Dormant account
Also called: inactive account
A dormant account is a workforce or IT user account that is still enabled but has not been used for a long time, such as one belonging to someone on leave, a retired project or a forgotten test user. Nobody watches its activity, so an attacker who obtains its password can use it with little chance of notice.
How it works
Attackers look for enabled accounts with old, simple passwords and no recent sign-ins, often through password guessing or leaked credentials. Because the real owner is not using the account, alerts such as unexpected MFA prompts reach no one. Some MFA tools also let a dormant account enroll a new device, which hands the attacker a working second factor.
A real example
CISA and the FBI reported that Russian state-sponsored actors guessed the password of an account that had been un-enrolled from its MFA service after a long period of inactivity but not disabled, then enrolled a new device and gained network access.
Source: Russian State-Sponsored Cyber Actors Gain Network Access by Exploiting Default Multifactor Authentication Protocols and "PrintNightmare" Vulnerability (AA22-074A) — Cybersecurity and Infrastructure Security Agency (CISA), 2022-03-15
How to stop it
Automatically disable accounts after a set period without sign-ins, require verification before any MFA re-enrollment, and review inactive accounts with their managers before reactivating them.
Related terms
Threat actors that use it
- APT29
Profile with government sources
Sources
- Russian State-Sponsored Cyber Actors Gain Network Access by Exploiting Default Multifactor Authentication Protocols and "PrintNightmare" Vulnerability (AA22-074A) — Cybersecurity and Infrastructure Security Agency (CISA), 2022-03-15
Last reviewed Oct 2, 2026