Over 390 abandoned iCalendar Sync Domains could expose ~4 million devices to risks.

Digital calendars are now an integral part of everyday life, for both personal and professional purposes. From planning vacations to managing meetings, users often subscribe to external calendarsso that updates automatically arrive on their device. However, this seemingly practical habit hides a serious and underestimated risk.
How an Expired Address Can Open the Door to Intruders
Each calendar subscription creates a permanent “bridge” between the user’s device and the external server that hosts it. If the specific domain is not renewed and eventually expires, it becomes vulnerable to re-registration by third parties. This is exactly where cybercriminals exploit the gap: they buy the abandoned domain and immediately inherit the trust that the original legitimate subscription had created.
See also: GreyNoise IP Check: Find out if your IP is “working” for hackers
Most worryingly, the attack is triggered without any user intervention. The device continues to send sync requests in the background, mistakenly believing that the domain is still secure. This gives the attacker an automatic communication channel through which to push malicious content.
From Scareware to Phishing: What Could Hit the Calendar
Attackers leverage this “trust channel” to push scareware that appears as a system notification, deceptive links that look like promotions, or even fake reminders that lead to phishing pages. Because the entry is made through the calendar interface and not via email, most security filters are bypassed, making the method extremely effective and difficult to detect.

Bitsight's Discovery: A Network of 390 Abandoned Domains
Bitsight discovered the problem by investigating a seemingly innocent domain that was distributing the “holiday events ” of a specific calendar. The analysis revealed that the incident was the tip of the iceberg: 390 abandoned domains were still receiving sync requests from users, as if they were functioning normally .
See also: Vulnerability in Angular HTTP Client exposes XSRF token
Even more impressive was the scope of the report: around four million unique IPs were communicating with these domains every day. Most of them came from devices iOS and macOS, which demonstrates how deeply embedded the habit of using external calendars is in the Apple ecosystem.
What Technical Analysis of the Synchronization Movement Shows
The researchers identified patterns that revealed the true nature of the background requests. The requests included an HTTP header accepting iCalendar files, while the User-Agent revealed the iOS Calendar daemon—a clear indication that the traffic was not coming from the user, but from an automated synchronization process.
A typical example of a request:
GET /[URI] Host: [Target_Domain] User-Agent: iOS/17.5.1 (21F90) dataaccessd/1.0 Accept: text/calendar
The returned malicious .ics files could contain events with modified content or embedded links. In several cases, the domains also hosted highly unreadable JavaScript designed for further exploitation.
See also: Malicious Chrome extension introduces hidden SOL fees into Solana transactions

How Organizations and Users Can Protect Themselves
This new threat shows how vulnerable a device can be to something as simple as an expired domain registration. Experts recommend regularly checking active calendar subscriptions, removing unused ones, and monitoring suspicious iCalendar. At the same time, IT administrators are urged to adopt firewall rules that block domains with suspicious behavior, even if they come from “innocent” channels.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
In a world where devices are constantly syncing data in the background, understanding these new tactics is essential to protecting millions of users from invisible breaches.
