Cybersecurity 3 min read September 26, 2026

Could we have a forgotten account nobody's watching?

A breach hit 5,700 Microsoft 365 accounts across 28 companies last week. Not one belonged to an actual employee — every single one was a service account nobody remembered setting up.

The question

"We've had the same Microsoft 365 setup for years, with a few different IT people touching it along the way. Is there any real way to know if there's some old integration or login still sitting there that nobody's watching anymore?"

Good question, and the timing helped answer it. Researchers just tracked a campaign that broke into 5,700 accounts across 28 Microsoft 365 tenants. Not one was a phished employee or a zero-day exploit. Every account was an unmanaged service account — set up years ago for some tool or integration, still running a default password, no multi-factor authentication, and nobody left at the company even remembered it existed.

What we told them

Almost certainly, yes — and it's rarely anyone's fault in particular. Service accounts get created for a specific reason (a CRM sync, a backup job, a vendor integration), the person who set it up moves on or the project ends, and the account just keeps existing. It doesn't show up in security awareness training. It doesn't get MFA prompts nagging a real person to fix. It's invisible until someone finds it.

Here's how we walked them through finding theirs:

  • Pull the full list of accounts, not just active employees. In Microsoft 365 admin center, that means every account and every registered app/service principal — not just the ones in your HR system.
  • Flag anything without MFA enrolled. A real, actively-used account almost always has MFA. An account with none is either forgotten or was set up to deliberately bypass it — both are worth investigating.
  • Check last sign-in dates. An account that hasn't authenticated in months but is still enabled is a candidate for disabling, not just monitoring.
  • Ask "who owns this?" for every service account that's still active. If nobody in the room can answer, that's the account most likely to be sitting on a default password right now.

None of this requires new tooling — it's an afternoon of looking somewhere most businesses never think to look, because "our accounts" mentally means "our people," not the invisible layer of logins those people set up on the business's behalf.

The takeaway

The account most likely to get you breached isn't the one you're watching — it's the one you forgot you had. If you can't name every login tied to your Microsoft 365 tenant right now, that's this week's to-do.

Got a question like this one?

Send it over — 20 minutes, no pitch, a straight answer either way.