Ghost Accounts: The Underground Market for Dormant Digital Identities and the Fraud They Enable
Photo: dormant account hacking digital identity cybercrime dark web, via c8.alamy.com
Somewhere, there is likely an account bearing your name and email address on a platform you have not visited in three years. Perhaps it is the gaming network you abandoned after a console upgrade, the streaming service you canceled but never formally deleted, or the Discord server you joined for a conference and never returned to. You have forgotten it. The platform has not. And neither, increasingly, have the criminals who have made a sophisticated business of acquiring exactly these kinds of digital ghosts.
The trade in dormant accounts is not new, but its scale and operational sophistication have grown considerably as cybercriminal ecosystems have matured. What was once a relatively crude market — stolen credentials exchanged for small sums on low-tier forums — has evolved into a layered economy in which aged, reputable accounts command premium prices precisely because of the trust they have accumulated over time.
Why Age and Credibility Matter
To understand why a dormant account is worth more than a freshly created one, it is necessary to understand how platform trust systems work. Services like Discord, PlayStation Network, Reddit, and Netflix assess account behavior over time. An account created in 2017 with a history of purchases, social connections, and consistent login patterns presents a fundamentally different risk profile to a platform's fraud-detection algorithms than one registered last Tuesday.
This is the core insight that drives the dormant-account economy. Criminal operators refer to these profiles as "aged accounts" — and in underground forums and encrypted marketplaces, age is a pricing variable. A Discord account with several years of history and membership in multiple servers sells for considerably more than a newly registered one. A PlayStation Network account with a substantial game library and a positive reputation score is worth more still, particularly if a payment method remains attached.
The trust that platforms extend to aged accounts is not irrational — it reflects genuine signal about account legitimacy. The problem is that criminals have learned to exploit that signal by acquiring accounts rather than building them.
The Acquisition Pipeline
Dormant accounts enter criminal circulation through several well-established pathways.
Credential stuffing remains the most volumetrically significant. Automated tools test username-and-password combinations harvested from prior breaches against dozens of platforms simultaneously. Because password reuse remains widespread among American consumers, a credential set exposed in a retail data breach from several years ago may still unlock a gaming account, a streaming subscription, or a social media profile. The success rate on any individual attempt is low; the scale at which these attacks operate makes even low success rates commercially viable.
Phishing campaigns targeting specific platforms generate higher-quality account access, particularly when they capture session cookies in addition to credentials — rendering two-factor authentication irrelevant, as the attacker inherits an already-authenticated session rather than attempting to log in from scratch.
Infostealer malware, distributed through malicious downloads, browser extensions, and compromised software installers, harvests saved credentials directly from infected machines. Security researchers tracking infostealer logs — packages of stolen data sold in bulk — have documented the routine inclusion of streaming and gaming credentials alongside banking and email account details.
Once acquired, accounts are either sold outright or retained for operational use, depending on their characteristics and the acquiring actor's objectives.
What Attackers Do With Them
The applications are varied and, from a law-enforcement perspective, genuinely difficult to trace.
Fraud and resale. Streaming accounts with active subscriptions are sold to consumers seeking discounted access — a practice so normalized that it has spawned semi-public storefronts on platforms including Telegram. The original account holder typically notices only when they are locked out or receive a notification about an unfamiliar login. Gaming accounts with rare in-game items or high competitive rankings are similarly resold, often for significant sums on gray-market exchanges.
Malware distribution. Discord, in particular, has been extensively documented as a malware distribution vector. Attackers who gain access to accounts with established server memberships and social connections can distribute malicious links to those communities with a credibility that a new or unknown account cannot replicate. Recipients who might dismiss a link from a stranger are more likely to act on one from a profile they have interacted with for years.
Social engineering. An aged social media account with followers, a posting history, and apparent legitimacy is a powerful tool for manipulation. Attackers have used compromised Reddit, Twitter/X, and Facebook accounts to spread disinformation, conduct romance scams, and impersonate individuals in targeted fraud schemes — all while the genuine account holder remains unaware.
Money laundering through virtual economies. In-game currencies and digital items on platforms including Steam, Roblox, and various MMOs have been used as intermediary value stores. Proceeds from fraud are converted into virtual goods, transferred across accounts, and then liquidated — a process that exploits the limited financial-crime oversight applied to gaming economies.
The Detection Gap
What makes dormant accounts particularly useful to attackers is the same thing that makes them dangerous for users: platforms have limited incentive to aggressively flag or terminate inactive accounts. A dormant account with a paid subscription is revenue. Aggressive account termination risks alienating legitimate users who simply haven't logged in recently. The result is that platforms extend a form of passive trust to accounts that may have changed hands without their knowledge.
Fraud-detection systems are calibrated around behavioral anomalies — sudden changes in login geography, unusual purchasing patterns, access from new devices. An attacker who takes control of an account gradually and uses it in ways consistent with its historical patterns may never trigger those systems at all.
Securing the Accounts You Have Forgotten
The practical response to this threat begins with an honest audit of your digital footprint.
Enumerate your accounts. Use your primary email address's search function to locate registration confirmations from platforms you may have forgotten. Tools such as HaveIBeenPwned can indicate whether your email address appears in known breach datasets, which may help prioritize which accounts require immediate attention.
Delete what you no longer need. Most platforms provide an account deletion mechanism, though it is rarely advertised prominently. Deleting a dormant account eliminates it as an attack surface entirely. If a platform does not offer deletion, submit a data deletion request under applicable state privacy law — California's CCPA, Colorado's CPA, and Virginia's CDPA all provide this right to residents.
Remove stored payment methods from accounts you intend to keep but use infrequently. A dormant account without an attached payment method is significantly less valuable as a fraud instrument.
Enable two-factor authentication universally. This remains the single most effective control against credential-stuffing attacks. Hardware security keys and authenticator apps provide substantially stronger protection than SMS-based codes, which remain vulnerable to SIM-swap attacks.
Use unique passwords for every account, managed through a reputable password manager. Password reuse is the primary mechanism through which credential-stuffing attacks succeed. Eliminating it closes the most common acquisition pathway.
The accounts you have abandoned are not inert. In a criminal ecosystem that assigns concrete value to accumulated digital credibility, every forgotten profile is a potential instrument of fraud waiting to be claimed.