HomeSecurityAbandoned iCalendar Sync Domains - 4 million devices at risk

Abandoned iCalendar Sync Domains – 4 million devices at risk

Over 390 abandoned iCalendar Sync Domains could expose ~4 million devices to risks.

Abandoned iCalendar Sync Domains - 4 million devices at risk

Digital calendars are now an integral part of everyday life, for both personal and professional purposes. From planning vacations to managing meetings, users often subscribe to external calendarsso that updates automatically arrive on their device. However, this seemingly practical habit hides a serious and underestimated risk.

How an Expired Address Can Open the Door to Intruders

Each calendar subscription creates a permanent “bridge” between the user’s device and the external server that hosts it. If the specific domain is not renewed and eventually expires, it becomes vulnerable to re-registration by third parties. This is exactly where cybercriminals exploit the gap: they buy the abandoned domain and immediately inherit the trust that the original legitimate subscription had created.

See also: GreyNoise IP Check: Find out if your IP is “working” for hackers

Most worryingly, the attack is triggered without any user intervention. The device continues to send sync requests in the background, mistakenly believing that the domain is still secure. This gives the attacker an automatic communication channel through which to push malicious content.

From Scareware to Phishing: What Could Hit the Calendar

Attackers leverage this “trust channel” to push scareware that appears as a system notification, deceptive links that look like promotions, or even fake reminders that lead to phishing pages. Because the entry is made through the calendar interface and not via email, most security filters are bypassed, making the method extremely effective and difficult to detect.

Abandoned iCalendar Sync Domains - 4 million devices at risk

Bitsight's Discovery: A Network of 390 Abandoned Domains

Bitsight discovered the problem by investigating a seemingly innocent domain that was distributing the “holiday events ” of a specific calendar. The analysis revealed that the incident was the tip of the iceberg: 390 abandoned domains were still receiving sync requests from users, as if they were functioning normally .

See also: Vulnerability in Angular HTTP Client exposes XSRF token

Even more impressive was the scope of the report: around four million unique IPs were communicating with these domains every day. Most of them came from devices iOS and macOS, which demonstrates how deeply embedded the habit of using external calendars is in the Apple ecosystem.

What Technical Analysis of the Synchronization Movement Shows

The researchers identified patterns that revealed the true nature of the background requests. The requests included an HTTP header accepting iCalendar files, while the User-Agent revealed the iOS Calendar daemon—a clear indication that the traffic was not coming from the user, but from an automated synchronization process.

A typical example of a request:

GET /[URI] Host: [Target_Domain] User-Agent: iOS/17.5.1 (21F90) dataaccessd/1.0 Accept: text/calendar

The returned malicious .ics files could contain events with modified content or embedded links. In several cases, the domains also hosted highly unreadable JavaScript designed for further exploitation.

See also: Malicious Chrome extension introduces hidden SOL fees into Solana transactions

Abandoned iCalendar Sync Domains - 4 million devices at risk

How Organizations and Users Can Protect Themselves

This new threat shows how vulnerable a device can be to something as simple as an expired domain registration. Experts recommend regularly checking active calendar subscriptions, removing unused ones, and monitoring suspicious iCalendar. At the same time, IT administrators are urged to adopt firewall rules that block domains with suspicious behavior, even if they come from “innocent” channels.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

In a world where devices are constantly syncing data in the background, understanding these new tactics is essential to protecting millions of users from invisible breaches.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS