What if you could receive a company’s private information without hacking its network, bypassing a firewall, or stealing a password?

You might only need to buy the right domain name.

That’s what security researcher Cory Solovewicz discovered after purchasing noreply.net. Instead of becoming the quiet corner of the internet he expected, the domain started receiving a staggering number of emails from companies and organizations that apparently assumed nobody was listening.

Some contained ordinary automated notifications. Others contained far more sensitive information, including test credentials, employee data, customer orders, injury reports, and thousands of attachments.

And this wasn’t a single company making a mistake.