Expired Anti-Spam Domain Leads to Email Mayhem at NZ’s Eden Park Stadium


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

Brief Overview

  • Eden Park’s email configuration included a lapsed domain, presenting possible email security threats.
  • Consultant Alex Shakhov collected DMARC reports for a year as a result of this configuration error.
  • Reports disclosed Eden Park’s interactions with 600 organizations, such as sponsors and representatives.
  • The stadium asserts that no data breach occurred and has revised its DNS settings.
  • Fujitsu verified that the expired domain was associated with a discontinued anti-spam service.

Email Issues at Eden Park

Eden Park, New Zealand’s principal stadium, neglected a vital email configuration flaw for several years. This error involved the inclusion of a lapsed anti-spam domain, enabling the potential interception of sensitive message authentication reports.

Email consultant Alex Shakhov, based in the US, uncovered that the DMARC record in Eden Park’s DNS pointed to spamcontrol.co.nz, a defunct domain. By acquiring this domain, Shakhov was able to receive DMARC reports, providing quick insight into Eden Park’s email system.

Findings from Collected Reports

In just one month, Shakhov analyzed Eden Park’s communication with 600 organizations, including sponsors and event management firms. This exposure had the potential to facilitate targeted phishing attempts if exploited by malicious entities.

Despite multiple efforts to inform Eden Park about the issue, Shakhov’s alerts went ignored for more than a year. His research underscored the considerable security vulnerabilities stemming from the lapsed domain reference.

Response and Reassurances from the Stadium

Eden Park acknowledged the problem and claimed that no data breaches occurred. The stadium has since revised its DNS configuration to remove the expired domain reference. Eden Park reassured that comprehensive cybersecurity measures are in place, actively monitored by their IT team.

However, the stadium did not explain the delay in responding to Shakhov’s warnings.

Understanding DMARC Configuration Errors

DMARC, which stands for domain-based message authentication, reporting, and conformance, aids in safeguarding domains against email spoofing. However, misconfigurations like those at Eden Park can inadvertently expose sensitive information.

DMARC records designate email addresses for receiving reports, but outdated or incorrect configurations may lead to data vulnerabilities. Shakhov’s findings serve as a cautionary example of the necessity for updated and accurate DMARC settings.

Fujitsu’s Involvement and Domain Background

The lapsed domain, spamcontrol.co.nz, was linked to Fujitsu’s operations in Australia and New Zealand. Fujitsu confirmed that it was part of an anti-spam service that was discontinued in June 2021.

Despite this setback, Fujitsu reported no evidence of negative impacts on existing customer systems due to the domain’s discontinuation.

Broader Implications and Research Insights

Shakhov’s evaluations found similar DMARC configuration errors across other organizations. A 2023 study revealed that 26% of domains with external DMARC reporting addresses failed verification checks, highlighting the common occurrence of such security failures.

Shakhov expressed his willingness to return the spamcontrol.co.nz domain to Fujitsu.

Conclusion

The failure to address an expired domain in Eden Park’s email configuration emphasizes the need for regular DNS audits. While there was no data breach, the risk for misuse was considerable, illustrating the necessity for vigilant cybersecurity practices.

Reader questions

Frequently asked questions

Fast answers to the questions readers ask most about Expired Anti-Spam Domain Leads to Email Mayhem at NZ's Eden Park Stadium.

What led to the email security problem at Eden Park?

The email settings at Eden Park referenced an expired domain, enabling the capture of DMARC reports.

Who identified the configuration error?

The error was identified by US-based email consultant Alex Shakhov.

Was there any data breach at Eden Park?

Eden Park indicated that no data was compromised despite the oversight.

What steps did Eden Park take post-discovery?

Eden Park updated its DNS configuration to remove the lapsed domain reference and assured strong cybersecurity measures are in place.

How was Fujitsu connected to the expired domain?

The domain was part of a defunct anti-spam service formerly managed by Fujitsu in Australia and New Zealand.

Are similar DMARC configuration issues prevalent?

A study indicated that 26% of domains with external DMARC reporting addresses failed verification, pointing to the commonality of such misconfigurations.

Posted by Matthew Miller

Matthew Miller is a Brisbane-based Consumer Technology Editor at Techbest covering breaking Australia tech news.

Leave a Reply

Your email address will not be published. Required fields are marked *