You've seen the sender a thousand times: noreply@. It's the address companies use for password resets, invoices, and account alerts — the one that's supposed to be a dead end.

According to Wired, two security researchers discovered that dead end can be a wide-open door. They bought cheap domains, including noreply.net and deleteduser.com, and set up email listening services on them. Hundreds of companies promptly began sending them corporate secrets.

The mechanism is mundane, which is exactly what makes it unsettling. When a system is configured to send from — or reply to — an address at a domain nobody actually owns, whoever does buy that domain inherits the mail. No hacking, no phishing, no malware. Just a domain registration and a mail server, and the messages arrive on their own.

Wired reports that the flow of sensitive corporate information isn't a trickle or a one-off misconfiguration at a single careless firm. It's constant, and it spans hundreds of companies.

The choice of deleteduser.com points at a related failure: systems that fall back to placeholder addresses when a real user account no longer exists. Those placeholders were presumably never meant to resolve to anything real. Someone made them real.

What makes this different from a typical breach is the absence of an attacker doing anything adversarial. The companies are the ones sending the data. The researchers simply registered names that engineers assumed were permanently unclaimed and set up something to catch what landed there.

It matters because the most expensive data leaks aren't always the sophisticated ones — sometimes an organization's secrets walk out the front door through an address everyone assumed nobody was reading.