Avatier

Orphaned or dormant accounts

Dormant account

Also called: inactive account

A dormant account is a workforce or IT user account that is still enabled but has not been used for a long time, such as one belonging to someone on leave, a retired project or a forgotten test user. Nobody watches its activity, so an attacker who obtains its password can use it with little chance of notice.

How it works

Attackers look for enabled accounts with old, simple passwords and no recent sign-ins, often through password guessing or leaked credentials. Because the real owner is not using the account, alerts such as unexpected MFA prompts reach no one. Some MFA tools also let a dormant account enroll a new device, which hands the attacker a working second factor.

A real example

CISA and the FBI reported that Russian state-sponsored actors guessed the password of an account that had been un-enrolled from its MFA service after a long period of inactivity but not disabled, then enrolled a new device and gained network access.

Source: Russian State-Sponsored Cyber Actors Gain Network Access by Exploiting Default Multifactor Authentication Protocols and "PrintNightmare" Vulnerability (AA22-074A) — Cybersecurity and Infrastructure Security Agency (CISA), 2022-03-15

How to stop it

Automatically disable accounts after a set period without sign-ins, require verification before any MFA re-enrollment, and review inactive accounts with their managers before reactivating them.

Related terms

Threat actors that use it

  • APT29

    Profile with government sources

Sources

  1. Russian State-Sponsored Cyber Actors Gain Network Access by Exploiting Default Multifactor Authentication Protocols and "PrintNightmare" Vulnerability (AA22-074A) — Cybersecurity and Infrastructure Security Agency (CISA), 2022-03-15

Last reviewed Oct 2, 2026