Zombie Accounts Are Real — And Yours Might Already Be Causing Damage
Somewhere on the internet, there's a version of you from 2009. Maybe it's an old MySpace page, a forum account for a game you played once, a newsletter signup from a brand that got acquired three times since then. You haven't thought about it in years. But it hasn't stopped existing — and it hasn't stopped collecting data.
Abandoned accounts are a specific kind of security problem that doesn't get enough attention. Most people assume that if they're not using something, it's not doing anything. That assumption is wrong in some pretty important ways.
Why Dormant Accounts Are Actually More Dangerous Than Active Ones
When you actively use an account, you notice things. You'd notice if your password stopped working, or if you got an email about a login from a weird location. Dormant accounts give you none of that feedback loop. Something can go wrong and you won't know for months — or ever.
Here's what's actually happening with those old accounts:
They're still collecting data. A lot of platforms continue to build behavioral profiles even for users who haven't logged in. If the site is still active, your account still exists in their database, and depending on their data practices, it may be getting linked to third-party data sources, updated with inferred information, and packaged into advertising profiles.
They're sitting targets for credential stuffing attacks. When a data breach happens somewhere — and they happen constantly — attackers take those leaked username/password combinations and try them automatically across thousands of other sites. If you used the same password on that old gaming forum as you did on your bank account, that's a real problem. Old accounts with recycled passwords are basically an open door.
The companies holding your data may not be the companies you signed up with. Acquisitions, mergers, and bankruptcies happen all the time in tech. That fitness app you used briefly in 2017 might have been bought by a data broker. Your information didn't disappear — it transferred.
Step 1: Find Out If You've Already Been Compromised
Before you start closing accounts, find out if any of your information has already leaked. The best tool for this is Have I Been Pwned (haveibeenpwned.com), a free service run by security researcher Troy Hunt.
Here's how to use it:
- Go to haveibeenpwned.com
- Enter your email address (try every email you've ever used)
- The site will show you a list of known data breaches that included your email
- For each breach, it tells you what type of data was exposed — passwords, phone numbers, physical addresses, and so on
If your email shows up in a breach, that's your signal to prioritize changing passwords and closing accounts associated with that service. Don't skip this step — it takes about 90 seconds and gives you a real picture of your exposure.
You can also set up alerts so you're notified if your email shows up in future breaches.
Step 2: Prioritize Which Accounts to Tackle First
Not all zombie accounts carry the same risk. Here's a rough priority order:
High priority — tackle these first:
- Anything that has your payment information stored (old shopping sites, expired subscription services)
- Accounts that use your primary email address as the username
- Anything connected to your Social Security number, even indirectly (old tax prep tools, credit monitoring services you signed up for once)
- Accounts on sites that have already appeared in a known breach
Medium priority:
- Old social media accounts (these often have more personal info than you remember — location data, relationship status, employment history)
- Accounts on platforms that got acquired or shut down but whose data may have transferred
- Any account where you used a password you still use elsewhere
Lower priority but still worth doing:
- Forum accounts, old gaming profiles, newsletter signups with no real personal data attached
Step 3: Actually Delete the Accounts (Not Just the App)
This is the part most people miss. Deleting an app from your phone doesn't delete your account. The account keeps living on the company's servers until you explicitly request deletion.
For major platforms, here's how to find the account deletion page:
- Google: myaccount.google.com → Data & Privacy → Delete your Google Account
- Facebook/Instagram: Settings → Your Facebook Information → Deactivation and Deletion (choose Delete, not Deactivate)
- Twitter/X: Settings → More → Settings and Support → Settings → Your Account → Deactivate account (note: full deletion takes 30 days)
- Old retail accounts: Look for a "Close account" or "Delete account" option in account settings, or email customer support directly
For services that make deletion difficult or impossible to find, try JustDeleteMe (justdeleteme.xyz) — it's a directory that rates how hard each site makes deletion and links directly to the right page.
If a company is unresponsive or the site appears defunct, you can submit a data deletion request under your rights as a California resident (even if you don't live in California, many companies honor CCPA requests from all US users) or just change the account email to a throwaway address and set a random password.
Step 4: Stop Creating New Zombie Accounts
The best long-term move is reducing how many accounts you create in the first place.
A few habits that help:
- Use "Sign in with Apple" when it's available. Apple creates a randomized relay email for each service, so the company never gets your real address, and you can revoke access anytime.
- Create a dedicated email for signups. Use a separate address for newsletters, trials, and one-off purchases. When it gets too cluttered, you can nuke the whole inbox without affecting your real accounts.
- Use a password manager. Tools like Bitwarden or 1Password keep a record of every account you've created, which makes auditing and deleting much easier down the road.
The Bigger Picture
The internet has a long memory, and most of the companies holding your old data have very little incentive to delete it on their own. The accounts you forgot about years ago are still out there, still potentially being used, and — if they've been compromised — potentially already working against you.
The good news is that cleaning this up isn't as overwhelming as it sounds once you have a system. Start with the high-priority accounts, check your breach exposure, and chip away at the rest over time. An hour of cleanup now is worth a lot more than the hassle of dealing with identity theft later.