Published on 10 August 2026
401,796 confidential emails ended up on someone else's servers – and nobody had to hack a single system to make it happen. At the Defcon 2026 security conference, researchers demonstrated just how easy it is to intercept the emails of entire companies: you simply buy the right internet domain that the firm uses for its automated messages. Among the intercepted messages were accident reports, account credentials and sensitive business information. Around 14,000 companies were affected. And according to the researchers, German firms are among the hardest hit.
Security researchers demonstrated at Defcon 2026 – one of the world's largest hacker and IT security conferences – that a large proportion of automatically sent corporate emails runs through addresses that don't actually belong to the company itself. These are so-called no-reply addresses, meaning email senders you're normally not supposed to reply to, such as confirmations or system notifications.
The problem: many of these addresses don't run through the company's own domain (so not, for example, through noreply@your-company.com), but rather through generic, publicly accessible domains such as noreply.net, noreply.us or deleteduser.com. According to the researchers, these domains were available for purchase or were no longer registered – in other words, freely available.
The researchers simply bought up these unused domains. In doing so, they automatically took control over any email traffic addressed to addresses on these domains. The result: 401,796 confidential messages from 6,200 domains belonging to around 14,000 companies ended up on the researchers' servers – without a single password being cracked, a firewall being bypassed or a software vulnerability being exploited.
To understand why this works so easily, you need to know how email delivery works technically. An email is routed to the correct server via the so-called domain part of the address (the part after the @ sign). Whoever controls the domain therefore also controls where the mail to all addresses on that domain goes.
Many companies and the software systems they use – booking systems, newsletter services, ticketing tools or internal business applications, for example – send automated messages via a generic sender address. Frequently a third-party domain such as noreply.net is used, either out of convenience, for historical reasons, or because a service provider preset this address.
As long as this domain belongs to a reputable operator, nothing happens. But as soon as the registration expires and the domain becomes freely available, anyone – including an attacker – can buy it. And from that moment on, all email traffic addressed to addresses on that domain flows directly to the new owner. This is precisely what the researchers demonstrated. They didn't have to "hack" anything in the classic sense – they simply carried out a legal domain registration.
According to the researchers, German firms are particularly severely affected. The reason: many automated systems in German companies use generic email addresses that are not hosted on their own domain, but on such third-party domains.
The nature of the intercepted data is especially explosive. Among the 401,796 messages, the researchers found, among other things:
So it's not only the companies themselves who are affected, but potentially also their customers, employees and business partners whose data was contained in these emails.
The published material does not name any official verification website or tool with which you can determine precisely whether your firm was among the 14,000 affected companies. However, based on the described attack method, you can check for yourself whether your company bears a fundamental risk:
noreply@your-company.com)? Or a third-party, generic domain such as noreply.net, noreply.us or deleteduser.com? Third-party domains are the actual risk.If you discover a third-party domain at any of these points that does not belong to you, you should take action.
Even though the material does not contain a detailed step-by-step guide from the vendor, clear, practical measures emerge from the attack method:
The no-reply incident did not stand alone. In parallel, it became known that the hacker group ShinyHunters compromised a total of 11.6 million email addresses. Such harvested address collections are the raw material for the next wave of attacks: targeted phishing campaigns in which criminals use fake emails to get recipients to click on malicious links or hand over data.
And this is precisely where a worrying development becomes apparent: AI-optimised phishing attacks now achieve a click rate of 54 percent. This means that more than every second recipient falls for such an AI-optimised phishing email. This figure makes it clear that the classic rule of thumb "an attentive employee will spot phishing anyway" no longer holds. AI has made the attacks so convincing that they can barely be distinguished from legitimate communication.
For German companies, the incident is not only a technical matter but also a data protection one. If personal data – for example in accident reports or in messages containing credentials – reaches unauthorised third parties via an insecurely configured, third-party no-reply domain, this can constitute a data breach within the meaning of the GDPR.
As a fundamental principle: companies are responsible for protecting the personal data they process – even when the cause is a misconfiguration in email delivery. If you discover that personal data could have leaked through such a third-party domain, you should treat the incident like a reportable data breach and bring in your data protection officer. Whether notification of the responsible supervisory authority and notification of the affected individuals is required depends on the individual case and the risk to the affected persons – you should have this assessed by a specialist.
What's remarkable about this case is its simplicity. It required no sophisticated malware and no zero-day vulnerability – i.e. no previously unknown security gap. It was enough to buy a domain that had become available. This brings an often overlooked issue into focus: the simple question of which domains a company's automated emails actually run through.
Many companies have geared their email security towards mailboxes, spam filters and passwords. The sender domains of automated systems easily slip out of view – especially when they were preset by service providers or software vendors. It is precisely these blind spots that the researchers made visible at Defcon 2026.
The attack demonstrated at Defcon 2026 impressively shows that security is not just a question of passwords and firewalls. Sometimes a wrongly chosen sender domain is enough for hundreds of thousands of confidential messages to fall into the wrong hands – entirely without classic hacking. With 401,796 intercepted emails from 6,200 domains belonging to 14,000 companies, a parallel compromise of 11.6 million email addresses and a phishing click rate of 54 percent for AI-optimised attacks, the threat situation for German firms is serious.
The good news: the most important protective measure is fundamentally straightforward. Check which domains your automated emails run through and ensure that only your own, self-controlled domain is used. This one step removes the foundation from the described attack. Take the time to review your email systems now – before someone else does it for you.