Dead Accounts Walking: How to Hunt Down and Permanently Close Your Forgotten Online Profiles
The Problem With Profiles You've Stopped Thinking About
At some point in the last decade, you signed up for a recipe-sharing platform, a niche fitness tracker, a regional coupon site, or a dating app you used for exactly three weeks. You moved on. The account did not.
Dormant online accounts — often called zombie accounts in security circles — are among the most overlooked components of personal digital risk. According to research from cybersecurity firm SpyCloud, the average American adult has accumulated well over 100 online accounts over their lifetime, yet actively uses fewer than 25 of them. The remainder sit idle, holding personal information, old passwords, and sometimes linked payment data, waiting for one of two events: a data breach at the company hosting them, or a credential-stuffing attack that lets a criminal walk right in.
Neither outcome requires any action on your part. That is precisely what makes forgotten accounts so dangerous.
Why Dormant Accounts Are a Preferred Target
Criminals who acquire leaked username-and-password combinations from past breaches do not simply try those credentials on major platforms. They run automated tools against hundreds of services simultaneously — streaming sites, retail portals, airline loyalty programs, obscure forums — searching for any account where the same password was reused. Because most people do not monitor accounts they no longer visit, a successful intrusion can go undetected for months.
The consequences extend beyond the compromised platform itself. An old account may contain answers to security questions you still use elsewhere. It may hold a linked email address that serves as a recovery pathway into more critical accounts. In some cases, platforms retain partial payment card numbers, home addresses, or date-of-birth data that can be aggregated with information from other breaches to construct a surprisingly complete identity profile.
There is also the matter of data brokers. Many third-party aggregators harvest publicly visible profile information — screen names, bios, photos, location data — from platforms that allow it. An account you abandoned in 2016 may still be feeding your personal information into commercial databases today, entirely without your awareness.
Step One: Map the Full Scope of Your Exposure
Before you can close accounts, you need to find them. Several methods work in combination.
Search your email inbox. The most reliable starting point is your primary email account. Search for phrases such as "welcome to," "thanks for signing up," "confirm your email," and "activate your account." Sort results by sender and work backward through the years. You will almost certainly surface registrations you have no memory of making.
Check your password manager or browser-saved passwords. If you use a password manager — and CipherWatch strongly recommends that you do — browse the full list of stored entries. Many users are surprised to discover entries for platforms they have not visited in years. Browser-saved passwords in Chrome, Firefox, Edge, and Safari can be exported and reviewed similarly.
Use Have I Been Pwned. The free service at HaveIBeenPwned.com allows you to enter your email address and receive a report of every known data breach in which that address appeared. Each breach entry identifies the platform involved and the categories of data exposed. This is not a list of every account you hold, but it is a direct map of accounts that have already been compromised — and therefore require immediate attention.
Run a Google search on your usernames. If you have used consistent usernames across platforms, a simple search may surface profiles on sites you no longer remember joining. Include quotation marks around the username for precision.
Check connected apps on major platforms. Facebook, Google, and Apple all maintain dashboards showing which third-party services you authorized to access your account. Many of these authorizations correspond to apps or services you signed up for using a social login and have since abandoned. Revoking these connections is a meaningful privacy step even before you delete the underlying accounts.
Step Two: Assess the Risk Each Account Carries
Not every dormant account warrants the same level of urgency. Prioritize based on what data the platform likely holds.
Accounts with stored payment information, Social Security numbers, government ID data, or medical details should be addressed first. E-commerce platforms, tax preparation services, healthcare portals, and financial apps fall into this category. Next, address accounts tied to email addresses or phone numbers you still actively use, as these represent potential recovery-pathway vulnerabilities. Finally, work through lower-stakes accounts — forums, hobby sites, old gaming profiles — where the primary risk is password reuse rather than sensitive data exposure.
Step Three: Delete, Don't Just Abandon
The instinct to simply change the password on a forgotten account and walk away is understandable but insufficient. Deletion removes your data from the platform's active systems and, in many cases, triggers data-retention policies that eventually purge your information from backups as well.
Most platforms bury the account deletion option. It is rarely found in the obvious settings menu. A resource called JustDeleteMe (justdeleteme.xyz) maintains a directory of direct deletion links for hundreds of popular services, rated by difficulty. For platforms not listed there, searching the service name alongside the phrase "delete account" or "close account" in a search engine typically surfaces the correct page.
Before deleting, take two preparatory steps. First, download any data you may wish to retain — photos, messages, documents. Most major platforms offer a data export option. Second, if the account uses a password you still use elsewhere, change that password on every other platform where it appears before closing the account.
For platforms that do not offer deletion — some older services and defunct companies in particular — submit a data deletion request under applicable privacy law. US residents in California can invoke rights under the California Consumer Privacy Act. Residents of other states may have similar protections depending on their state's privacy legislation. Even outside those frameworks, a formal written request to a company's privacy contact often produces results.
Step Four: Prevent Future Accumulation
The most effective long-term strategy is to reduce the rate at which new dormant accounts are created in the first place.
Avoid using social logins — "Sign in with Google" or "Sign in with Facebook" — for services you do not intend to use regularly. While convenient, these connections expand your attack surface and make it harder to track your account inventory over time. Instead, use a dedicated email alias for new signups. Services such as Apple's Hide My Email, SimpleLogin, or Fastmail's masked addresses allow you to create unique, disposable addresses for each platform. If that address begins receiving spam or appears in a breach, you know precisely which service was the source — and you can disable the alias without affecting your primary inbox.
Maintain a running log of new account creations in your password manager. A single note field indicating the date of signup and the purpose of the account takes seconds to complete and pays dividends during future audits.
The Audit Is Not a One-Time Event
A thorough account audit conducted today will not remain current indefinitely. New accounts accumulate, companies are acquired and change their security practices, and breach disclosures continue at a steady pace. Security professionals recommend repeating a simplified version of this process at least once per year — ideally aligned with an annual review of passwords, two-factor authentication settings, and connected devices.
The accounts you have forgotten are not inert. They are active liabilities sitting in databases you do not control, secured with passwords you may still be using, and holding information you shared years ago without thinking twice. Finding them and eliminating them is not a technical exercise reserved for specialists. It is a basic act of digital self-preservation that any American with an internet connection can — and should — complete.