Old company accounts and logins are a cybersecurity risk and exactly what criminals look for
- Innovec

- Jul 13
- 3 min read
Every business builds up old accounts over time. Software you've switched away from, free trials nobody closed, logins tied to staff who've since left. Most of it gets
forgotten rather than properly shut down, and that's exactly where the risk sits.

NordPass's most recent research, published in May 2026, found that the average person now handles around 120 personal passwords and 67 work related ones. That's actually a drop from a peak of 168 in 2024, largely put down to more people using single sign on and passkeys instead of creating a new password for every service.
On the surface that sounds like good news, but with the shift of developments such as Web3, one reason old accounts cybersecurity now pose a much deeper security risk is because they're built on legacy software. This is very attractive to cyber actors.
But the researchers were clear that it doesn't mean people have fewer accounts, just fewer unique passwords. The overall number of accounts, and the logins attached to them, keeps growing. Dormant accounts on platforms you rarely visit are a particular concern, since they tend to sit on weaker security and get missed when breach notifications go out.
For businesses handling client data, it's a data protection issue, and one that tends to build up quietly through staff turnover, finished projects and tools used temporarily.
It's the same pattern we've seen play out in real world data breach cases, where the exposed account is often one nobody remembered was still active.
Where the risk usually sits
Account type | Typical example | Main risk | What to do |
Retired software | Old CRM or accounting tool | Client or financial data left unmonitored | Export what's needed, then formally close it |
Free trials | A tool tried once, then forgotten | Weak, reused password | Search email for signups, delete what's unused |
Ex-employee logins | Personal accounts under a work email | Access that outlives employment | Build closure into offboarding |
Client or project portals | Access from a finished job | No current business reason to keep it | Remove access at project close out |
A quick audit of your inbox and browser will usually turn up more old accounts than expected.
We recommend that you close what's no longer needed rather than just letting it sit unused, and for anything still in use, a password manager and multi factor authentication make a real difference since they remove the temptation to reuse the same weak password across several accounts.

The habit that matters most long term is building account closure into your existing processes. Add it to your offboarding checklist when staff leave, and to your project close out steps when client work wraps up. That way it's routine maintenance rather than an occasional clear out, and it fits naturally alongside the Cyber Essentials aligned protections most SMEs already have in place.
Safety FAQ
Are old, unused online accounts actually a security risk?
Yes. Dormant accounts tend to sit on outdated or weak security, and they're often missed when a breach happens because nobody remembers they exist. That makes them an easier target than accounts you actively monitor.
How do I find old accounts I've forgotten about?
Search your email inbox for old welcome and signup messages, and check what's saved in your browser or password manager. Between the two, most people turn up far more accounts than they expected.
What should happen to an ex-employee's accounts?
Any account created under a former staff member's work email should be closed or reassigned as part of offboarding, not left active by default. This is one of the most common gaps we see in SME account hygiene.
Does using fewer passwords mean less risk?
Not on its own. NordPass's 2026 research found the average number of passwords per person has dropped, but that's mostly down to single sign on, not fewer accounts overall. The total number of accounts, and the data sitting in them, keeps growing.
If you'd like help auditing where your business might be exposed, get in touch and we can talk it through.
Source: NordPass, "Juggling security: how many passwords does the average person have in 2026?", May 2026.
.png)




Comments