Observed Signal · Aug 10, 2026 · Report · Source: t3n · Impact: 3/5 · Sentiment: Negative
Companies Accidentally Send Sensitive Emails to Third Parties
Security researchers report that many companies inadvertently forward sensitive customer and employee data to unintended recipients by routing addresses to reusable no-reply or catch-all domains. Researcher Cory Solovewicz says he has received more than 400,000 misdirected emails since December 2024 by owning domains such as @noreply.us and @noreply.net; over 28,000 of those included attachments. Solovewicz scanned 7,136 domains that could be abused and found 328 configured as catch-all. Researcher Mike Sheward, after acquiring deleteduser.com, received messages from more than 100 companies. Solovewicz and Sheward have bought 30+ domains to demonstrate the issue and contacted affected organizations; only a few have taken corrective action.
Widespread email misconfiguration and catch-all/no-reply usage can leak employee and customer data at scale, posing privacy, compliance and operational risks for companies and marketers that rely on email communication.
Track WIRED Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Security researcher Cory Solovewicz received more than 400,000 misdirected emails since December 2024 by owning domains such as @noreply.us and @noreply.net.
- More than 28,000 of the received emails contained attachments like PDFs.
- The misdirected messages originated from over 14,000 addresses across roughly 6,200 different domains.
- Solovewicz scanned 7,136 domains that could be abused for this purpose and found 328 configured as catch-all domains.
- Mike Sheward acquired deleteduser.com and receives emails from over 100 companies; Sheward and Solovewicz bought more than 30 domains to demonstrate the problem and contacted affected organizations, with few companies making fixes.
Connected Companies & Entities
4 Entities mapped“Security researcher Cory Solovewicz warns about this serious security problem in a report by Wired....”
“The page states: "Here you will find external content from TargetVideo GmbH that complements our editorial offering on t3n.de."...”
“The page states: "Here you will find external content from Podigee GmbH that complements our editorial offering on t3n.de."...”
“The article and editorial notes appear on the t3n.de website, e.g. "…that complements our editorial offering on t3n.de."...”
Ontology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Scammers Abuse Internal Microsoft Account to Send Spam
Scammers have been exploiting a loophole to send spam emails appearing to come from an internal Microsoft notification address (msonlineservicesteam@microsoftonline.com) that is normally used for legitimate account alerts like two-factor authentication. Attackers apparently create new Microsoft accounts and use that access to send emails with subject lines and links that mimic official alerts, directing recipients to scam websites. The Spamhaus Project confirmed the abuse and said the activity dates back several months; it has notified Microsoft. TechCrunch contacted Microsoft, which acknowledged the inquiry but has not confirmed whether the issue is resolved. The report notes similar incidents at other companies, and places this episode in a broader pattern of threat actors abusing trusted notification systems to phish users.
Apple 'Hide My Email' Bug Reveals Real Addresses
A security researcher has reported a vulnerability in Apple’s 'Hide My Email' feature (part of iCloud+) that can reveal users’ actual email addresses behind one-time, randomly generated forwarding addresses. According to 404 Media, researcher Tyler Murphy of the data-deletion service Easyoptouts discovered the bug in June 2025 and notified Apple, but the company has not fixed the issue for about a year. 404 Media says it was able to reproduce the disclosure using the exploit supplied by Murphy. Both Murphy and 404 Media withheld technical details to avoid enabling abuse; Apple previously asked the researcher not to publish exploit details. The flaw raises privacy risks, including the ability to link masked addresses to personal data on public people-search sites.
Bug in Apple’s Hide My Email Exposes Real Addresses
New research reported by 404 Media and summarized by TechCrunch claims a vulnerability in Apple’s Hide My Email feature can reveal users’ real email addresses. Researcher Tyler Murphy, co‑founder of EasyOptOuts, says he informed Apple more than a year ago and that 404 Media tested and verified the issue; in limited volunteer tests Murphy reported 100% of Hide My Email addresses were exploitable. Details of the vulnerability have been withheld from public disclosure to avoid abuse. Murphy warned that people‑search and data broker sites can link exposed emails to additional personal information, increasing privacy risk. TechCrunch contacted Apple for comment. The report follows prior scrutiny of Apple privacy features in 2022 and 2023 for other perceived privacy failures.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
