Corporate Honeypot through bad email processes

I almost wanted to post this into Threat Intel or Cyber News but figured I would let someone else do that if it was appropriate.

The TL;DR -

Mike purchased the domain delete [dot] com, and has been collecting PII data from companies assuming bad logic/practices.

Small sample list provided by Mike’s post:

  • UAE based Gym Chain
  • South African HR Platform
  • EU based Hotel Reservations Platform
  • India based Delivery Service

Kind of a useful reminder that almost anything can be an opportunity.

In a similar vein, it turned out Microsoft was routing Outlook account creation attempts to example dot com to the Japanese office of JSEI…for quite some time.

I just read through the article and the sauce is the JSON statement.

{"email":"email@example.com","services":[],"protocols":[{"protocol":"imap","hostname":"imapgms.jnet.sei.co.jp","port":993,"encryption":"ssl","username":"email@example.com","validated":false},{"protocol":"smtp","hostname":"smtpgms.jnet.sei.co.jp","port":465,"encryption":"ssl","username":"email@example.com","validated":false}]}

From an AUDIO SERVICE Autodiscover service in Exchange Server | Microsoft Learn ?!

I’m admittedly not an expert in Microsoft’s internal workings, but this appears to be a simple misconfiguration - Michael Taggart

That Michael Taggart guy sounds like someone we should reach out to. Maybe get him to weigh in.

Just wanted to highlight this detailed post in the thread:

https://mike-sheward.medium.com/deleteduser-com-a-15-pii-magnet-c4396eb21061