← 返回 Avalaches

資安研究員 Cory Solovewicz 每天收到大量非預期的電子郵件。自從他購買了 noreply.us 和 noreply.net 等網域後,已經收到了超過四十萬封郵件。這些信件並非一般的垃圾郵件,而是許多企業和組織在無意間外洩的敏感資訊,包含用戶個資、內部憑證與商業機密。(關鍵數字:400,000)

這種情況的發生,主要是因為許多公司在系統設定時發生錯誤,他們會將郵件發送到這些看似無人使用的預設網域,誤以為這些信箱不存在或無人監控。另一位研究員 Mike Sheward 也遇到了類似的狀況,他在購買了 deleteduser.com 網域後,同樣收到了大量包含私人訂單、工作休假紀錄甚至監控影像的機密信件。

為了防止這些敏感資料落入駭客或惡意攻擊者手中,這兩位研究員已經買下了數十個類似的網域以進行保護。他們積極地向受影響的公司發出警告,呼籲這些企業應盡快審查並修正內部系統的錯誤,避免持續外洩員工與客戶的隱私資料,儘管有些公司的回應並不積極。

Security researcher Cory Solovewicz receives a massive amount of unexpected daily emails. Since purchasing domains like noreply.us and noreply.net, he has received over 400,000 messages. These emails are not typical spam, but rather sensitive information accidentally leaked by businesses and organizations, including personal user data, internal credentials, and company secrets.

This situation occurs primarily because many companies misconfigure their systems, sending emails to placeholder domains under the false assumption that they do not exist or are unmonitored. Another researcher, Mike Sheward, encountered a similar issue; after purchasing the domain deleteduser.com, he also received a flood of confidential emails containing personal orders, work vacation records, and even surveillance images.

To prevent this sensitive data from falling into the hands of hackers or malicious actors, these two researchers have purchased dozens of similar domains for protection. They are actively issuing warnings to the affected companies, urging them to audit and fix their internal system errors to stop the ongoing leakage of employee and customer privacy data, even though some companies have not been responsive.

2026-08-09 (Sunday) · 1d26ad5cbf83da07e99b5a50125ab261e9bbc118