Subscribe to the Zog Blog to get news Delivered straight to Your box!
Newsletter Signup
Recent Posts
Archives
Archives
- September 2026 (7)
- August 2026 (1)
- May 2026 (2)
- November 2025 (1)
- September 2025 (1)
- May 2025 (1)
- March 2025 (1)
- November 2024 (1)
- October 2024 (1)
- August 2024 (1)
- July 2024 (1)
- June 2024 (1)
- May 2024 (1)
- December 2023 (2)
- November 2023 (1)
- August 2023 (1)
- June 2023 (1)
- May 2023 (1)
- April 2023 (1)
- December 2022 (4)
- November 2022 (3)
- October 2022 (2)
- September 2022 (2)
- August 2022 (3)
- July 2022 (2)
- May 2022 (3)
- April 2022 (2)
- March 2020 (1)
- November 2019 (1)
- October 2019 (2)
- September 2019 (3)
- August 2019 (2)
- July 2019 (5)
- June 2019 (3)
- May 2019 (2)
- April 2019 (1)
- March 2019 (2)
- August 2018 (2)
- July 2018 (1)
- June 2018 (1)
- May 2018 (4)
- April 2018 (5)
- March 2018 (2)
- February 2018 (3)
- January 2018 (3)
- December 2017 (3)
- November 2017 (2)
- October 2017 (3)
- September 2017 (4)
- August 2017 (2)
- July 2017 (4)
- June 2017 (4)
- May 2017 (5)
- April 2017 (4)
- March 2017 (3)
- February 2017 (4)
- January 2017 (5)
- December 2016 (4)
- November 2016 (5)
- October 2016 (4)
- September 2016 (3)
- August 2016 (4)
- July 2016 (1)
The Password Graveyard: Your Old Passwords Aren't as Dead as You Think
Five years ago, an employee created an account on an unrelated website.
They used their work email address.
And the same—or similar—password they used elsewhere.
Years later, that website is breached.
The employee has forgotten the account even exists.
The internet hasn’t.
Those credentials can resurface in breach data and criminal marketplaces. And suddenly, a password from years ago is trying to come back from the dead.
Welcome to Week 4 of Zog’s 8 Weeks of Cyber Horrors and The Password Graveyard.
Because passwords have a way of sticking around long after we've forgotten about them.
Password Reuse Keeps Old Breaches Alive
Think about how many online accounts the average person accumulates.
Work applications. Shopping sites. Professional associations. Software trials. Cloud services. Vendors. Websites you signed into once and never thought about again.
Remembering a completely unique password for every account is difficult.
So people reuse them and cybercriminals know this.
When usernames and passwords are exposed in a breach, attackers can try those credentials—or variations of them—against other services.
This is known as credential stuffing.
The original breach doesn't even have to involve your company. A breach at an unrelated website can create a problem for your organization if an employee reused those credentials somewhere that matters.
Email. Microsoft 365. Cloud applications. Remote access. Business systems.
That's why a breach involving some website you've barely heard of can still come knocking on your door.
One Password Can Unlock More Than One Door
A compromised business account can give an attacker more than access to a single application.
Consider email.
Many online services use an email address as the username. Password-reset links are often delivered to that same inbox.
If an attacker gains access to an employee's email, they may be able to use it to target other accounts, impersonate that employee or send convincing messages to coworkers, customers and vendors.
The attacker isn't necessarily pretending to be your employee anymore.
They're using your employee's actual account.
That's a much harder attack to recognize.
Then There Are the Forgotten Accounts
Passwords aren't the only things buried in the graveyard.
There are also accounts your organization may have forgotten.
Former employees.
Old vendors.
Unused administrators.
Temporary accounts.
Test accounts.
Accounts for applications nobody uses anymore.
Maybe an employee left two years ago, but an account was never disabled.
Maybe a vendor received access for a project that ended months ago.
Maybe someone created an administrator account to solve a problem and nobody remembered to remove it.
Every unnecessary account represents another potential door.
And forgotten doors don't get checked very often.
A Strong Password Isn't Enough
Strong, unique passwords still matter.
But even an excellent password can be compromised.
Someone can enter it into a convincing phishing page. Malware can steal credentials. A third-party service can suffer a breach.
That's why businesses shouldn't rely on passwords as the only thing standing between an attacker and critical systems.
Passwords should be one layer of security—not the entire strategy.
Multi-factor authentication can create another barrier when a password is stolen. Password managers can help employees maintain unique credentials. Monitoring can identify suspicious sign-ins. Access controls can limit the damage if an account is compromised.
And good identity management makes sure unnecessary accounts aren't hanging around indefinitely.
Your Password Graveyard May Be Bigger Than You Think
The real issue isn't simply weak passwords.
It's identity management.
Who has access?
What can they access?
Why do they have that access?
Do they still need it?
Are former employees removed promptly?
Are old vendor accounts disabled?
Are privileged accounts limited?
Is MFA protecting important systems?
Those are questions business leaders should be asking. Because you can't protect an account you don't know still exists.
CONCLUSION
A Business Leader’s Question
This week, ask your IT team:
“If we looked at every account that can access our systems today, could we confidently explain who owns it, why it exists and whether it still needs access?”
The Password Graveyard grows quietly.
An employee leaves. A vendor finishes a project. An application gets replaced. A password gets reused. Another account gets forgotten.
Individually, none may seem particularly frightening.
Together, they can leave behind credentials and access nobody is paying attention to.
And that's exactly where attackers like to look.
Passwords aren't dead yet. But businesses need to stop treating them like they're the only thing standing between an attacker and the network.
Can You Survive the Scare?
On Thursday, we'll return to The Password Graveyard with practical ways to keep old credentials from coming back from the dead.
Because sometimes the best way to deal with a ghost from your past is to make sure it can't log in anymore.


Leave a Comment
Your email address will not be published. Required fields are marked *