What Are Zombie Accounts and Why Are They a Cybersecurity Risk?

What Are Zombie Accounts and Why Are They a Cybersecurity Risk?

Every business accumulates old accounts over time: a former employee’s login that was never deactivated, a trial software account nobody remembers signing up for, a shared account from a project that ended years ago. Individually, each one seems trivial. Collectively, they represent one of the more overlooked security risks a small business carries.

Direct answer: a zombie account is a login or user profile that remains active in a system even though nobody is genuinely using it anymore, most commonly belonging to a former employee, an old service, or an abandoned trial. These accounts are a real cybersecurity risk because they often carry outdated, weak or reused passwords, sit outside regular monitoring, and give attackers a quiet way into your systems that nobody’s actively watching.

Why zombie accounts are more dangerous than they sound

An active account gets used regularly, which means unusual activity tends to stand out. A zombie account sits dormant, which means unauthorised access can go unnoticed for a long time, sometimes indefinitely. Attackers specifically favour these accounts because they’re easier to exploit and harder to detect than a genuinely active login.

The main risks

Unauthorised access

A former employee’s still-active login gives them, or anyone who obtains their old credentials, a way into your systems long after they’ve left the business. This is one of the most common and preventable security gaps small businesses carry.

Credential stuffing and the dark web

Old credentials, particularly reused passwords, regularly end up in dark web data dumps following unrelated breaches elsewhere. If a zombie account shares a password with any of those exposed credentials, it becomes an easy target for automated attacks that simply try known username and password combinations at scale.

Wasted licence costs

Many cloud tools, including Microsoft 365, Google Workspace and various seat-based software subscriptions, charge per active user. A zombie account isn’t just a security risk, it’s often a small, ongoing, unnecessary cost that adds up across a growing list of forgotten logins.

Compliance and audit failures

Data protection regulations generally expect a business to know who has access to what. A pile of unaccounted-for zombie accounts undermines this, and can genuinely cause a business to fail a security audit or fall short of its data protection obligations.

How zombie accounts typically appear

  • A former employee’s account, never formally deactivated after they left
  • An old trial or free-tier software signup nobody remembers creating
  • A shared or generic account used for a specific project that’s since ended
  • A contractor or freelancer’s temporary access, never revoked after the work finished

How to clean them up

1. Run a regular account audit

Periodically review every active account across your key systems, checking specifically for logins that haven’t been used in a meaningful amount of time. This doesn’t need to be complicated for a small business, a simple, scheduled review of user lists across your main platforms catches most of the risk.

2. Build deactivation into your offboarding process

The most reliable way to prevent zombie accounts is to make account deactivation a mandatory, checked step whenever someone leaves the business or a contractor’s work ends, not an afterthought that depends on someone remembering.

3. Enforce multi-factor authentication

Even if a zombie account’s password is compromised, multi-factor authentication adds a genuine second barrier that significantly reduces the risk of it being exploited.

4. Keep a central record of accounts and licences

A simple, maintained list of who has access to what makes both security reviews and licence cost management considerably easier, rather than trying to reconstruct this information after the fact.

A simple checklist

Task Frequency
Review active accounts across key systems Quarterly
Deactivate accounts as part of offboarding Every time someone leaves
Confirm multi-factor authentication is enabled Ongoing, checked periodically
Review software licence costs against actual active users Quarterly or at renewal

This is part of a wider governance habit

Managing zombie accounts is really one specific piece of a broader access control practice. Our guide on IT governance for small businesses covers the wider set of decisions, including access control and accountability, that this kind of housekeeping fits into.

FAQs

How do I find zombie accounts in my business? Review the user lists across your key systems, particularly email, cloud storage and any subscription software, looking specifically for accounts that haven’t logged in or been used in a meaningful period of time.

Is a zombie account really a serious security risk? Yes. Dormant accounts often carry outdated or weak passwords, sit outside regular monitoring, and give attackers a quieter route into your systems than an actively used account would.

How often should I audit accounts for zombie logins? A quarterly review is a reasonable starting point for most small businesses, alongside making account deactivation a mandatory step whenever an employee or contractor leaves.

Do zombie accounts cost money as well as posing a security risk? Often, yes. Many cloud tools charge per active user, so a forgotten account can represent a small, unnecessary, ongoing cost in addition to the security exposure.

progressd Avatar
No comments to show.

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua.

Insert the contact form shortcode with the additional CSS class- "wydegrid-newsletter-section"

By signing up, you agree to the our terms and our Privacy Policy agreement.