Attack vector
Orphaned or dormant accounts
An orphaned or dormant account is one that outlived the person or purpose it was created for: a former employee, a finished contractor engagement, a retired project or a test login. Nobody watches it and nobody would notice it being used, so a working credential for it gives an attacker quiet, long-lived access.
Accounts that outlived the person or the purpose.
How attackers use it
Attackers test old credentials from earlier breaches and can find accounts that were never switched off. A departed employee's login, a contractor account from last year or an admin test account can still carry real permissions. Since no one expects activity from it, its use rarely raises an alarm.
What breach letters say
None of the 2,161 California breach filings in the ledger (January 1, 2023 – August 14, 2026) names this vector. That says what notification letters disclose, not how often it happens.
How to stop it
Use lifecycle automation, driven by the HR or contract record, to disable access the day someone leaves or a project ends. Back it with regular sweeps for accounts with no owner or no recent sign-in.
Terms under this vector
- Dormant account
A dormant account is a workforce or IT user account that is still enabled but has not been used for a long time, such as one belonging to someone on leave, a retired project or a forgotten test user.
- Offboarding gap
An offboarding gap is the time or the systems in which a departing employee, contractor or vendor keeps access after their work has ended.
- Orphaned account
An orphaned account is a user, admin or application account that no longer has a valid owner, usually because the person left, changed roles or a system was retired, yet the account remains active.
Threat actors tied to it
- APT29
Profile with government sources
Last reviewed Oct 2, 2026