top of page

Old company accounts and logins are a cybersecurity risk and exactly what criminals look for

  • Writer: Innovec
    Innovec
  • Jul 13
  • 3 min read

Every business builds up old accounts over time. Software you've switched away from, free trials nobody closed, logins tied to staff who've since left. Most of it gets

forgotten rather than properly shut down, and that's exactly where the risk sits.


Sign-in form with Twitter and Facebook buttons, username and password fields, keep me signed in checkbox, and green Sign In button.


NordPass's most recent research, published in May 2026, found that the average person now handles around 120 personal passwords and 67 work related ones. That's actually a drop from a peak of 168 in 2024, largely put down to more people using single sign on and passkeys instead of creating a new password for every service.


On the surface that sounds like good news, but with the shift of developments such as Web3, one reason old accounts cybersecurity now pose a much deeper security risk is because they're built on legacy software. This is very attractive to cyber actors.


But the researchers were clear that it doesn't mean people have fewer accounts, just fewer unique passwords. The overall number of accounts, and the logins attached to them, keeps growing. Dormant accounts on platforms you rarely visit are a particular concern, since they tend to sit on weaker security and get missed when breach notifications go out.



For businesses handling client data, it's a data protection issue, and one that tends to build up quietly through staff turnover, finished projects and tools used temporarily.


It's the same pattern we've seen play out in real world data breach cases, where the exposed account is often one nobody remembered was still active.


Where the risk usually sits

Account type

Typical example

Main risk

What to do

Retired software

Old CRM or accounting tool

Client or financial data left unmonitored

Export what's needed, then formally close it

Free trials

A tool tried once, then forgotten

Weak, reused password

Search email for signups, delete what's unused

Ex-employee logins

Personal accounts under a work email

Access that outlives employment

Build closure into offboarding

Client or project portals

Access from a finished job

No current business reason to keep it

Remove access at project close out

A quick audit of your inbox and browser will usually turn up more old accounts than expected.


We recommend that you close what's no longer needed rather than just letting it sit unused, and for anything still in use, a password manager and multi factor authentication make a real difference since they remove the temptation to reuse the same weak password across several accounts.


Create Your Account pop-up with email and password fields, green Create My Account button, and perks list on a food-ordering site

The habit that matters most long term is building account closure into your existing processes. Add it to your offboarding checklist when staff leave, and to your project close out steps when client work wraps up. That way it's routine maintenance rather than an occasional clear out, and it fits naturally alongside the Cyber Essentials aligned protections most SMEs already have in place.


Safety FAQ

Are old, unused online accounts actually a security risk? 

Yes. Dormant accounts tend to sit on outdated or weak security, and they're often missed when a breach happens because nobody remembers they exist. That makes them an easier target than accounts you actively monitor.


How do I find old accounts I've forgotten about?

Search your email inbox for old welcome and signup messages, and check what's saved in your browser or password manager. Between the two, most people turn up far more accounts than they expected.


What should happen to an ex-employee's accounts?

Any account created under a former staff member's work email should be closed or reassigned as part of offboarding, not left active by default. This is one of the most common gaps we see in SME account hygiene.


Does using fewer passwords mean less risk?

Not on its own. NordPass's 2026 research found the average number of passwords per person has dropped, but that's mostly down to single sign on, not fewer accounts overall. The total number of accounts, and the data sitting in them, keeps growing.


If you'd like help auditing where your business might be exposed, get in touch and we can talk it through.


 
 
 

Comments


bottom of page