Offcanvas Logo

Menu

  • IT Support
  • Cybersecurity
  • IT Compliance
  • AI Services
  • Blog
  • Why Us

Contact us

  • 1 Executive Dr Suite 100 #123 Marlton NJ 08053
  • 856-282-4100
  • info@xitx.com

Menu

  • IT Support
  • Cybersecurity
  • IT Compliance
  • AI Services
  • Blog
  • Why Us

Contact Us

  • 1 Executive Dr Suite 100 #123 Marlton NJ 08053
  • 856-282-4100
  • info@xitx.com

info@xitx.com
856-282-4100
1 Executive Drive Suite 100 Marlton, NJ 08053
+1 856-282-4100
Facebook-f X-twitter Instagram Linkedin-in Youtube
Xact IT Solutions
Let’s Talk
  • IT Support
  • Cybersecurity
  • IT Compliance
  • AI Services
  • Blog
  • Why Us
Xact IT Solutions
  • IT Support
  • Cybersecurity
  • IT Compliance
  • AI Services
  • Blog
  • Why Us
Let’s Talk

Dormant User Accounts Are Handing Attackers Your Front Door Key

When an employee leaves your company, how long does their login still work? If you don’t know the answer, you’re not alone — and that uncertainty is exactly what attackers are counting on. Dormant user accounts — credentials that once belonged to former employees, departed contractors, or vendor contacts no one remembers onboarding — are one of the most reliable entry points for attackers targeting small and mid-sized businesses right now. CISA, the FBI, and a string of breach disclosures from 2024 into 2025 all tell the same story: organizations that don’t formally shut down access when a working relationship ends are leaving a key under the mat. This post covers what the data shows, why the gap between someone’s last day and the death of their credentials is so dangerous, and what a sound defense looks like.

  1. The Threat Landscape: What the Advisories Are Saying
  2. The Timeline Gap: Why Offboarding Schedules Fail
  3. Who This Affects: The Small Business Blind Spot
  4. Real Examples from Public Disclosures
  5. How Attackers Use Dormant Credentials
  6. Building a Defense Posture That Closes the Gap
  7. What to Ask Your IT Firm Right Now

The Threat Landscape: What the Advisories Are Saying About Dormant User Accounts

CISA’s advisories published throughout 2024 have repeatedly flagged weak identity hygiene as a precondition for successful intrusions. In joint advisories co-authored with the FBI and the National Security Agency, CISA consistently lists “valid accounts” among the top techniques observed in hands-on-keyboard attacks. That means attackers are not always exploiting a software flaw to get in. They are logging in. With real credentials. That nobody thought to revoke.

The 2024 Verizon Data Breach Investigations Report found that stolen or misused credentials were the most common attack path across all incident categories. The FBI’s 2023 Internet Crime Complaint Center report — the most recent full-year data publicly available as of mid-2025 — noted that business email compromise and account takeover losses exceeded $2.9 billion in a single year, with a significant share tied to persistent access that predated the attack by months.

CISA’s 2024 advisory on Scattered Spider, the threat group behind several high-profile intrusions, specifically called out accounts belonging to individuals no longer actively working at the victim organization. The accounts were still live. The passwords hadn’t been changed. In some cases, multi-factor authentication had never been applied to the legacy account at all.

The Timeline Gap: Why Offboarding Schedules Fail

dormant user accounts — Wide shot of a server room or network cabinet with a focus on tangled cables and blinking indicator lights, suggesting complex infrastructure where dormant access points remain hidden among active systems.

The deprovisioning problem is not primarily a technical failure. It’s a process failure that technology then magnifies. When someone leaves, access termination is rarely anyone’s first priority. HR is managing paperwork. The departing employee’s manager is focused on knowledge transfer. IT — if there’s a dedicated IT function at all — may not be notified for days, if ever.

Research compiled by identity security firms and cited in CISA guidance documents suggests the average time between an employee’s last working day and full access termination exceeds two weeks in small business environments. For contractors and vendors, the gap is often indefinite — their accounts drift into dormancy with no formal review triggering their removal.

Two weeks is a long time. In breach timeline analysis, that window is more than enough for an attacker who already holds credentials — obtained through a phishing kit, a dark web purchase, or a prior breach — to test those credentials against cloud applications. Many will succeed because the account still exists and the password hasn’t been rotated.

The compounding factor is cloud application sprawl. A mid-sized company today runs dozens of software-as-a-service applications. Even a diligent IT team may successfully close the primary email account and revoke network access during offboarding. But the accounts in secondary applications — the project management tool added six months ago, the file-sharing platform a client required, the legacy system no one thinks about anymore — those often go untouched. Each one is a potential entry point for attackers who exploit dormant user accounts.

Who This Affects: The Small Business Blind Spot

Enterprise organizations with dedicated identity governance teams aren’t immune to deprovisioning failures, but they at least have systems and staff whose job is to catch them. Small businesses — particularly those in the 10-to-150 employee range — have neither the tooling nor the headcount that makes consistent deprovisioning possible without a formal process.

The typical small business has no identity governance platform. Access decisions are informal. The offboarding checklist lives in someone’s memory or in a shared document that rarely gets updated. Contractors and vendor contacts exist in a particular gray zone: they may never have had formal onboarding, so there’s no corresponding offboarding trigger. Their credentials persist until someone notices — which, in the absence of regular access reviews, may be never.

Professional services firms, healthcare-adjacent organizations, and small manufacturers are categories most frequently cited in CISA’s small business guidance as under-resourced on identity hygiene. In these environments, a former employee’s email account — if still active — provides access not just to internal resources, but potentially to client communications, financial systems, and production environments.

For any business operating under a compliance framework — HIPAA, SOC 2, CMMC, or similar — the deprovisioning gap is not just a security risk. It’s a direct audit finding. Access review and timely deprovisioning are explicit requirements in every major framework. An unreviewed account belonging to a former employee is evidence of control failure, full stop.

Real Examples from Public Disclosures

Because many small business breaches go unreported or are disclosed only in general terms, the clearest public data comes from mid-market and enterprise incidents. The patterns apply directly to smaller environments.

  • The 2023 breach of a major U.S. casino and hospitality group, attributed to Scattered Spider, involved attackers exploiting help desk procedures to reset credentials — including legacy accounts not subject to the same controls as current-employee accounts. CISA published a specific advisory in September 2023 addressing this campaign.
  • A 2024 CISA advisory on Volt Typhoon, a state-sponsored threat group, identified valid accounts — including those belonging to former employees of critical infrastructure operators — as a primary persistence mechanism. The group maintained access in some victim environments for years without detection.
  • The 2023 MOVEit vulnerability chain, while primarily a software exploit, was amplified in several victim organizations by service accounts and vendor accounts that had been provisioned for a specific integration and never reviewed or removed after the original project ended.
  • A mid-2024 breach disclosure from a healthcare technology vendor revealed that the attacker’s initial access came through credentials belonging to an IT contractor whose engagement had ended 14 months prior. The account had been overlooked during a software platform migration.

These are not edge cases. They’re representative of a pattern security researchers and incident responders have documented consistently over the past three years. In every scenario above, dormant user accounts were the attacker’s point of entry — not a zero-day exploit, not a sophisticated phishing campaign, but a door that was simply left open.

How Attackers Use Dormant Credentials

Understanding the attack mechanic matters because it informs the defense. Attackers using dormant credentials behave differently than those working from fresh phishing captures.

First, dormant accounts are often unmonitored. Security tooling is typically configured to flag anomalous behavior from active user accounts. An account with no login activity for 90 days that suddenly authenticates from an overseas IP address may not generate the same alert as an active account showing the same behavior — depending on how monitoring rules are written.

Second, dormant accounts tend to have weaker authentication controls. Multi-factor authentication was often never applied to accounts created before an organization’s current security policies were adopted. A contractor account set up in 2019 may pre-date the company’s multi-factor authentication rollout entirely.

Third, dormant accounts are useful for slow-burn intrusions. An attacker who gains access to a dormant account is not immediately detected. They can use that foothold to map the environment over days or weeks, escalate privileges quietly, and exfiltrate data before anyone notices. The Volt Typhoon advisory is the clearest documented example of this approach operating at scale.

Fourth, dormant accounts frequently carry broader permissions than current employees in equivalent roles. Access tends to expand over time as users accumulate permissions when their responsibilities grow. When they leave, those accumulated permissions leave with them — unreviewed and intact. That over-provisioning makes dormant user accounts especially valuable to attackers looking for lateral movement opportunities.

Building a Defense Posture That Closes the Gap on Dormant User Accounts

A sound defense against dormant account exploitation requires both a process layer and a technical layer. Neither is sufficient on its own.

On the process side, the most important change is a formal offboarding workflow triggered automatically by HR activity — not by IT awareness. If access termination depends on someone remembering to notify IT, it will fail. The trigger must be structural. A departure date entered in the HR system should automatically initiate an access review and termination sequence — not inform it, initiate it.

Vendor and contractor accounts require their own governance. Every account provisioned for a non-employee should have an expiration date or a scheduled review date attached at the time of creation. That’s a cultural and process change more than a technical one, but modern identity platforms support it natively.

On the technical side, the core controls are:

  • Regular access reviews conducted no less than quarterly, with a defined owner for each review cycle
  • Automated detection of accounts with no login activity over a defined window — typically 30 to 60 days
  • Multi-factor authentication applied universally, including to service accounts and legacy accounts, not just new ones
  • Privileged access reviews conducted separately from general user access reviews, and more frequently
  • Application-level access audits that extend beyond the primary directory — covering every cloud application, not just the core identity provider

CISA’s Identity and Access Management guidance for administrators outlines a practical baseline for organizations building or auditing these controls. It’s worth reading in full — and worth handing to your IT firm with a direct question: “Which of these do we currently have in place?”

For organizations subject to compliance frameworks, tying the access review cadence to audit evidence is an added benefit. Every completed access review is a documented control execution. Every dormant account caught and disabled is a finding that won’t appear in your next audit.

Our cybersecurity practice treats identity hygiene as a foundational control, not an optional add-on. The organizations that avoid breaches close these gaps before someone else finds them. You can also explore our broader managed IT services to see how we integrate account lifecycle management into ongoing operations.

Dormant user accounts remain active long after an employee or contractor departs, creating a persistent and often unmonitored entry point for threat actors.

What to Ask Your IT Firm Right Now

The dormant account question is one of the best diagnostics you can run on your current IT provider. The answers will tell you quickly how seriously they treat identity hygiene as a security control — not a checkbox.

  • How are we notified when an employee or contractor account should be deprovisioned? Is that trigger automatic or manual?
  • When was the last full access review conducted across all of our cloud applications — not just our primary email or network environment?
  • Do we have dormant user accounts in any system that haven’t logged in for more than 60 days? If so, what’s the process for reviewing and closing them?
  • Are multi-factor authentication requirements applied to all accounts — including legacy accounts created before our current security policies were adopted?
  • How do we handle vendor and contractor accounts? Is there an expiration or review date attached to each one at the time of creation?
  • If a former employee’s credentials were used to access one of our systems today, how quickly would we detect it?

A provider with mature identity hygiene practices will have clear, specific answers to every one of those questions. Vague answers — or answers that shift responsibility back to you without a defined process — are a warning sign worth taking seriously.

The deprovisioning failure is not a new problem. What has changed is the size of the target surface. Every cloud application, every vendor portal, every project collaboration tool is a door. When someone leaves your organization, the question isn’t whether their access should be removed — it’s whether your current process guarantees that every door closes behind them.

Most small business environments, assessed honestly, can’t make that guarantee. That gap is exactly what the threat actors highlighted in the 2024 and 2025 CISA advisories are counting on. Closing it is one of the highest-return security investments your business can make.

If you want a clear-eyed look at where your access controls stand, Book a Free Cybersecurity Strategy Call. It’s a 20-minute conversation with our team — no pressure, no obligation — and you’ll leave knowing exactly what we’d look at first.

Frustrated With Your Current IT Provider?

If your current MSP isn’t catching the things this post describes, that’s a signal worth acting on. Book a strategy call and we’ll walk through what an honest IT partnership looks like for a business your size.

Claim Your Free Strategy Call

Recent Posts

  • Why Your General Liability Policy Will Deny a Cyber Breach Claim
  • When Checking “Yes” Becomes Fraud: Personal Liability for Cybersecurity for Mid-Market COOs
  • HIPAA IT Compliance Checklist: Is Your Small Practice Audit-Ready?
  • Stop Wasting Staff Hours: AI Automation Agency vs. DIY Software Tools
  • Who Owns Your Domain? How to Prevent Vendor Lock-In and Secure Your Digital Identity

Categories

  • AI for Business
  • Backup & Recovery
  • Blog
  • Business
  • Buyer Guides
  • CMMC
  • Compliance
  • Cybersecurity
  • Healthcare
  • Managed IT
  • News & Analysis
  • Threat Intelligence

Share

FRUSTRATED WITH YOUR CURRENT IT PROVIDER? LET’S TALK.

Get a Free IT Consultation
Xact IT Solutions
  • info@xitx.com
  • +1 856-282-4100
  • 1 Executive Drive Suite 100 Marlton NJ 08053

Follow Us

Quick Links
  • Home
  • Partner Program
  • Why Choose Xact IT Solutions | Xact IT Solutions
  • Book Your Strategy Call
Services
  • IT Support
  • Cybersecurity Services for SMBs | Xact IT Solutions
  • IT Compliance
Recent Blogs
  • Supply-Chain Ransomware Attack Impacts 60 Credit Unions
  • Comcast Xfinity Data Breach Exposes 36 Million Customers’ Data
  • Crown Equipment’s Cyberattack: Recovery and Lessons Learned
Copyright © 2026. Website Design by Xact IT Solutions
  • Privacy Policy and Terms & Conditions
  • Home
  • Partner Program
  • Why Choose Xact IT Solutions | Xact IT Solutions
  • Book Your Strategy Call