Avatier

Orphaned or dormant accounts

Orphaned account

Also called: zombie account

An orphaned account is a user, admin or application account that no longer has a valid owner, usually because the person left, changed roles or a system was retired, yet the account remains active. It keeps its access and credentials, so it becomes an unmonitored way in for former insiders or outside attackers who obtain them.

How it works

Orphaned accounts build up when offboarding misses a system, a shared or local account is never tied to a person, or an app account outlives its project. Attackers find them through leaked credentials or directory reconnaissance. Because no one owns the account, nobody notices new sign-ins, and its old permissions often reach sensitive systems.

A real example

In a February 2024 advisory, CISA and MS-ISAC said a state government organization found that documents posted on a dark web brokerage site had been accessed through the compromised account of a former employee.

Source: Threat Actor Leverages Compromised Account of Former Employee to Access State Government Organization (AA24-046A) — Cybersecurity and Infrastructure Security Agency (CISA), 2024-02-15

How to stop it

Give every account a named owner, tie account removal to HR departure records across all systems, and run regular reconciliations that disable any account without a current owner.

Related terms

Threat actors that use it

  • APT29

    Profile with government sources

Sources

  1. Threat Actor Leverages Compromised Account of Former Employee to Access State Government Organization (AA24-046A) — Cybersecurity and Infrastructure Security Agency (CISA), 2024-02-15

Last reviewed Oct 2, 2026