When an employee leaves your company, how long does their login still work? If you don’t know the answer, you’re not alone — and that uncertainty is exactly what attackers are counting on. Dormant user accounts — credentials that once belonged to former employees, departed contractors, or vendor contacts no one remembers onboarding — are one of the most reliable entry points for attackers targeting small and mid-sized businesses right now. CISA, the FBI, and a string of breach disclosures from 2024 into 2025 all tell the same story: organizations that don’t formally shut down access when a working relationship ends are leaving a key under the mat. This post covers what the data shows, why the gap between someone’s last day and the death of their credentials is so dangerous, and what a sound defense looks like.
- The Threat Landscape: What the Advisories Are Saying
- The Timeline Gap: Why Offboarding Schedules Fail
- Who This Affects: The Small Business Blind Spot
- Real Examples from Public Disclosures
- How Attackers Use Dormant Credentials
- Building a Defense Posture That Closes the Gap
- What to Ask Your IT Firm Right Now
The Threat Landscape: What the Advisories Are Saying About Dormant User Accounts
CISA’s advisories published throughout 2024 have repeatedly flagged weak identity hygiene as a precondition for successful intrusions. In joint advisories co-authored with the FBI and the National Security Agency, CISA consistently lists “valid accounts” among the top techniques observed in hands-on-keyboard attacks. That means attackers are not always exploiting a software flaw to get in. They are logging in. With real credentials. That nobody thought to revoke.
The 2024 Verizon Data Breach Investigations Report found that stolen or misused credentials were the most common attack path across all incident categories. The FBI’s 2023 Internet Crime Complaint Center report — the most recent full-year data publicly available as of mid-2025 — noted that business email compromise and account takeover losses exceeded $2.9 billion in a single year, with a significant share tied to persistent access that predated the attack by months.
CISA’s 2024 advisory on Scattered Spider, the threat group behind several high-profile intrusions, specifically called out accounts belonging to individuals no longer actively working at the victim organization. The accounts were still live. The passwords hadn’t been changed. In some cases, multi-factor authentication had never been applied to the legacy account at all.
The Timeline Gap: Why Offboarding Schedules Fail

The deprovisioning problem is not primarily a technical failure. It’s a process failure that technology then magnifies. When someone leaves, access termination is rarely anyone’s first priority. HR is managing paperwork. The departing employee’s manager is focused on knowledge transfer. IT — if there’s a dedicated IT function at all — may not be notified for days, if ever.
Research compiled by identity security firms and cited in CISA guidance documents suggests the average time between an employee’s last working day and full access termination exceeds two weeks in small business environments. For contractors and vendors, the gap is often indefinite — their accounts drift into dormancy with no formal review triggering their removal.
Two weeks is a long time. In breach timeline analysis, that window is more than enough for an attacker who already holds credentials — obtained through a phishing kit, a dark web purchase, or a prior breach — to test those credentials against cloud applications. Many will succeed because the account still exists and the password hasn’t been rotated.
The compounding factor is cloud application sprawl. A mid-sized company today runs dozens of software-as-a-service applications. Even a diligent IT team may successfully close the primary email account and revoke network access during offboarding. But the accounts in secondary applications — the project management tool added six months ago, the file-sharing platform a client required, the legacy system no one thinks about anymore — those often go untouched. Each one is a potential entry point for attackers who exploit dormant user accounts.
Who This Affects: The Small Business Blind Spot
Enterprise organizations with dedicated identity governance teams aren’t immune to deprovisioning failures, but they at least have systems and staff whose job is to catch them. Small businesses — particularly those in the 10-to-150 employee range — have neither the tooling nor the headcount that makes consistent deprovisioning possible without a formal process.
The typical small business has no identity governance platform. Access decisions are informal. The offboarding checklist lives in someone’s memory or in a shared document that rarely gets updated. Contractors and vendor contacts exist in a particular gray zone: they may never have had formal onboarding, so there’s no corresponding offboarding trigger. Their credentials persist until someone notices — which, in the absence of regular access reviews, may be never.
Professional services firms, healthcare-adjacent organizations, and small manufacturers are categories most frequently cited in CISA’s small business guidance as under-resourced on identity hygiene. In these environments, a former employee’s email account — if still active — provides access not just to internal resources, but potentially to client communications, financial systems, and production environments.
For any business operating under a compliance framework — HIPAA, SOC 2, CMMC, or similar — the deprovisioning gap is not just a security risk. It’s a direct audit finding. Access review and timely deprovisioning are explicit requirements in every major framework. An unreviewed account belonging to a former employee is evidence of control failure, full stop.
Real Examples from Public Disclosures
Because many small business breaches go unreported or are disclosed only in general terms, the clearest public data comes from mid-market and enterprise incidents. The patterns apply directly to smaller environments.
- The 2023 breach of a major U.S. casino and hospitality group, attributed to Scattered Spider, involved attackers exploiting help desk procedures to reset credentials — including legacy accounts not subject to the same controls as current-employee accounts. CISA published a specific advisory in September 2023 addressing this campaign.
- A 2024 CISA advisory on Volt Typhoon, a state-sponsored threat group, identified valid accounts — including those belonging to former employees of critical infrastructure operators — as a primary persistence mechanism. The group maintained access in some victim environments for years without detection.
- The 2023 MOVEit vulnerability chain, while primarily a software exploit, was amplified in several victim organizations by service accounts and vendor accounts that had been provisioned for a specific integration and never reviewed or removed after the original project ended.
- A mid-2024 breach disclosure from a healthcare technology vendor revealed that the attacker’s initial access came through credentials belonging to an IT contractor whose engagement had ended 14 months prior. The account had been overlooked during a software platform migration.
These are not edge cases. They’re representative of a pattern security researchers and incident responders have documented consistently over the past three years. In every scenario above, dormant user accounts were the attacker’s point of entry — not a zero-day exploit, not a sophisticated phishing campaign, but a door that was simply left open.
How Attackers Use Dormant Credentials
Understanding the attack mechanic matters because it informs the defense. Attackers using dormant credentials behave differently than those working from fresh phishing captures.
First, dormant accounts are often unmonitored. Security tooling is typically configured to flag anomalous behavior from active user accounts. An account with no login activity for 90 days that suddenly authenticates from an overseas IP address may not generate the same alert as an active account showing the same behavior — depending on how monitoring rules are written.
Second, dormant accounts tend to have weaker authentication controls. Multi-factor authentication was often never applied to accounts created before an organization’s current security policies were adopted. A contractor account set up in 2019 may pre-date the company’s multi-factor authentication rollout entirely.
Third, dormant accounts are useful for slow-burn intrusions. An attacker who gains access to a dormant account is not immediately detected. They can use that foothold to map the environment over days or weeks, escalate privileges quietly, and exfiltrate data before anyone notices. The Volt Typhoon advisory is the clearest documented example of this approach operating at scale.
Fourth, dormant accounts frequently carry broader permissions than current employees in equivalent roles. Access tends to expand over time as users accumulate permissions when their responsibilities grow. When they leave, those accumulated permissions leave with them — unreviewed and intact. That over-provisioning makes dormant user accounts especially valuable to attackers looking for lateral movement opportunities.
Building a Defense Posture That Closes the Gap on Dormant User Accounts
A sound defense against dormant account exploitation requires both a process layer and a technical layer. Neither is sufficient on its own.
On the process side, the most important change is a formal offboarding workflow triggered automatically by HR activity — not by IT awareness. If access termination depends on someone remembering to notify IT, it will fail. The trigger must be structural. A departure date entered in the HR system should automatically initiate an access review and termination sequence — not inform it, initiate it.
Vendor and contractor accounts require their own governance. Every account provisioned for a non-employee should have an expiration date or a scheduled review date attached at the time of creation. That’s a cultural and process change more than a technical one, but modern identity platforms support it natively.
On the technical side, the core controls are:
- Regular access reviews conducted no less than quarterly, with a defined owner for each review cycle
- Automated detection of accounts with no login activity over a defined window — typically 30 to 60 days
- Multi-factor authentication applied universally, including to service accounts and legacy accounts, not just new ones
- Privileged access reviews conducted separately from general user access reviews, and more frequently
- Application-level access audits that extend beyond the primary directory — covering every cloud application, not just the core identity provider
CISA’s Identity and Access Management guidance for administrators outlines a practical baseline for organizations building or auditing these controls. It’s worth reading in full — and worth handing to your IT firm with a direct question: “Which of these do we currently have in place?”
For organizations subject to compliance frameworks, tying the access review cadence to audit evidence is an added benefit. Every completed access review is a documented control execution. Every dormant account caught and disabled is a finding that won’t appear in your next audit.
Our cybersecurity practice treats identity hygiene as a foundational control, not an optional add-on. The organizations that avoid breaches close these gaps before someone else finds them. You can also explore our broader managed IT services to see how we integrate account lifecycle management into ongoing operations.
What to Ask Your IT Firm Right Now
The dormant account question is one of the best diagnostics you can run on your current IT provider. The answers will tell you quickly how seriously they treat identity hygiene as a security control — not a checkbox.
- How are we notified when an employee or contractor account should be deprovisioned? Is that trigger automatic or manual?
- When was the last full access review conducted across all of our cloud applications — not just our primary email or network environment?
- Do we have dormant user accounts in any system that haven’t logged in for more than 60 days? If so, what’s the process for reviewing and closing them?
- Are multi-factor authentication requirements applied to all accounts — including legacy accounts created before our current security policies were adopted?
- How do we handle vendor and contractor accounts? Is there an expiration or review date attached to each one at the time of creation?
- If a former employee’s credentials were used to access one of our systems today, how quickly would we detect it?
A provider with mature identity hygiene practices will have clear, specific answers to every one of those questions. Vague answers — or answers that shift responsibility back to you without a defined process — are a warning sign worth taking seriously.
The deprovisioning failure is not a new problem. What has changed is the size of the target surface. Every cloud application, every vendor portal, every project collaboration tool is a door. When someone leaves your organization, the question isn’t whether their access should be removed — it’s whether your current process guarantees that every door closes behind them.
Most small business environments, assessed honestly, can’t make that guarantee. That gap is exactly what the threat actors highlighted in the 2024 and 2025 CISA advisories are counting on. Closing it is one of the highest-return security investments your business can make.
If you want a clear-eyed look at where your access controls stand, Book a Free Cybersecurity Strategy Call. It’s a 20-minute conversation with our team — no pressure, no obligation — and you’ll leave knowing exactly what we’d look at first.
Frustrated With Your Current IT Provider?
If your current MSP isn’t catching the things this post describes, that’s a signal worth acting on. Book a strategy call and we’ll walk through what an honest IT partnership looks like for a business your size.