A friend handed me her iPhone last week with the specific exhaustion of a person losing an argument to an object. A calendar event would not go away. It was titled “⚠️ Action Required: Permanent data loss Warning!” — warning emoji included, because these people do not believe in subtlety — and it claimed to come from “iCloud® Storage.” She’d tap Decline. It came back. She’d tap Decline again. It came back again, refreshed and cheerful, like a raccoon that has reviewed your objections to it living on your porch and found them adorable.
Good news first: her phone was fine. Nothing installed, nothing infected, nothing “hacked” in the scary sense. This was a scam invitation — junk mail wearing an Apple badge it printed at home — and it’s one of the most common and most aggressively irritating things hitting phones right now.
So let’s do three things: prove it’s fake in ten seconds, evict it for good, and — because I pulled the thread on who’s behind it — spend a minute enjoying how deeply unimpressive they are.
It’s fake, and it can’t hide it
The whole scam runs on one bet: that you’ll panic and tap before you read. Read, and it collapses.
The address gives it up, and you read it backwards. The link points somewhere like icloud-storage-alert.greatmail.top. Your eye catches “icloud” and relaxes. Don’t. The part that says who really owns a web address is the end — the last chunk before the first slash. Apple lives at apple.com and icloud.com. This lives at greatmail.top, which is not Apple, has never been Apple, and has a restraining order from Apple’s lawyers pending in my imagination. They parked “icloud” at the front hoping you’d stop reading early. Don’t stop reading early.
The sender name is a Halloween costume. “iCloud® Storage” is just text typed into a name field — anyone can type it. They added the little ® for credibility, which is the funniest detail in the whole thing: a scammer pausing to make sure their fake brand looked properly trademarked.
Apple doesn’t do this. Apple never warns you about storage through a calendar event. Real notices live in Settings or arrive by email. Not as a meeting that RSVPs itself onto your week.
And the timing is a confession. The event ran eleven straight days, which is why it squatted on every single day of her calendar. That’s not a schedule. That’s a man standing on your lawn with a sign.
Why it would not die
This is the part that made it feel like a hack, so it’s worth thirty seconds.
Your calendar doesn’t actually live on your phone. It lives in your account — iCloud, Gmail, or Outlook — and the phone just shows a copy. So when you delete or decline the event on the phone, the account still has the original, and the next sync cheerfully hands it right back. You weren’t losing to the event. You were losing to a photocopier.
And tapping Decline is the one move that actively helps them. Declining sends a reply, and that reply tells the scammer exactly what they were fishing for: the address is real, a human reads it, and the human taps buttons. You RSVP’d “no thanks” to a party whose entire purpose was to find out whether you’d answer the door. You answered the door.
So the rule is almost insultingly simple: don’t tap anything. Not the link, not Accept, not Maybe, not Decline. A calendar invite you never touch is just an ugly sticky note. Ignore it completely and it’s powerless. It hates that.
Who’s behind it (brace yourself — it’s not a genius)
Because this is what I do, I looked into the actual invite. I’ll keep what I know separate from what I’m guessing, because that’s the job — but the short version is there’s no hooded mastermind here. This is spam with extra steps.
Two tells:
They have a CRM. The link had a tracking code baked into it — the exact same kind of thing a marketing email uses to know whether you opened it. Decoded, it tags which mailing list you came from, which “campaign” this was, and which specific person you are. So picture the villain honestly: somewhere there’s a scammer with a dashboard, checking his open rates, quietly disappointed that engagement is down this quarter. You weren’t hunted by a criminal genius. You were a row in a spreadsheet, and the spreadsheet has analytics.
They shop at the internet’s dollar store. The scam runs off a .top domain — one of the cheapest, most abuse-ridden corners of the web, and consistently ranked among the very worst for phishing. Real infrastructure costs money; they declined to spend it. The entire operation is a free-tier bulk mailer, a knockoff logo, and a trademark symbol they did not earn.
None of that makes them harmless — cheap and annoying still steals real passwords and real money. But it should kill the mental image of a mastermind. Their one clever move was noticing that your calendar lets total strangers put things on it without asking permission. That’s the whole trick. That’s it.
How to actually evict it
Fix it at the account, not the phone, or it just re-syncs back. Find which account it’s in: open Calendar, tap Calendars at the bottom, and see whether the junk event sits under iCloud, Gmail, or Outlook.
- iCloud: open the event, scroll to the bottom, tap Report Junk if it’s there — deletes it and reports the sender without replying to them. The clean kill. No button? Sign in at iCloud.com on a computer, open Calendar, delete it there.
- Gmail: on a computer, calendar.google.com → open the event → delete and report as spam. Then delete the original invite email in Gmail too, or it grows back.
- Outlook: on a computer, delete the invite email from the inbox, delete the event from the calendar, and block the sender.
Then sweep the phone: Settings → Calendar → Accounts, remove anything you don’t recognize; and Settings → General → VPN & Device Management, remove any profile you didn’t personally install. Gone from the account, gone from the phone.
Slam the door for good
One setting ends this entire genre: stop your calendar from auto-adding invites from strangers.
- iCloud: iCloud.com → Calendar settings → set invitations to arrive as email instead of on the calendar.
- Gmail: calendar.google.com → Settings → Event settings → “Add invitations to my calendar” → only if the sender is known.
- Outlook: Settings → Calendar → Events from email → turn off automatic adding.
Three habits that make you a hard target: never answer an invite you weren’t expecting (silence gives them nothing); check your storage the real way (Settings → [your name] → iCloud, never a link); and read every address from the end — something.apple.com is Apple, apple.something.top is a stranger in an Apple hat.
If you already tapped
Opening the page almost certainly didn’t hurt your phone. What matters is whether you typed something.
- Apple password? Change it now at account.apple.com (a link you type yourself), check the signed-in devices, remove anything you don’t recognize, confirm two-factor is on.
- Card number? Call the number on the back of the card, tell them it went into a scam site, let them handle it.
- Nothing? Close the page, run the removal steps, carry on. You’re fine.
Forward a sample to reportphishing@apple.com while you’re at it — it helps get the fake sites taken down.
The actual lesson
Strip the emoji and the fake ® and here’s the machine underneath: manufacture a deadline, wear a trusted logo, and make yourself impossible to ignore by camping on every day of someone’s week — then bank on them being annoyed enough to tap something just to make it stop. The entire scam is engineered around your irritation. So do the exact opposite of what the irritation wants: don’t tap, kill it at the account, switch off auto-add, and go live your life. The raccoon only wins if you keep arguing with it.
If one of these has its claws in your calendar and you can’t tell which account it’s hiding in — or you tapped something and want a straight, no-drama answer about whether it actually mattered — that’s the kind of thing I do. No panic, no judgment, no “your phone has 37 viruses.” Just a real look and a clear next step.
General guidance to help you stay safe, not a guarantee every scam gets caught. If something doesn’t look right, stop and ask before you tap.
