Orphaned Account
An orphaned account is an active login whose owner has left or whose purpose has lapsed. Unwatched and unowned, it is a favorite entry point for attackers.
An orphaned account is an account that remains active after its reason for existing has gone: a former employee's login that was never disabled, a contractor's access that outlived the contract, a service account for a system that was decommissioned, or a SaaS seat nobody remembers creating. The defining feature is the missing owner — there is no person responsible for the account, no one who would notice unusual activity on it, and no one who would complain if it were disabled.
How it becomes a security problem
Orphaned accounts combine three properties attackers love. They are valid, so logins raise no alarms that a forged credential would. They are unwatched, because behavioral monitoring keys on the habits of a user who no longer has any. And they are unmaintained — passwords never rotate, multi-factor enrollment is stale or absent, and permissions reflect whatever the owner accumulated before leaving. Credential dumps and infostealer logs give attackers a steady supply of passwords for accounts that organizations believe are closed; credential stuffing and simple reuse do the rest. The pattern shows up in major incidents: the 2021 Colonial Pipeline ransomware attack began with a legacy VPN profile that was not supposed to be in use, protected by a single reused password. An orphaned account that still carries admin rights is effectively a standing account takeover waiting for a claimant.
How to defend against it
Prevention is disciplined deprovisioning: every account gets an owner and, where possible, an expiry at creation; termination automatically disables the identity and the long tail of SaaS, keys and grants behind it — the same-day process detailed in our guide to departing-employee risk. Detection is reconciliation: periodic user access reviews comparing every system's live accounts against current staff and vendors, plus alerts on dormant accounts that suddenly wake up. Treat any login from an account inactive for 90 days as an incident trigger, not a curiosity, and fold leaver-account monitoring into the wider insider threat program.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo