privacy

Ghost Accounts: The Cloud Services Still Holding Your Files

Most people have tried a dozen cloud storage services over the years. Nearly all of them still have your files. Each one is a security liability you've stopped thinking about.

Think back to every cloud storage service you’ve ever tried. The one you used for a year before switching. The photo backup app that came pre-installed on your old Android. The service you signed up for during a promotion offering several gigabytes free. The one a colleague recommended, which you used to share a single project file.

Most people can name a few. Fewer people can name all of them. And almost no one has closed all the accounts they’ve opened over the years.

Those accounts still exist. They still hold your files. And they are, in many cases, significantly less secure than the accounts you actually use and manage today.


The Accumulation Problem

Cloud storage proliferated rapidly during the 2010s. The promise of free storage — initially generous, then gradually constrained — drove millions of signups. Services competed on features, storage allowances, and platform integration. Users tried multiple options before settling on a primary service, often leaving accounts open elsewhere.

The typical pattern looks something like this: Dropbox in the early days when it was the default sync tool, then Google Drive when it became integrated with Gmail, then iCloud when switching to iPhone, then maybe Box during a corporate job, then a brief experiment with another service during one of the periodic “Google is killing off free storage” panics.

At each transition, the old account was usually not closed. There wasn’t a compelling reason to close it, and closing accounts takes effort. The files stayed. The password stayed. The linked email address stayed.

Now multiply this by the number of services that have launched, been acquired, pivoted, or quietly degraded since cloud storage became mainstream. The accumulation of ghost accounts across any given user’s history is substantial.


What These Accounts Still Hold

The specific risk of a ghost cloud account depends on what’s in it and how the service has evolved.

In the best case, the account holds a few irrelevant files from years ago, uses a unique password, and the email address linked to it is still actively monitored. In this case, the ghost account is a minor liability.

In more common cases, the account holds:

Personal files you’ve forgotten about. Old photo backups, scanned documents, early drafts of personal projects. Content that felt unimportant at the time may include information you’d now prefer wasn’t sitting in a poorly-monitored account — addresses, financial details, ID scans, personal photos.

A reused password. The password you used for the ghost account was probably set years ago, when password reuse was a near-universal habit. If that password appears in any subsequent breach — and at this point, most older passwords do appear in some breach database — the cloud account is accessible to anyone who queries that database.

Your primary email as the linked contact. If attackers gain access to the ghost account, they can potentially trigger a password reset to whatever email is registered there. If that email is your current primary account, the chain goes the other way: your current account is now linked to a service you haven’t thought about in years.

Files shared with others, or shared by link. Many old cloud accounts have open sharing links — links that were created years ago for a temporary purpose and never revoked. Anyone with those links still has access.


Services That Have Changed or Shut Down

Some cloud storage services have changed in ways that specifically affect dormant accounts.

Amazon Drive terminated its unlimited photo and file storage service for consumer users in December 2023. Users who had backed up files there without realising the service was ending may have lost access to files they assumed were safely stored. This is one consequence of ghost account status: when a service changes its policies or shuts down, inactive users are the last to know.

Flickr reduced its free tier from one terabyte to 1,000 photos in 2019. Photos above the limit were deleted. Users with dormant Flickr accounts who weren’t monitoring them lost files permanently.

Various “unlimited backup” services — including some that specifically marketed to photographers and video creators — have shut down or changed terms without adequate user notification. The files simply stopped being accessible.

For dormant accounts, these transitions are particularly costly. An active user notices the service announcement, takes action, and migrates their files. A dormant user doesn’t notice, and discovers the loss later — if at all.


The Security Posture of Older Accounts

There’s a structural problem with accounts you haven’t touched in years: their security reflects the standards of when you created them, not today’s.

In 2014, a strong password might have meant something with eight characters and a number. Multi-factor authentication wasn’t widely available or expected. Security questions — “what was the name of your first pet?” — were considered meaningful identity verification.

A ghost cloud account created in 2014 probably has:

  • A shorter, simpler password than you’d choose today
  • No multi-factor authentication enabled (because it wasn’t mandatory or even offered)
  • Security questions with answers easily findable through your social media history
  • A recovery email address that may be another ghost account

Meanwhile, the service itself may have had security incidents since your last login. Dropbox disclosed a breach in 2012 that affected 68 million accounts; the full scope wasn’t confirmed until 2016. Users who had dormant Dropbox accounts during that period may not have taken remediation steps, because they weren’t actively using the service and didn’t see the notification.


Finding Your Ghost Accounts

Most people underestimate how many cloud storage and file sharing accounts they have. The most systematic way to find them is through your email history.

Search for signup and welcome emails

In your primary email account, search for terms like:

  • “welcome to” combined with “storage”, “drive”, “files”, “photos”, “backup”, “cloud”
  • “verify your email” from services you don’t currently recognise
  • “your account” from services you haven’t thought about in years
  • Specific service names you’re uncertain about: Box, Tresorit, pCloud, Mega, MediaFire, SugarSync, Amazon Drive, Carousel, Copy.com, Bitcasa

The results will show the accounts you’ve created over the years, including many you’d forgotten.

Check your password manager

If you’ve used a password manager for several years, it contains a record of accounts you’ve created. Look for cloud storage, file sharing, and photo backup services in the saved entries. If you find credentials for services you don’t currently use, that’s a ghost account.

Check browser saved passwords

Similar to a password manager: your browser’s saved passwords include sites you’ve visited and authenticated with. Review the list for cloud services.


What to Do With Ghost Accounts

Once you’ve identified dormant cloud storage accounts, you have a few options.

Close the account. For accounts you no longer use and don’t want to keep, request account deletion. Under GDPR (for users in the European Union and EEA) and CCPA (for California residents), you have the right to request erasure of your personal data. Most cloud services have a deletion option in account settings; for older or obscure services, a direct email request citing your right to erasure is appropriate.

Before closing an account, download any files you want to keep. Use the service’s export or download function, or a tool like Google Takeout for Google-based accounts. Confirm the download is complete before requesting deletion.

Migrate the files and close. If the account holds files you want to keep, download them and store them in your current, actively managed cloud storage. Then close the old account. This consolidates your files into a place you actually monitor.

Update security and keep the account. For accounts you want to keep active, update the password to a unique, strong credential, enable multi-factor authentication if available, update the recovery email to an address you actively use, and review any files shared by link, revoking access for shares you no longer need.

The goal isn’t necessarily to close everything — it’s to ensure that every cloud account you have is either actively managed or definitively closed. Ghost accounts, by definition, are neither.


Consolidation as a Privacy Strategy

The more places your personal files live, the more breach surfaces you have. Each cloud account is a potential entry point. Each one governed by its own terms of service, its own privacy policy, and its own security practices — which may have changed significantly since you signed up.

Consolidating your personal files into a smaller number of actively managed, deliberately chosen services reduces this surface. It also makes it practical to actually pay attention to the security practices of those services — their incident disclosures, policy changes, and security updates.

A single trusted service you actively use and monitor is meaningfully safer than a primary service you trust plus five ghost accounts you’ve forgotten about.

The files in those ghost accounts feel safe because nothing bad has happened yet. But that’s not the same as being safe. It means the breach, if it comes, will be one you don’t see coming.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts