Security researchers who registered abandoned or commonly misused domains such as noreply.net, noreply.us, and deleteduser.com began receiving large volumes of misdirected automated email from companies, exposing a widespread data leakage problem. Reports say one domain alone received 401,796 messages since December 2024—about 700 per day—with mail arriving from thousands of sender addresses and root domains. The messages were generated by corporate systems rather than individual users, showing that many organizations continue to route notifications and workflows to recycled, invalid, or poorly controlled addresses.
The unintended emails reportedly included sensitive business and personal information, attachments, HR requests, hotel bookings, Zoom invitations, and other internal communications. Researchers said the issue stems from weak email hygiene, poor account deprovisioning, and unsafe use of placeholder or supposedly non-monitored addresses in automated systems. The findings highlight an avoidable exposure risk that can be reduced through stricter auditing of outbound email flows and the use of internal-only or guaranteed-invalid domains for non-deliverable addresses.

See attribution, scope, and your downstream exposure.
9 events from the most recent confirmed update back to the earliest known activity.
Sheward said deleteduser.com received emails from three different organizations within the first hour after he bought the domain, indicating some companies had not fully removed old addresses from their systems.
Mike Sheward, head of security at Xeal, bought the deleteduser.com domain earlier in the year for about $15 to observe whether organizations were still sending mail to deleted-user placeholder addresses.
Since December 2024, one of the domains monitored by the researchers reportedly received 401,796 messages, averaging about 700 emails per day and containing sensitive corporate information.
Cory Solovewicz bought the noreply.net domain in 2024, adding it to his monitoring of placeholder-style domains that organizations mistakenly treat as unreachable. He later observed large volumes of misdirected automated email sent to the domain.
Cory Solovewicz said the noreply.us domain he owns has received 37,255 messages over 2,345 days since he purchased it in 2020, showing the placeholder-domain email leakage problem has persisted for years.
A researcher re-registered the expired domain gca-emailauth.org for $10 and began receiving DMARC aggregate reports from 86 domains across more than 20 organizations, including 56 domains belonging to The Toro Company. The stale reporting endpoint had appeared in Global Cyber Alliance DMARC training materials dating back to 2019.
After the expired gca-emailauth.org reporting endpoint issue was noticed, the University of Wisconsin–Stevens Point removed the rua tag from its DMARC configuration while retaining a p=reject policy. This reflects a concrete remediation step by one affected organization.
Solovewicz said he has been notifying affected companies that their systems are sending sensitive automated emails to domains he controls and urging them to correct the misconfigurations.
Security researchers Cory Solovewicz and Matt Bryant bought inexpensive domains including noreply.net and deleteduser.com and configured them to receive inbound traffic, passively collecting emails misaddressed by corporate systems.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
7 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcereddit.com
Open sourcereddit.com
Open sourcesh.consulting
Open sourcescworld.com
Open sourcearstechnica.com
Open sourcewired.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.