Ghost Accounts: The Forgotten Corners of Your Digital Past That Are Still Leaking Your Data Today
Somewhere in a database you have not visited in years, a version of you still exists. Perhaps it is the account you created on a now-obscure photo-sharing platform in 2011, or the profile you registered on a flash-sale shopping site before it quietly folded. You have long since moved on. The account, however, has not moved anywhere — and neither has the personal information stored inside it.
For most Americans, the tally of forgotten online accounts runs far higher than intuition suggests. Research from cybersecurity firm NordPass has estimated that the average internet user maintains well over 100 online accounts. A significant proportion of those are effectively abandoned — no activity, no monitoring, no updated security settings. That neglect carries a concrete cost that compounds silently over time.
Why Dormant Accounts Are a Preferred Target
Cybercriminals are rational actors. They pursue the path of least resistance, and dormant accounts represent exactly that. When a data breach exposes a forgotten platform's user database — an event that happens with startling regularity — the credentials harvested from that breach are fed into automated credential-stuffing tools. These tools attempt the same username-and-password combination across hundreds of other services simultaneously.
The danger is amplified by a behavioral pattern that security researchers have documented extensively: password reuse. If the email address and password you registered on a defunct coupon website in 2014 are identical to the credentials protecting your current bank account or primary email inbox, a breach at that long-forgotten site becomes a direct threat to your financial life today.
Dormant accounts are also less likely to have benefited from security improvements that active users encounter naturally — mandatory password resets, multi-factor authentication prompts, or suspicious-login alerts. A platform that has gone through several security overhauls may have pushed those updates to active users while leaving legacy accounts in an older, more vulnerable state.
The Compounding Risk of Zombie Platforms
Not every dormant account lives on a thriving platform. Many reside on services that have themselves been abandoned, acquired, or run into financial difficulty. When a company is sold, its user database is often transferred as an asset — sometimes to buyers whose data-handling practices are far less rigorous than the original operator's. When a company simply shuts down, that database may linger in storage for years, governed by a privacy policy no one is enforcing.
Several high-profile cases illustrate the pattern. The 2016 disclosure of the LinkedIn breach — which had actually occurred in 2012 — revealed that 117 million credentials had been circulating on criminal forums for four years before the public was informed. MySpace, a platform most users had mentally archived as a cultural relic, disclosed in 2016 that approximately 360 million accounts had been compromised in a breach dating back to before 2013. In both instances, users who had not logged in for years discovered that their old passwords — passwords they may still have been using elsewhere — had been exposed and traded.
The Have I Been Pwned database, maintained by security researcher Troy Hunt, currently indexes billions of breached records spanning hundreds of compromised services. A substantial portion of those records originate from platforms that no longer operate in any meaningful sense.
Finding What You Have Forgotten
The first step toward addressing dormant-account risk is an honest audit. Most people significantly underestimate how many accounts they have created. A methodical approach is more reliable than relying on memory alone.
Begin with your email inbox. Search for registration confirmation messages using terms such as "welcome," "confirm your account," "verify your email," and "you're registered." Filtering by sender domains you do not recognize often surfaces platforms you have entirely forgotten. Repeat this process across every email address you have ever used, including older accounts that may themselves be dormant.
Next, review your password manager if you use one — and if you do not, consider this a compelling reason to start. A password manager's vault functions as an inadvertent ledger of every site where you have stored credentials. Entries you have not accessed in years deserve scrutiny.
Third-party discovery tools such as Deseat.me or Apple's "Sign in with Apple" management panel can surface accounts linked to specific email addresses or identity providers. Google's account security checkup similarly lists third-party applications and services that have been granted access to your Google identity.
Assessing and Prioritizing Risk
Not every dormant account warrants the same level of urgency. A practical triage framework helps allocate attention efficiently.
High-priority accounts are those that store financial information — saved payment cards, billing addresses, or transaction histories. Dormant accounts on retail platforms, subscription services, or any site that retains payment data should be addressed first. Similarly, any account that uses a password you currently employ elsewhere is an immediate priority, regardless of the platform's apparent significance.
Medium-priority accounts include social media profiles and communication platforms. Even an account you have not touched in a decade can be hijacked and weaponized — used to send phishing messages to your former contacts, impersonate you in targeted scams, or harvest personal information visible in old posts.
Lower-priority accounts — those on platforms that hold no financial data, no sensitive communications, and passwords unique to that site — still merit eventual action, but can be addressed after more critical accounts are secured.
Closing the Door: Deletion Versus Fortification
For accounts you no longer need, deletion is the cleanest solution. Most platforms are required under applicable privacy law — including the California Consumer Privacy Act for California residents — to honor deletion requests. The website JustDeleteMe maintains a directory of direct links to account-deletion pages for hundreds of services, along with ratings indicating how difficult each platform makes the process.
Where deletion is not possible — some platforms obscure or complicate the process — fortification is the next best option. Change the account's password to a long, randomly generated string unique to that site. Enable multi-factor authentication if the platform supports it. Replace the associated email address with a dedicated throwaway address if you wish to sever the link to your primary identity. Then log out and leave it.
For accounts on platforms that appear to have ceased operations entirely, focus your energy on ensuring the associated password is not reused anywhere active. The platform's data may already be compromised; what you can control is the blast radius.
The Broader Principle
The security community has a phrase for the accumulation of unnecessary software, permissions, and access points within an organization: attack surface. The same concept applies to individuals. Every account you maintain — active or dormant — is a point of potential entry. Every account you close is a door you have permanently shut against anyone who might otherwise walk through it.
The internet has an extraordinarily long memory. The version of you that registered for a streaming beta or an early social network in the mid-2000s is still out there, preserved in someone's database, waiting. The question is not whether that data exists. The question is whether you are going to leave it unguarded.