i was quite surprised to discover that no one had registered deleteduser [dot] com, and was curious to see how many emails i'd get if i registered it, assuming many orgs 'delete' logic probably just overwrote the email address with [email protected] or similar.

The answer, is at least 3 different orgs in the hour that I've owned that domain and been listening for email.

And yes, all of those emails contain the actual PII of the person who has been 'deleted' :-D

#infosec

Up to about 24 different orgs now, overnight had some emails containing PII of 'deleted' users from a:

UAE based Gym Chain
South African HR Platform
EU based Hotel Reservations Platform
India based Delivery Service

and best of all

US based Antivirus Manufacturer and Cybersecurity Provider

And of course the hotel reservations platform is happily spitting out the name of guests and their contact info to the Deleted User email address
Deleteduser.com —a $15 PII Magnet

When is a delete, not a delete? When it’s an publicly routable placeholder.

Medium
Thursday must be PHI day - a platform that appears to be used by care workers and psychologists is happily sending patient names and details to deleteduser dot com.

Couple of new additions today to the internet dumpster:

- Some internal system at one of the worlds largest and most recognizable consumer electronics manufacturer is telling deleteduser.com all about approved purchase orders, including direct links to the orders, and the names of all the people who are involved.

- More gyms, very common.

- Some platform used to offer temporary shifts to healthcare workers asked a nurse at deleteduser.com if they were available to urgently cover a shift at a South African healthcare facility.

Side note, if you want to see how common of a pattern this is, and I can't believe I didn't think of this earlier, go search Github.com for 'deleteduser.com', lots of examples of delete functions from apps there that do this type of thing.

I added 5 variations on this domain (not going to say what they are just yet to not interfere with the results) and in the first 20 minutes I have 3 more orgs all sending PII to these addresses for now deleted users.

Includes a managed IT services provider in Malaysia's ticketing system which includes the full content of the ticket - system names, IP's etc.

Rather ironically a platform that helps companies "hire the world’s top remote talent without the search" is now on the list
yeah so i registered internaluser.com and wow
oh noe - one of those places what sell knock off viagra does this

Haven’t done this because I’m an ethical sausage, but I do wonder - how many of these sites would happily send a password reset link to [email protected], and after resetting the password, how much order history/other PII and the like would be there?

I’d guess between 98-100% of them.

ok, curiosity won and I tried it on a couple

yes, they all willingly sent the password reset link to the domain

yes, they let me reset the password

no, they didn’t have mfa

yes, they let me log in to the “deleted” accounts

yes, i saw order histories, names, dob’s, last four of credit cards

yes, i disclosed to the security contacts i could find at the companies

yes, one of them was the viagra place

In one of the more ironic welcomes to the internet dumpster, an EU-based Bug Bounty program provider apparently uses a publicly routable placeholder domain for it's "deleted" users email addresses.

one org got back to me and said, 'yeah we effed up - and are fixing'

I was thinking of that scene in the bart falls down the well episode of the simpsons where at the end they say, 'and now to make sure nobody ever falls down this well again', followed by them putting up a small sign that says 'caution: well'.

I bet they'll run something like:

UPDATE users
SET email = REPLACE(email, '@deleteduser.com', '@deleteduser2.com')
WHERE email LIKE '%@deleteduser.com';

So no one ever falls down the well again.

Another good one - a European country's licensing authority for construction workers sends an email to deleteduser.com each time an employee is added to, presumably, the "deleted" users former company.

That email includes the name, trade and license info of the person being added, alongside the PII of the "deleted" user.

@SecureOwl "...and this is how we managed to send the DPO to the E.R.".