← All terms

Orphaned Account

An orphaned account is an active login whose owner has left or whose purpose has lapsed. Unwatched and unowned, it is a favorite entry point for attackers.

An orphaned account is an account that remains active after its reason for existing has gone: a former employee's login that was never disabled, a contractor's access that outlived the contract, a service account for a system that was decommissioned, or a SaaS seat nobody remembers creating. The defining feature is the missing owner — there is no person responsible for the account, no one who would notice unusual activity on it, and no one who would complain if it were disabled.

How it becomes a security problem

Orphaned accounts combine three properties attackers love. They are valid, so logins raise no alarms that a forged credential would. They are unwatched, because behavioral monitoring keys on the habits of a user who no longer has any. And they are unmaintained — passwords never rotate, multi-factor enrollment is stale or absent, and permissions reflect whatever the owner accumulated before leaving. Credential dumps and infostealer logs give attackers a steady supply of passwords for accounts that organizations believe are closed; credential stuffing and simple reuse do the rest. The pattern shows up in major incidents: the 2021 Colonial Pipeline ransomware attack began with a legacy VPN profile that was not supposed to be in use, protected by a single reused password. An orphaned account that still carries admin rights is effectively a standing account takeover waiting for a claimant.

How to defend against it

Prevention is disciplined deprovisioning: every account gets an owner and, where possible, an expiry at creation; termination automatically disables the identity and the long tail of SaaS, keys and grants behind it — the same-day process detailed in our guide to departing-employee risk. Detection is reconciliation: periodic user access reviews comparing every system's live accounts against current staff and vendors, plus alerts on dormant accounts that suddenly wake up. Treat any login from an account inactive for 90 days as an incident trigger, not a curiosity, and fold leaver-account monitoring into the wider insider threat program.

Related terms

DeprovisioningDeprovisioning is the removal of a user's accounts, credentials and entitlements when they leave or change roles. Slow deprovisioning leaves doors open.Offboarding (Leaver Risk)Offboarding is the controlled removal of a departing employee's access and data. Done late or incompletely, it leaves accounts attackers and insiders can use.Account Takeover (ATO)Account takeover is an attack in which a criminal gains control of a legitimate user account and operates it for fraud, theft, or further attacks.Credential StuffingCredential stuffing is an automated attack that tries username-password pairs stolen from one breach against many other sites, exploiting password reuse.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo