LobstersTuesday · August 11, 2026FREE

A researcher bought noreply.net. Companies started sending him secrets

securityemailprivacy

A researcher bought the domain noreply.net and subsequently started receiving emails from companies that had sent sensitive information to no-reply addresses. The story, originally reported by WIRED and republished by Ars Technica, describes how the researcher gained access to these secrets. The article, titled "A researcher bought noreply.net. Companies started sending him secrets," was published on August 10, 2026. The report underscores that organizations routinely send emails to no-reply addresses, and when those domains are acquired by third parties, the information can be exposed. The researcher's purchase of the domain allowed him to see all incoming messages, which included confidential data. The article does not specify the exact nature of the secrets or the companies involved, but it highlights the potential security risks associated with using no-reply email addresses for sensitive communications.

// why it matters

Developers should avoid sending sensitive data to no-reply addresses, as domain ownership can change and expose secrets.

Sources

Primary · Lobsters
▸ Read original at arstechnica.com

Like this? Get the next digest.