Defcon 2026: 401,796 Confidential Emails Intercepted via No-Reply Domains

Step by step
How the attack unfolded
Click a phase for details – or let the animation play through.
PHASE 1/4 · Reconnaissance

Researchers identified generic third-party domains used by companies for their automated no-reply emails.

T1590 – Gather Victim Network Information: DNS T1596 – Search Open Technical Databases
  • Affected are no-reply senders such as noreply.net, noreply.us and deleteduser.com
  • Many systems (booking, newsletter, ticket tools) use third-party domains instead of the corporate domain
  • Around 6,200 domains from roughly 14,000 companies were identified
PHASE 2/4 · Initial Access

Researchers purchased the expired or freely available domains, taking control of the associated email traffic.

T1583.001 – Acquire Infrastructure: Domains
  • No password cracked, no firewall bypassed, no software vulnerability exploited
  • Purely legal domain registration as the attack vector
  • Whoever controls the domain controls delivery for all addresses on that domain
PHASE 3/4 · Collection

All messages addressed to the seized domains automatically arrived on the researchers' servers.

T1114.003 – Email Collection: Email Forwarding Rule T1557 – Adversary-in-the-Middle
  • 401,796 confidential emails were intercepted
  • Contents included accident reports, account credentials and sensitive business information
  • German companies were among the main victims
PHASE 4/4 · Impact

The undetected data leakage affected companies as well as their customers, employees and business partners.

T1213 – Data from Information Repositories
  • Intercepted credentials enable potential follow-up logins to services
  • Personal and sensitive data from 14,000 companies exposed
  • Demonstrated at Defcon 2026 as a proof-of-concept study
Short & clear answers
Frequently asked questions about this incident
Is my company affected by this incident?
There is no official tool to determine exactly whether your company was among the roughly 14,000 affected businesses. However, a general risk exists if your automated emails run through a third-party domain such as noreply.net or noreply.us instead of your own company domain. According to the researchers, German companies are among the hardest hit.
How do I check whether my emails use a vulnerable domain?
Open an automated email your company sends, for example an order confirmation or a password reset message. Look at the sender address and check the part after the @ sign. If it shows your own domain (e.g. noreply@your-company.com), you're fine; if it shows a generic third-party domain like noreply.net, there is a risk.
What exactly do I need to do now?
Make sure all automated sender addresses used by your systems (booking systems, newsletters, ticket tools) run on your own company domain and not on a generic third-party domain. Also check the default settings of any service providers you use, as they often preconfigure such external addresses. Adjust any affected addresses promptly.
Was anything actually hacked or a security flaw exploited?
No. The researchers did not crack any passwords, bypass any firewalls, or exploit any software vulnerability. They simply purchased freely available, unused domains legally, which automatically gave them all email traffic sent to addresses on those domains.
What data is at risk if I'm affected?
The researchers intercepted accident reports, account credentials, and sensitive business information, among other things. This puts at risk not only the affected companies themselves but potentially also their customers, employees, and business partners whose data was contained in those emails.
More security news
You might also be interested in
Critical Elementor Pro Flaw: Attackers Can Fully Take Over WordPress Sites
A file upload bug in Elementor Pro up to 4.2.1 allows RCE without login. Version 4.2.2 fixes the flaw – update now!
Pods Plugin: Critical Flaw Enables Admin Takeover, No Login
A critical flaw in the WordPress plugin Pods lets attackers overwrite admin passwords without login. Over 100,000 sites are affected.
miniOrange SAML SSO: Critical Bypass Turns Attackers Into Admins
Two critical auth bypasses in the miniOrange SAML SSO plugin allow forged SAML assertions—up to full WordPress admin access.