Estimated reading time: 9 minutes
There are billions of subdomains on the internet pointing to nothing. Silent Push calls them “billions of forgotten, abandoned, and misconfigured subdomains.” Most sit quietly. None of them look dangerous. Silent Push just proved how wrong that assumption is. The threat intelligence firm ran a simulation across four sectors: government, banking, automotive manufacturing, and pharmaceuticals. It gave the project a name built for headlines, dubbing DNS takeover risk Danglegeddon.
The Simulation
Silent Push started with 12,500 apex domains. Each one had a vulnerability disclosure or bug bounty program in place. That gave researchers safe harbor to test them.
Mike Sweeney, Silent Push’s Director of Preemptive Threat Intelligence, put it plainly. “Every one of those records is dangling and a liability for the companies,” Sweeney told CINI.
From that sample, researchers isolated 16,000 dangling subdomains. They automated takeovers of 4,000. Another 7,000 needed manual review. Of those, 5,000 turned out safe, thanks to provider-side safeguards.
Claude, Anthropic’s AI model, sped up the discovery process. Researchers used it to map the domains against known vulnerable provider CNAMEs and cross-check availability. A takeover script came together within hours.
Demonstrated, Not Modeled
Every takeover in this report actually happened. Silent Push’s researchers redirected the hijacked subdomains to their own infrastructure to prove the point. They disclosed every exposure responsibly afterward. The huge dollar figures later in this piece did not happen. They’re projections.
Sweeney draws that line clearly. “In each instance, our researchers demonstrated actual, successful takeover of the abandoned resource related to the identified organization’s dangling DNS infrastructure,” he told CINI. The projected losses for a full-scale cascading attack are Silent Push’s modeling, not measured claims data. Underwriters should read them as scenario analysis, not loss history.
Four Sectors, One Technique
Silent Push picked one target per sector based on willingness to be tested, not random sampling. “Our goal was to demonstrate that virtually any organization with dangling DNS infrastructure is vulnerable to a subdomain takeover,” Sweeney said. The Sweeney interview also referenced additional targets in aviation and AI firms. Silent Push hasn’t published sector-level detail on those, the way it did for the four core cases below.
Government
A U.S. federal agency left a DNS record pointing to an unassigned Azure Blob Storage resource. The hijacked page used a nautical theme. That folds easily into a spear-phishing campaign. It also inherits the built-in trust of a .gov domain.
Applied broadly, Silent Push says the same technique could reach into Department of Defense systems. The firm puts $66 billion of departmental resources at risk in that scenario. That figure is the department’s IT and cyberspace activities budget request for FY2026. It represents about 8% of DoD’s total $848.3 billion budget request.
Sweeney called the narrower framing a conservative choice. He also told CINI that questioning whether the impact could reach the broader budget is fair. IT and cyber infrastructure underpins most of what the department does.
Banking
A large French bank had an unassigned Azure Blob Storage resource pointing to a live application. Silent Push says Azure serves as cloud infrastructure for more than 80% of the world’s largest banks. That makes this a repeatable pattern, not an isolated miss.
Automotive
A U.S. automaker left a dangling record pointing to a development application gateway on an Azure VM, exposed to stored cross-site scripting from internal scripts. An attacker could harvest developer credentials this way, or use the VM to host malware behind a valid TLS certificate.
Silent Push points to last year’s Jaguar Land Rover attack as the real-world comparator. That incident halted production for five weeks. It cost the UK economy an estimated $2.5 billion, according to the UK’s Cyber Monitoring Centre. It also triggered a government-backed loan to keep JLR’s supply chain solvent. More than 5,000 supplier and dealer organizations felt the disruption, and the Bank of England cited it in its own GDP commentary. Silent Push pegs JLR’s direct cost at $350 million.
Pharmaceuticals
A global pharma company left a record pointing to Paperturn, an online publishing platform that allows custom CNAME assignment. It doesn’t require domain verification first. Silent Push estimates 75% to 85% of major pharmaceutical enterprises run on Azure. The firm points to Merck’s 2017 NotPetya losses as a reference point: roughly $1.4 billion. That’s the scale of disruption Silent Push says a coordinated pharma-sector attack could reach. The comparison is illustrative, not a claims estimate.
Why CNAME, MX, and NS Records Carry Different Risk
A dangling CNAME still resolves. The service behind it is gone. Whoever claims that resource inherits the hostname, the brand’s reputation, and often a valid TLS certificate. This is the condition Silent Push exploited in every simulation, and the most common one by volume.
A dangling MX record means mail addressed to the domain routes to a host that no longer exists. An attacker who reclaims that host receives password resets, invoices, and account recovery email meant for someone else.
A dangling NS record is rarer and worse. It hands over an entire zone, not one hostname, including the ability to create records that never existed. As Silent Push puts it, “One dangling NS record can be worth more to an attacker than a thousand dangling CNAMEs.”
What It Takes to Turn a Foothold Into a Breach
A hijacked subdomain is a launchpad, not a breach by itself. Sweeney is direct about the gap between the two. “A taken-over subdomain isn’t itself an intrusion; it’s a start, or a trusted launchpad,” he told CINI.
Reaching internal systems from there takes separate failures: weak MFA, excessive internal trust between systems, or third-party relationships that extend access too far. The dangling record opens the door. What sits behind it decides how bad the loss gets.
Should Dangling DNS Be an Underwriting Control?
Sweeney thinks so, without hedging. “DNS is a foundational technology used by companies, so the hygiene of the infrastructure needs to be forefront,” he said. He wants DNS review treated the way carriers already treat MFA and endpoint detection. That means a specific, checkable control, reviewed more often than pre-AI cadences allowed.
The Accumulation Risk Underwriters Should Watch
Widespread dangling DNS exposure worries Sweeney for a reason specific to insurance math. “If many policyholders across unrelated sectors depend on the same handful of cloud platforms, a single repeatable technique…can be run against many targets simultaneously using the same low-cost playbook, triggering correlated claims across an entire book rather than isolated ones,” he said. Concentration on one cloud provider breaks the diversification assumption a book of business relies on.
It’s worth separating two different claims inside Silent Push’s own report here. AI clearly sped up discovery and enumeration, the desk-research phase of finding candidates. It’s a separate question whether AI also shortens the manual-verification step. The firm’s own numbers show 7,000 of 16,000 candidates still needed that step. Those are different timelines for an accumulation event. Underwriters modeling correlated claims should ask Silent Push which part of the clock AI actually moved.
Cybersecurity’s Middle Age
Sweeney’s closing point reaches beyond DNS. “I would say the start of the reassessment needs to be ‘what technologies are absolutely foundational for the public internet to work and be safer,'” he said, pointing to migrations already underway: HTTP to HTTPS, Telnet to SSH, DNS to encrypted alternatives like DoH.
CINI has made a version of this point before. Craig Ramsay of Omada made a similar case on CINI’s identity governance podcast last year. Legacy identity systems, he said, are “ticking time bombs of technical debt.” Dangling DNS is the same debt, wearing a different name.
Fixing It: A Sequencing Rule
Silent Push’s own advice is simple. Work the record types in order of blast radius: NS first, then MX, then external CNAMEs, then internal ones. Delete what’s unused. Reclaim what’s still claimable before removing the reference.
The underlying fix is a sequencing rule for IT teams: “the DNS record dies before the cloud resource does.” Most of the exposure in this study came from teams decommissioning a storage account or VM and leaving the pointer behind. Reversing that order at the decommissioning stage removes the risk at its source.
A few more moves round out Silent Push’s recommendations:
- Require domain-ownership verification, such as Azure’s TXT-based asuid check.
- Publish CAA records to limit which certificate authorities can issue for your domains.
- Monitor certificate transparency logs for anything you didn’t request.
- Assign an owner and a review date to every DNS record. Employee turnover and M&A activity are what create orphaned zones in the first place.
The Sprawl Problem Isn’t Just DNS
Dangling DNS is one branch of a wider problem CINI has tracked all year. Non-human identities now outnumber people 45 to 1 inside most organizations, Myriad360’s Marshall Sorensen told CINI earlier this year. Permissions nobody remembers granting are exactly the kind of standing exposure Danglegeddon describes.
Forgotten, unclassified data creates the same problem for breach severity once an attacker gets in, RecordPoint’s Josh Mason argued on CINI’s podcast earlier this year. Per Verizon’s 2026 DBIR, unpatched vulnerabilities and third-party exposure are now the more common way in. Stolen passwords aren’t.
The common thread is what happens to infrastructure, identities, and data after the team that created them moves on. None of it gets an exit interview.
FAQ – Dangling DNS Takeover Risk
A dangling DNS record points to a resource, like a cloud storage bucket or web app, that no longer exists or was never claimed. Anyone can claim that resource and inherit the trust of the original domain.
Researchers demonstrated real, successful takeovers of abandoned cloud resources tied to a federal agency, a bank, an automaker, and a pharmaceutical company, all disclosed responsibly through vulnerability programs. The multi-billion-dollar loss figures elsewhere in the report are modeled projections, not measured outcomes.
An NS record hands over control of an entire DNS zone, not one hostname. Whoever claims it can create any record type inside that zone, including ones that never existed before.
Silent Push’s Sweeney argues yes, comparing it to MFA and endpoint detection: low-cost to fix, and worth reviewing on a shorter cycle than most companies currently use.
Because so many organizations share the same handful of cloud providers, a single repeatable takeover technique can be run against many unrelated policyholders at once, producing correlated claims instead of isolated ones.
Related Cyber Insurance Posts
- Burp AT Puts Agentic AI on the Pentest. PortSwigger Keeps It Caged.
- Cyber Insurance Policy Impact: NINJIO Insights Delivers Cyber Risk Reporting(Opens in a new browser tab)
- Silent Push 6.0 Gives Cyber Underwriters Sharper Threat Intelligence(Opens in a new browser tab)
- DDoS Attacks Became A Constant, Link11(Opens in a new browser tab)
- AI Risk Reshapes Cyber Insurance: Key Takeaways From Lockton Re and Armilla’s “Ready or Not”(Opens in a new browser tab)