61,500 Abandoned IoT Apps Continue to Send Sensitive Data to Inactive Servers
A study by the University of Massachusetts revealed that 74% of abandoned IoT apps contain software dependencies associated with documented vulnerabilities, exposing millions of users to significant security risks. The study analyzed 61,500 Android apps for IoT devices, defined as "abandoned" if not updated for at least two years or removed from Google Play Store by March 2025.
Quick Response
Abandoned IoT apps pose a critical security risk: 74% contain known vulnerabilities, 25% send data to non-existent servers, and 11% to domains associated with phishing or malware. Many of these apps, despite not being updated for years, are still used by millions of users to manage smart home devices.
Among the abandoned apps, 12 had surpassed 100 million downloads before development was discontinued. According to researchers, 5% of the top 1,000 apps on Google Play Store are updated less than once a year, while 869,000 apps have not received updates for over two years.
Vulnerabilities and Unreachable Domains
Most abandoned apps use software libraries associated with vulnerabilities registered in the National Vulnerability Database, many of which are classified as high severity. The apps contain thousands of hard-coded web addresses: about a quarter of the unique domains no longer resolve, and each app contains at least one FQDN that is not reachable via DNS.
A separate analysis discovered that 11% of the extracted web addresses corresponded to domains blocked for phishing, scams, spyware, and malware. More than two-thirds of the apps in the dataset contained at least one blocked domain.
Sensitive Data Sent to Unsafe Servers
Abandoned apps request permissions beyond simple connectivity, including access to external memory, precise location, and camera. The collected data is transmitted almost exclusively via Wi-Fi. 38.4% of data flow sources and destinations were associated with unreachable, blocked, or changed ownership domains.
For comparison, analyzing 500 of the most installed and updated IoT apps after March 2025, researchers found this problem in less than 1% of the active group.
Outdated Encryption and Developers' Responses
Some abandoned apps use cryptographic algorithms not recommended such as DES, MD5, or RC4, although with a lower frequency than active apps. Researchers interpreted this as a sign that outdated encryption is a widespread problem in the IoT app ecosystem.
The authors of the study contacted the developers of thousands of apps in the dataset. About 20% of the emails were rejected as undeliverable. Among the responses received, some vendors removed their apps from Google Play, others claimed that the reported vulnerability did not apply to their product, and a larger group acknowledged the problem and stated they were working on a solution.
Differences Between Abandoned and Active Apps
Dependencies associated with CVEs were detected at similar rates in both groups: 73.6% of abandoned apps and 69.8% of active apps. Deprecated encryption was more common in the active group, present in 17% of those apps compared to 8.4% of abandoned apps.
The most significant difference was in the destination of sensitive data: 40.8% of unique destinations in the abandoned app data was associated with vulnerable or unreachable endpoints, compared to 0.4% in the active comparison group.
Impact on Compliance and Cyber Insurance
These results raise serious concerns for companies seeking to comply with regulations on NIS2 compliance and digital operational resilience according to the DORA regulation. The use of abandoned IoT apps could make it more difficult to obtain an ISO 27001 certification or maintain a cyber risk policy under favorable conditions.
Organizations using IoT devices should consider implementing a SIEM to actively monitor data flows and an MDR service for a rapid response to incidents. Additionally, consider adopting corporate DLP solutions to protect sensitive data transmitted by these apps.
Considerations for Risk Management
The persistence of these abandoned apps represents a significant security risk for IoT ecosystems. Organizations should conduct regular assessments of the IoT devices and apps in use, with particular attention to those that have not received updates for a long time. Implementing a zero trust architecture could help mitigate the risks associated with these apps.
For companies managing large amounts of sensitive data through IoT devices, it may be useful to explore disaster recovery as a service solutions to ensure operational continuity in case of data compromise.
Future Perspectives and Recommendations
The research highlights the need for a more proactive approach to managing the security of IoT apps. Developers should consider adopting safer development practices and ensuring long-term support for their applications. Distribution platforms like Google Play Store could implement stricter policies for removing abandoned apps.
Organizations should consider implementing a managed Security Operations Center to continuously monitor IoT devices and promptly identify potential vulnerabilities. Additionally, consider adopting a robust identity access management system to limit access to sensitive data.
Impact on the Cyber Insurance Market
The widespread presence of these vulnerabilities is already affecting the cyber insurance market. Some providers are reviewing subscription criteria for companies using IoT devices, directly impacting the cyber insurance cost. Policies for organizations with abandoned IoT apps could see premium increases of up to 30%, according to recent Aon data.
Evolution of Risk in the IoT Ecosystem
The situation highlights a structural problem in the IoT ecosystem: the discrepancy between the useful life of devices (estimated at about a decade) and the lifecycle of the apps that control them. This gap creates a vulnerability window that could widen further with the expected 25% increase in connected IoT devices by 2030, according to Gartner.
Implications for Incident Response Strategies
Organizations using these abandoned apps should review their incident response strategies. The specific nature of these vulnerabilities requires the integration of specialized breach remediation solutions to effectively manage potential incidents arising from these unmanaged endpoints.
Challenges for SOC as a Service Providers
Providers of managed Security Operations Center are facing new challenges in monitoring these devices. The decentralized and outdated nature of abandoned IoT apps requires the adoption of advanced analysis techniques, such as machine learning, to identify anomalies in data flows.
Impact on Corporate Risk Management
For companies, the presence of these apps represents a significant operational risk that must be assessed within the broader context of corporate risk management. The adoption of a zero trust architecture framework could offer a partial solution, implementing strict access controls to limit exposure.
Considerations for Protecting Sensitive Data
The transmission of sensitive data to unreachable or compromised servers raises serious concerns about sensitive data protection. Organizations should consider implementing corporate DLP solutions to monitor and control data flows from these devices.
Future Perspectives for IoT Developers
IoT app developers will face increasing pressure to ensure long-term support for their products. The adoption of safer development practices, such as continuous integration and automated vulnerability testing, will be crucial to addressing consumer and insurer concerns.
Evolution of IoT Security Regulations
These results could accelerate the development of specific regulations for IoT security. The European Union is already considering the introduction of mandatory requirements for security updates, similar to those proposed in the NIS2 directive, which could extend to IoT devices in the coming years.
Impact on Compliance Strategies
For organizations subject to NIS2 compliance and the DORA regulation, the presence of these apps represents a significant compliance risk. Security assessments will need to explicitly include the identification and management of these abandoned apps to avoid sanctions or loss of certifications.
Challenges for Security Audits
Security auditors will need to adapt their methods to address this new class of vulnerabilities. Traditional security audits may not be sufficient to identify abandoned IoT apps, requiring the adoption of more advanced and specialized analysis techniques.
Perspectives for the IoT Device Market
The IoT device market could see a significant change in the coming years, with an increase in demand for more secure and sustainable solutions. IoT device manufacturers may need to guarantee longer support periods for their apps, responding to consumer and insurer concerns.
Impact on the Value of Tech Companies
For tech companies that develop IoT apps, managing these vulnerabilities could have a significant impact on their value. Investors may increasingly favor companies that demonstrate a proactive commitment to security and compliance, potentially influencing corporate valuations.
Considerations for End Users
End users should be aware of the risks associated with using abandoned IoT apps. The lack of updates and the potential sending of sensitive data to unsafe servers represent a significant risk to personal privacy and security. Users should consider adopting more robust security practices, such as using separate networks for IoT devices.
Perspectives for the Adoption of Security Standards
The industry may see an increase in the adoption of security standards such as ISO 27001 for IoT apps. These standards could offer a framework to ensure that apps are developed and maintained securely, reducing risks for end users and organizations.
Impact on Cyber Insurance Strategies
Cyber insurance companies are reviewing their policies in response to these findings. The adoption of specific clauses to cover risks associated with abandoned IoT apps could become common practice, influencing premiums and policy conditions.
Perspectives for Technological Innovation
These challenges could stimulate technological innovation, with the development of new solutions to manage and protect IoT devices. The adoption of advanced technologies such as artificial intelligence and machine learning could offer new ways to identify and mitigate risks associated with these apps.
Conclusion and Future Forecasts
The situation of abandoned IoT apps represents a complex challenge that requires a multi-faceted approach. Developers, end users, and organizations will need to collaborate to address these vulnerabilities and ensure a safer IoT ecosystem. In the coming years, we are likely to see an increase in regulations, security standards, and technological solutions to address these challenges, driving significant change in the IoT device market.
Frequently Asked Questions
What is the impact of abandoned IoT apps on corporate security?
Abandoned IoT apps pose a significant risk to corporate security, exposing sensitive data to known vulnerabilities and potential attacks. Organizations must carefully evaluate the use of these apps and consider safer alternative solutions.
How can companies mitigate the risks associated with these apps?
Companies can mitigate risks by implementing breach remediation solutions, adopting a zero trust architecture, and conducting regular assessments of IoT devices in use. The adoption of a SIEM for active monitoring of data flows is highly recommended.
What are the future prospects for IoT security?
In the coming years, we are likely to see an increase in regulations, security standards, and technological solutions to address the challenges associated with abandoned IoT apps. The adoption of advanced technologies such as artificial intelligence and machine learning could offer new ways to identify and mitigate risks.
Editorial Note and Disclaimer
The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.
GoYou does not constitute a journalistic publication nor an editorial product under Law No. 62/2001 and does not provide real-time information.
The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any responsibility for the improper use of the information published.
In the Crypto sector, every investment involves risks: readers are invited to always inform themselves independently before making any decision.