Five years ago, an employee created an account on an unrelated website.
They used their work email address.
And the same—or similar—password they used elsewhere.
Years later, that website is breached.
The employee has forgotten the account even exists.
The internet hasn’t.
Those credentials can resurface in breach data and criminal marketplaces. And suddenly, a password from years ago is trying to come back from the dead.
Welcome to Week 4 of Zog’s 8 Weeks of Cyber Horrors and The Password Graveyard.
Because passwords have a way of sticking around long after we've forgotten about them.
Password Reuse Keeps Old Breaches Alive
Think about how many online accounts the average person accumulates.
Work applications. Shopping sites. Professional associations. Software trials. Cloud services. Vendors. Websites you signed into once and never thought about again.
Remembering a completely unique password for every account is difficult.
So people reuse them and cybercriminals know this.
When usernames and passwords are exposed in a breach, attackers can try those credentials—or variations of them—against other services.
This is known as credential stuffing.
The original breach doesn't even have to involve your company. A breach at an unrelated website can create a problem for your organization if an employee reused those credentials somewhere that matters.
Email. Microsoft 365. Cloud applications. Remote access. Business systems.
That's why a breach involving some website you've barely heard of can still come knocking on your door.
One Password Can Unlock More Than One Door
A compromised business account can give an attacker more than access to a single application.
Consider email.
Many online services use an email address as the username. Password-reset links are often delivered to that same inbox.
If an attacker gains access to an employee's email, they may be able to use it to target other accounts, impersonate that employee or send convincing messages to coworkers, customers and vendors.
The attacker isn't necessarily pretending to be your employee anymore.
They're using your employee's actual account.
That's a much harder attack to recognize.
Then There Are the Forgotten Accounts
Passwords aren't the only things buried in the graveyard.
There are also accounts your organization may have forgotten.
Former employees.
Old vendors.
Unused administrators.
Temporary accounts.
Test accounts.
Accounts for applications nobody uses anymore.
Maybe an employee left two years ago, but an account was never disabled.
Maybe a vendor received access for a project that ended months ago.
Maybe someone created an administrator account to solve a problem and nobody remembered to remove it.
Every unnecessary account represents another potential door.
And forgotten doors don't get checked very often.
A Strong Password Isn't Enough
Strong, unique passwords still matter.
But even an excellent password can be compromised.
Someone can enter it into a convincing phishing page. Malware can steal credentials. A third-party service can suffer a breach.
That's why businesses shouldn't rely on passwords as the only thing standing between an attacker and critical systems.
Passwords should be one layer of security—not the entire strategy.
Multi-factor authentication can create another barrier when a password is stolen. Password managers can help employees maintain unique credentials. Monitoring can identify suspicious sign-ins. Access controls can limit the damage if an account is compromised.
And good identity management makes sure unnecessary accounts aren't hanging around indefinitely.
Your Password Graveyard May Be Bigger Than You Think
The real issue isn't simply weak passwords.
It's identity management.
Who has access?
What can they access?
Why do they have that access?
Do they still need it?
Are former employees removed promptly?
Are old vendor accounts disabled?
Are privileged accounts limited?
Is MFA protecting important systems?
Those are questions business leaders should be asking. Because you can't protect an account you don't know still exists.
CONCLUSION
A Business Leader’s Question
This week, ask your IT team:
“If we looked at every account that can access our systems today, could we confidently explain who owns it, why it exists and whether it still needs access?”
The Password Graveyard grows quietly.
An employee leaves. A vendor finishes a project. An application gets replaced. A password gets reused. Another account gets forgotten.
Individually, none may seem particularly frightening.
Together, they can leave behind credentials and access nobody is paying attention to.
And that's exactly where attackers like to look.
Passwords aren't dead yet. But businesses need to stop treating them like they're the only thing standing between an attacker and the network.
Can You Survive the Scare?
On Thursday, we'll return to The Password Graveyard with practical ways to keep old credentials from coming back from the dead.
Because sometimes the best way to deal with a ghost from your past is to make sure it can't log in anymore.