Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All
Security researcher Cory Solovewicz has been receiving thousands of unwanted emails containing sensitive information from companies and organizations. He has been tracking the issue and has purchased multiple domains to limit the potential for malicious actors to access t…
Intelligence analysis by Llama

Cory Solovewicz, a security researcher, has been receiving thousands of unwanted emails containing sensitive information from companies and organizations. He has been tracking the issue and has purchased multiple domains to limit the potential for malicious actors to access the data.
Imagine you have a big trash can where people throw away their private information, like passwords and credit card numbers. But instead of throwing it away, it gets sent to a stranger's email address. That's what's happening with companies and organizations who are sending sensitive information to the wrong people. A security researcher is trying to help them fix this problem so they don't accidentally share private information.
Analysis
The Problem of Misconfigured Email Systems
Cory Solovewicz, a security researcher, has been tracking a widespread issue where companies and organizations are inadvertently sharing sensitive information through misconfigured email systems. He has been receiving thousands of unwanted emails containing sensitive information from companies and organizations, including injury reports, confirmation of people's pizza orders, and account setup emails from a school platform. Solovewicz has been tracking the issue and has purchased multiple domains to limit the potential for malicious actors to access the data.
The Scale of the Problem
The issue is not new, but it is inherently avoidable. Companies could use internal domains or the .invalid domain that is guaranteed not to exist. Solovewicz has been scanning domains and has identified 328 of them as having catch-all inboxes configured. He is concerned that the problem may be larger than he initially thought.
The Consequences of Misconfigured Email Systems
The consequences of misconfigured email systems can be severe. If the data falls into the wrong hands, it can be used for malicious purposes, such as identity theft or extortion. Solovewicz is not alone in this voluntary endeavor, which is helping protect the data of companies - often large ones. He has been working independently to alert affected companies of their problems, encouraging them to fix the errors and misconfigurations.
The Solution
The solution to this problem is for companies and organizations to audit their systems and fix their misconfigurations. Solovewicz is advocating for a more proactive approach to email security, where companies take steps to prevent sensitive information from being shared inadvertently. By doing so, they can protect their data and prevent it from falling into the wrong hands.
Key points
- Companies and organizations are inadvertently sharing sensitive information through misconfigured email systems.
- Cory Solovewicz, a security researcher, has been tracking the issue and has purchased multiple domains to limit the potential for malicious actors to access the data.
- The issue is not new, but it is inherently avoidable.
- Companies could use internal domains or the .invalid domain that is guaranteed not to exist.
- The consequences of misconfigured email systems can be severe, including identity theft and extortion.
If companies and organizations take steps to audit their systems and fix their misconfigurations, they can prevent sensitive information from being shared inadvertently. This can help protect their data and prevent it from falling into the wrong hands.
If companies and organizations do not take steps to audit their systems and fix their misconfigurations, they risk accidentally sharing sensitive information with the wrong people. This can have severe consequences, including identity theft and extortion.



