i was quite surprised to discover that no one had registered deleteduser [dot] com, and was curious to see how many emails i'd get if i registered it, assuming many orgs 'delete' logic probably just overwrote the email address with [email protected] or similar.

The answer, is at least 3 different orgs in the hour that I've owned that domain and been listening for email.

And yes, all of those emails contain the actual PII of the person who has been 'deleted' :-D

#infosec

Up to about 24 different orgs now, overnight had some emails containing PII of 'deleted' users from a:

UAE based Gym Chain
South African HR Platform
EU based Hotel Reservations Platform
India based Delivery Service

and best of all

US based Antivirus Manufacturer and Cybersecurity Provider

And of course the hotel reservations platform is happily spitting out the name of guests and their contact info to the Deleted User email address
Deleteduser.com —a $15 PII Magnet

When is a delete, not a delete? When it’s an publicly routable placeholder.

Medium
Thursday must be PHI day - a platform that appears to be used by care workers and psychologists is happily sending patient names and details to deleteduser dot com.

Couple of new additions today to the internet dumpster:

- Some internal system at one of the worlds largest and most recognizable consumer electronics manufacturer is telling deleteduser.com all about approved purchase orders, including direct links to the orders, and the names of all the people who are involved.

- More gyms, very common.

- Some platform used to offer temporary shifts to healthcare workers asked a nurse at deleteduser.com if they were available to urgently cover a shift at a South African healthcare facility.

Side note, if you want to see how common of a pattern this is, and I can't believe I didn't think of this earlier, go search Github.com for 'deleteduser.com', lots of examples of delete functions from apps there that do this type of thing.

I added 5 variations on this domain (not going to say what they are just yet to not interfere with the results) and in the first 20 minutes I have 3 more orgs all sending PII to these addresses for now deleted users.

Includes a managed IT services provider in Malaysia's ticketing system which includes the full content of the ticket - system names, IP's etc.

Rather ironically a platform that helps companies "hire the world’s top remote talent without the search" is now on the list
yeah so i registered internaluser.com and wow
@SecureOwl that's mindblowing. You've just discovered a terrible secret that software devs have been committing. PII violations from so many orgs.