Somewhere out there is a forum account you made in 2011, a food delivery profile from a city you left, a free trial you never cancelled because it was free. You have not thought about them in years. That is exactly the problem: each one is a little vault of your data, guarded by the person you were a decade ago, whose password habits were worse than yours.

Why dormant accounts matter more than active ones

Three reasons. First, they hold your old passwords, and old passwords are fossils of your reuse era: crack one forgotten site and the password probably matches other accounts from the same years. Second, the companies behind dormant accounts decay: they get acquired, abandoned, or breached without anyone maintaining the security, and abandoned services are exactly the ones that never notice an intrusion. Third, you will never see the warning signs on an account you never log into. A breach notification goes to an email you stopped checking; suspicious activity happens in a place you never look.

Your practical exposure is the sum of every place your data sits, not just the places you remember. Shrinking that footprint is one of the few security tasks that is genuinely permanent: a deleted account cannot appear in next year's breach.

How to find what you forgot

You cannot audit from memory, but three sources reconstruct the list fast. Your password manager, if you use one, is the ledger: every saved login is an account that exists. Your inbox is the archaeology: search for "welcome to," "verify your email," and "your account has been created," and scroll back through the years. And your breach scan results are the involuntary record: every breach containing your email names a service that had an account, including ones you forgot entirely. People routinely discover accounts in their scan results that they have no memory of creating.

Closing them properly

Order matters. Before deleting an account, remove what it holds: delete saved payment cards, clear the address book if it has one, and strip profile details. Then delete the account itself, usually buried under privacy or account settings. If a service offers no deletion, empty it instead: replace the profile data with nothing, and change the password to a long random one used nowhere, which at least breaks the link to your reuse history. Residents of states with privacy laws, and anyone in the EU, can also send a formal deletion request, which services are legally obliged to honor. The email address for that request is usually in the privacy policy.

Do not try to do this in one sitting. Close the five oldest and the five most data-heavy accounts today, then make it a habit: every scan result or breach letter that names a service you no longer use becomes a two-minute deletion instead of a shrug.

Keep reading

Shrinking your footprint handles the data you left behind. Next, an honest look at a fear that mostly expired years ago:

Is Public Wi-Fi Still Dangerous?

The coffee-shop hacker of 2012 is mostly extinct, and the advice built around him misdirects your caution. What actually matters now.

← Back to all guides