Your Old Accounts Are a Security Risk: How to Find and Delete Them


Somewhere out there is a forum you signed up to in 2013 to ask one question about a broken washing machine. It still has your email address, the password you used everywhere back then, your date of birth, and possibly your home postcode. You have not thought about it in a decade. An attacker looking for a way into your life would be delighted to find it.

The average person has somewhere between 100 and 200 online accounts. Most are dormant. Every one of them is a copy of your personal data sitting on a server maintained by a company that may no longer be paying attention. Cleaning them up is unglamorous, genuinely effective, and something almost nobody does.

Why Dormant Accounts Are Dangerous

They hold your old passwords

The password you used in 2013 was probably reused across dozens of sites, and it probably resembles the ones you use now. When that forum gets breached — and small, unmaintained sites get breached constantly — the credentials go into a combo list and get tried automatically against every major service. This is credential stuffing, and it is the single most common way ordinary accounts get taken over.

They hold identity-verification answers

Old sign-up forms asked for date of birth, mother's maiden name, first school, home town. That is precisely the data used to verify you at a bank or reset an account. A breach of a defunct hobby site can supply the answers to your current security questions.

They are unmonitored

If someone takes over an account you check daily, you notice. If they take over an account you forgot in 2015, they can sit in it indefinitely — using it to send scams to your old contacts, harvest anything stored inside, or wait for it to become useful.

Their security has decayed

The site was built to the standards of its era, possibly on a framework that stopped receiving updates years ago. Some store passwords with weak or no hashing. If the company folded, nobody is patching anything, and the database may end up sold or abandoned on a server nobody is watching.

They keep your data circulating

Old accounts feed data brokers and marketing lists. Every dormant profile is another source of the personal information that fuels targeted phishing.

Warning Signs You Have a Dormant-Account Problem

  • You get marketing email from companies you have no memory of joining.
  • A breach notification arrives for a service you did not know you had an account with.
  • Your password manager shows a large number of entries you cannot identify.
  • "Sign in with Google" or "Sign in with Facebook" shows a long list of connected apps you no longer use.
  • Searching your email for "welcome to" or "verify your email" returns hundreds of results.
  • You still receive password reset emails from services you abandoned.

How to Find Every Account You Have

You cannot delete what you cannot find. Use all five of these methods — each one catches accounts the others miss.

1. Search your email archive

The most complete record of your online life is your inbox. Search each of these terms across all mail, including archived and spam:

  • welcome to
  • verify your email / confirm your account
  • thanks for signing up
  • your new account
  • password reset
  • your order / your receipt
  • unsubscribe

Do this for every email address you have ever used, including old work and university addresses if you can still access them. Keep a running list.

2. Export your password manager

If you use one, this is your fastest inventory. Export the entry list and work through it. Most managers also flag reused and breached passwords — sort by those first.

3. Check your browser's saved passwords

Chrome, Safari, Firefox, and Edge have all been quietly saving logins for years. In Chrome, open the password manager from settings. In Safari, Settings → Passwords. You will find accounts you have completely forgotten.

4. Review social login connections

Every time you clicked "Continue with Google," you created an account somewhere. Check:

  • Google: Google Account → Security → Your connections to third-party apps and services
  • Apple: Settings → your name → Sign-In & Security → Sign in with Apple
  • Facebook: Settings → Apps and Websites
  • Microsoft: the account privacy dashboard

Revoke anything you do not actively use. Note that revoking access is not the same as deleting the account at that service — do both.

5. Check breach databases

Run every email address you own through Have I Been Pwned. The list of breaches you appear in is also a list of services you signed up to. Several will surprise you.

How to Delete Them Properly

1. Triage into three piles

  • Delete — anything you no longer use and that holds personal data
  • Keep and secure — accounts you still need: change to a unique strong password, enable two-factor authentication, update the recovery email
  • Cannot delete — services with no deletion option; strip these instead (see below)

2. Empty the account before you close it

Deletion requests are not always honoured completely, and backups persist. Before requesting deletion:

  • Remove saved payment cards and addresses
  • Delete stored files, photos, and messages
  • Overwrite profile fields with junk — change the name, clear the date of birth, remove the phone number
  • Change the email address to a throwaway if the service allows it

This way, even if a copy survives in a backup, it holds much less about you.

3. Find the deletion route

Deletion is often hidden deliberately. Look under Account Settings → Privacy, or Account Settings → Advanced. If you cannot find it, search "[service name] delete account" — community sites catalogue direct links and rate how difficult each service makes it.

4. Use your legal right to erasure

If you are in the EU, UK, California, or a growing number of other jurisdictions, you have a statutory right to request deletion of your personal data. Email their privacy or data protection contact with a short, clear request:

"Under [GDPR Article 17 / the CCPA], I request the erasure of all personal data you hold about me associated with the email address [address]. Please confirm in writing once completed."

Under GDPR they generally must respond within one month. This works on companies that hide the delete button, and it also works on data brokers.

5. Handle services that refuse

Some sites genuinely have no deletion path. For those: strip every field to junk, unsubscribe from all communications, change the password to a long random string you do not keep, and remove any saved payment method. The account remains, but it no longer contains you.

6. Keep a record

Log what you deleted, when, and any confirmation reference. If a company later leaks data you asked them to erase, that record matters.

7. Prevent the problem recurring

  • Use email aliases. Apple's Hide My Email, Firefox Relay, and similar services generate a unique forwarding address per site. When one starts getting spam, you know exactly who leaked it — and you can kill that alias without touching your real address.
  • Use guest checkout instead of creating an account for one-off purchases.
  • Save new signups to your password manager immediately, so your inventory stays current by default.
  • Schedule an annual cleanup. Put it in the calendar next to your recovery audit. An hour a year keeps the list from growing back.

If an Old Account Has Already Been Breached

  1. Identify every place you reused that password. This is the real emergency — not the forum, but your email and banking if they shared a password.
  2. Change the important accounts first, in order: primary email, then banking and payments, then anything with a saved card, then everything else.
  3. Revoke active sessions on each one, not just the password.
  4. Enable two-factor authentication on anything that offers it, prioritising email.
  5. Check the breached account for what it actually held — an old shopping site may have your address and partial card details, which enables convincing phishing.
  6. Watch for targeted phishing. Breached data gets used to write believable emails referencing real purchases or real personal details. Be extra sceptical for a few months.
  7. Then delete the account once you have secured everything downstream.
  8. Consider a credit freeze if identity documents or financial details were exposed.

The Bottom Line

Old accounts are the security equivalent of clutter in an unused room: harmless-looking, easy to ignore, and quietly flammable. Each one is a copy of your personal data protected by whatever standards a company had years ago and may no longer maintain.

You do not have to fix this in a day. Start with one hour: search your inbox for "welcome to", list what comes back, and delete the twenty most obviously useless accounts. Then do the same next weekend. Within a month you will have removed most of the copies of yourself scattered across the internet — and the next big breach will have far less of you in it.

Comments

Popular posts from this blog

Best Antivirus Software of 2026: Top 5 Compared After Real Testing

Public Wi-Fi Dangers: 7 Critical Steps to Stay Safe

Best Identity Theft Protection Services of 2026: Top 5 Ranked and Reviewed