Tech company ignored ethical hacker’s emails, so he contacted himself from their account
He pulled an "Uno Reverse."

Computer breach. By Cybernews/Unsplash.
- Security researcher Zachi says he found vulnerabilities in an undisclosed app from Betterapp Tech.
- He says Betterapp Tech ignored his reports for about two months.
- Zachi claimed he emailed the company from its own address after earlier messages received no response.
- Cybernews researchers say open systems, admin access, or email misconfiguration could explain the incident.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
After vulnerability disclosures fell on deaf ears, a security researcher decided to show the internet just how vulnerable one company really was.
Developer and security researcher Zachi (@iam_zachi on X) found an exploit in an app by the company Betterapp Tech.
From what we could find, Betterapp Tech is a productivity and utility app company that develops apps such as “My Diary,” “Good Calendar,” and “Ringtone Maker.”
The researcher did note that the company has 2 different domains: betterapplab and betterapptech.
Zachi reached out to “betterapptech,” which functions as the vendor for the apps.
“They’re an agency and probably separating domains per app for a cleaner overview,” explained the researcher.
Zachi claims to have found an exploit in one of its apps roughly 2 months before his post went viral at the start of this month.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
The post showed an email from Zachi to “support@betterapptech” with the title “YOUR APP IS LEAKING.”
This email is presumably a follow-up from Zachi after receiving no response following his initial messages.
Cybernews has contacted Zachi for comment.
In the email, Zachi compares the undisclosed app to “Swiss cheese” due to the number of vulnerabilities he found.
“Your app is as full of holes as Swiss cheese,” the researcher told the company.
After receiving no response, Zachi decided to write to them one last time.
But this time, he allegedly wrote to them from their own email address.
I’M WRITING TO YOU RIGHT NOW FROM YOUR OWN EMAIL,Security researcher Zachi supposedly wrote using the company's exploited email.
How is this even possible?
While it’s hard to say for certain how Zachi managed to access the company’s email without having spoken to the researcher, our own security researchers have some suspicions.
Cybernews researchers speculate that Zachi could’ve exploited an open system or a known admin account to get access to the company’s internal email account.
This could also be the result of an email misconfiguration, which allows hackers or bug hunters to use other email addresses to impersonate companies.
But we won’t know for certain until we speak to Zachi himself.