Join our Newsletter — 33% off our NHI Course

How should people handle old accounts that are no longer in active use?

The safest approach is to close accounts you no longer need and remove personal details first, including address, phone number, and financial information. If an account must stay open, change the password to something strong and unique and store it securely. Dormant accounts can still expose private data in a breach, so reducing what they contain limits the damage.

Why old accounts should not be left untouched

Old accounts are a long-lived attack surface. Even when nobody uses them, they can still retain personal details, saved payment methods, password reset paths, or access to other services tied to the same email address. A forgotten account also creates uncertainty about who is responsible for it, which makes later cleanup harder and increases the chance of silent exposure.

That is why the safest default is to remove any sensitive data first and then close the account if the provider allows it. If closure is not possible, the remaining account should be treated as a standing exposure that still needs control.

What to remove before you close an account

Before shutting an account down, strip out the data that would cause the most harm if the account were breached later. That usually means profile details, stored addresses, phone numbers, payment cards, bank details, recovery email addresses, and any saved documents or messages that are no longer needed.

If the account must remain open, reduce what it can reveal. Replace reusable passwords with a strong unique one, remove autofill or stored payment methods, and review whether the account still serves any business or personal purpose. The point is to shrink the amount of useful data and the number of ways an attacker could use the account.

How to decide whether an account should stay open

Keep an account open only when there is a clear reason, such as an active subscription, compliance record, or a service you still rely on. If the account is just being kept “in case” it might be needed later, that is usually a sign it should be closed instead of preserved.

When retention is unavoidable, make the account easy to defend and easy to revisit. Use a password manager to store the credentials securely, confirm that account recovery details are current, and document why the account exists so it does not become forgotten again.

Risk and Threat Considerations

Unused accounts are attractive because they are often overlooked, rarely monitored, and more likely to contain stale recovery paths or old data. If an attacker gains access, the account may provide direct access to personal information or a foothold into other services that still trust that email address or identity.

Failure mechanism: Dormant accounts fail because they remain valid after the owner has stopped paying attention to them, so old passwords, recovery options, and stored data can persist far longer than intended.

Impact: A breach of an old account can expose private data, enable password resets on connected services, or create an entry point for fraud and account takeover.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-53 Rev 5 sets the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
OWASP Non-Human Identity Top 10 NHI-01 — Improper Offboarding Old accounts kept open after use ends create the same stale-access problem.
NHI-02 — Secret Leakage Dormant accounts can still expose saved credentials and recovery material.
Recommendation — Close unused accounts promptly and remove residual data before access is no longer needed. Remove or rotate any secret material tied to accounts that must remain active.
NIST SP 800-53 Rev 5 IA-5 — Authenticator Management Unused accounts should not retain weak or unmanaged credentials.
AC-2 — Account Management Account lifecycle handling is central to closing or preserving dormant accounts safely.
Recommendation — Manage account authenticators tightly and revoke stale credentials when accounts are retired. Disable or remove accounts that are no longer needed and review retained exceptions.
ISO/IEC 27001:2022 A.5.16 — Identity management Account cleanup is an identity lifecycle and ownership issue.
Recommendation — Maintain ownership and lifecycle controls for accounts until they are removed or formally retained.

Practitioner Guidance

What to prioritise: Start with accounts that hold payment details, identity documents, or password reset access to other services. Those accounts create the largest blast radius if they are ever compromised.

What to verify: Before closing an account, confirm that no active service depends on it for login, billing, or recovery. After closure, keep a record of what was deleted and what had to remain for business or legal reasons.

Common mistake: Leaving an account open because it is “free” or “inactive” but never reviewing the stored data. In practice, dormant accounts are only safe when they contain little or nothing useful and have no downstream dependencies.

Practitioner takeaway: Treat unused accounts as liabilities, not conveniences, and close them once they no longer serve a real purpose.