Pull down to refresh stories
Patrick Tech Media
Write Login VITi?ng Vi?t Store

A researcher bought noreply.net. Companies started sending him secrets

What to watch next: The next question is whether the signal becomes a durable rollout, a pricing move, a product limitation, or a short update that fades after the news cycle.

Why it matters: The practical impact sits in workflow, cost, risk, or a buying decision; A researcher bought noreply. net. Companies started sending him secrets. should be explained through that lens before any broad claim is made.

Reference image for: A researcher bought noreply.net. Companies started sending him secrets
Reference image from Ars Technica. Ars Technica

Since December 2024, one of the domains at which the security researcher receives email has registered 401,796 messages—by his calculations that’s an average of 699. The source signal from Ars Technica should be placed in context first: the timing, the confirmed detail, and the reason it belongs in today's technology queue.

What happened

Cory Solovewicz receives more unwanted emails than you. Seriously—it’s a lot more. Since December 2024, one of the domains at which the security researcher receives email has registered 401,796 messages—by his calculations that’s an average of 699. 99 pings per day. The source signal from Ars Technica should be placed in context first: the timing, the confirmed detail, and the reason it belongs in today's technology queue. This section should establish the confirmed change before moving into interpretation.

Practical impact for readers

Companies may send emails to [companyname]@noreply. net or similar variations believing they aren’t going anywhere, or could not be monitored in any way. Broadly it’s also possible that they may transform a person’s individual email address to send to one of these placeholder style domains if someone leaves a company or deletes their account. The practical impact sits in workflow, cost, risk, or a buying decision; A researcher bought noreply. net. Companies started sending him secrets. should be explained through that lens before any broad claim is made. This section should connect the report to reader workflow, spending, security, or product decisions.

Details worth verifying

What started out as a personal email project has become a large-scale effort to warn businesses and other groups that they have misconfigured their internal systems and are accidentally sharing sensitive information. Solovewicz, who presented his work at the Defcon security conference yesterday, says ultimately he is relieved that he ended up with the domains rather than criminal hackers or nation states who could use the data maliciously. The next question is whether the signal becomes a durable rollout, a pricing move, a product limitation, or a short update that fades after the news cycle. This section should keep only verifiable details and avoid repeating the same source phrasing.

Who should act or wait

“I did not realize that this was going to be as big of a problem as it is,” says Solovewicz, who is not publicly naming impacted entities. The researcher has been alerting affected companies of their problems, encouraging them to fix the errors and misconfigurations. “I just want companies and organizations to do the right thing and to be auditing their systems and fixing their stuff. For readers, the useful frame is evidence, affected users, remaining risk, and the next point worth checking before acting. This section should name the reader group that benefits from acting now or waiting for confirmation.

What is still unclear

Solovewicz says that the noreply. net domain is the largest he owns and has received 400,000 messages over the year and a half that he’s owned it, with 28,365 of those containing attachments. The noreply. us domain has been sent 37,255 messages over 2,345 days since he purchased it in 2020. Over the month before his conference talk, combined, they’ve received more than 11,000 messages. Overall, emails have been sent from more than 14,000 “from” addresses, from 6,200 root domains. The messages are automated by company systems, not written by humans, the researcher says. A stronger article separates the source fact, the reader impact, and the follow-up question so the piece does not feel like a loose link summary.

Source notes