08.09.26

Why cybercriminals love dormant online accounts and how to lock them down

Old online accounts are easy to forget. You may still have accounts for shopping sites, old email providers, gaming platforms, job boards, social apps, travel sites, forums, cloud tools, or services you tried once and never used again. Cybercriminals love those dormant accounts because nobody is watching them.

A dormant account can still hold personal data, saved payment details, old messages, reused passwords, recovery email links, and access to connected apps. If attackers break in, they may use that account to steal information, impersonate you, or reset passwords elsewhere.

What is a dormant online account?

A dormant online account is an account you no longer use but that still exists. That could mean you have not logged in for months or years, but the account still has your username, email address, password, profile data, purchase history, or saved files.

Google’s Inactive Google Account Policy defines an inactive Google Account as one that has not been used within a two-year period, and Google says inactive personal accounts and their data may be deleted after that period. Google also explains in its inactive account policy update that accounts unused for long periods are more likely to be compromised because they often rely on old or reused passwords and receive fewer security checks from the user.

Why do hackers target old accounts?

Hackers target dormant accounts because old accounts often have weak security and low visibility. You are less likely to notice a suspicious login if you never check the account.

Cybercriminals may use dormant accounts to:

  • Test stolen passwords from old data breaches
  • Send scams from a trusted-looking profile
  • Access saved addresses, payment details, or documents
  • Reset passwords on connected accounts
  • Recover access to other services
  • Bypass suspicion because the account looks legitimate
  • Hide activity for weeks or months

Microsoft says stale accounts pose a security risk because attackers can use compromised inactive accounts to gain unauthorized access, move laterally, or escalate privileges. While that Microsoft guidance focuses on organizational accounts, the same basic idea applies to personal accounts: unused access still creates risk.

How big is the account takeover risk?

Dormant accounts become especially risky when you reuse passwords. Verizon’s 2025 Data Breach Investigations Report is summarized in MojoAuth’s account takeover and credential stuffing analysis, which says credential stuffing accounted for a median 19% of all authentication attempts in single sign-on provider logs. That means a large share of login attempts on typical services may be attackers testing stolen credentials.

If an old password leaked years ago and you reused it across accounts, a criminal can try that same email-and-password combination on shopping, banking, email, cloud, and social platforms.

How does deleting dormant accounts help someone become safer online?

Cleaning up dormant accounts helps someone become safer online because it reduces the number of doors criminals can try. Every forgotten account is another place where your email, password, personal data, or payment history might sit unprotected.

This habit helps you:

  • Reduce your digital footprint
  • Remove accounts you no longer monitor
  • Limit damage from old breach data
  • Stop password reuse from spreading risk
  • Cut down on scam and spam exposure
  • Protect old messages, resumes, addresses, and files
  • Make account recovery easier during a real emergency

Think of dormant accounts like old house keys. If you do not need them, do not leave them floating around.

How to find dormant accounts

Start with places where old accounts usually hide.

Check:

  • Password manager entries
  • Saved browser passwords
  • Old email inboxes for “welcome,” “verify,” or “receipt”
  • App store subscriptions
  • Social login permissions such as “Sign in with Google”
  • Banking and credit card statements
  • Old resumes and job board profiles
  • Cloud storage folders
  • Gaming and ecommerce accounts

Google says account activity can include actions like reading email, using Drive, watching YouTube, downloading an app, or using “Sign in with Google” for a third-party service in its inactive account policy, so checking connected sign-ins can reveal accounts you forgot existed.

What should you do with old accounts?

Use this simple cleanup process:

  1. Make a list of old accounts
    Start with your password manager, inbox, and saved browser logins.
  2. Decide what to keep
    Keep accounts tied to taxes, banking, medical records, active purchases, subscriptions, or important files.
  3. Download anything important
    Save photos, receipts, documents, or messages before deleting.
  4. Delete accounts you no longer need
    Use the official account deletion page or privacy settings.
  5. Change passwords on accounts you keep
    Use long, unique passwords for every account.
  6. Turn on multifactor authentication
    Add MFA to email, banking, cloud, social, and shopping accounts.
  7. Remove connected apps
    Revoke access for apps and websites you no longer use.
  8. Set a reminder
    Review old accounts every six months.

Cybercriminals love dormant accounts because people forget them, reuse passwords on them, and rarely monitor them. Delete what you do not need, secure what you keep, and reduce your online attack surface one old login at a time.