A technology journalist uncovered dozens of dormant online accounts, some created years earlier during product reviews. These inactive profiles remained accessible, raising concerns about their potential risks. The discovery prompted an investigation into how many forgotten accounts might still exist and what dangers they could pose.
Consumer Reports had previously detailed a manual method for locating forgotten accounts by searching email archives for signup confirmations. The journalist expanded on this by using an AI assistant to automate the process. The technique leverages tools like Claude Cowork, Google’s Gemini Spark, Meta’s Muse, or ChatGPT Dot to scan email histories for signs of account creation.
The AI prompt directs the tool to search emails from the past five years for messages such as welcome notifications, verification codes, or password-reset links. Results are compiled into a spreadsheet listing each service’s name, website, earliest and latest email dates, and whether it appears on Have I Been Pwned’s breached sites. The spreadsheet also includes links to official account-deletion pages, marking those unavailable as “not found.”
Read Also: PCWorld highlights discounted AMD and Intel mini PCs
One critical limitation is that the AI does not interact with external sites or request password resets. It performs only a passive check, confirming whether a service has been compromised—not whether the user’s specific email was exposed. This approach avoids unintended actions while verifying breach status.
Testing the prompt across four AI agents produced results within five to 30 minutes. ChatGPT Dot identified the most accounts, 73, while the others detected at least 50. Among the findings were well-known services like Facebook, Netflix, and Microsoft, alongside lesser-known ones such as a Bowers & Wilkins review account from 2022, a Hawaii Pacific Health portal from a 2023 trip, and an unexpected Dunkin’ Rewards profile.
Some accounts, like Golf Galaxy and LocalFlirt, were entirely unexpected. The latter had bypassed email filters as a spam message, yet the AI still flagged it as active. Roughly half of the services lacked clear deletion links, with many redirecting users to privacy policies instead.
The method efficiently catalogs dormant accounts but does not confirm their security. The AI’s checks only verify past breaches, not whether individual user data was compromised.
Read Also: Prime Day Offers Deep Discounts on Thunderbolt Docks
Most accounts belonged to legitimate services, though a few stood out as unusual. For instance, the journalist had no recollection of signing up for Golf Galaxy or LocalFlirt, yet both appeared in the results. The spreadsheets also noted which services had experienced breaches, though no personal data exposure was confirmed.
Deletion remains straightforward for services with clear removal links, but many either lack them or hide them in FAQs. The process combines efficiency with frustration, AI handles the initial detection, but users still face the manual cleanup.
Unexpected Accounts and Unrecognized Signups Identified
The AI-assisted search uncovered accounts the journalist had no memory of creating, including a Dunkin’ Rewards profile and a Golf Galaxy account. LocalFlirt was also flagged, despite having been mistaken for spam and bypassing email filters. The discovery suggests some signups occurred without conscious awareness, possibly through automated confirmations or unintended clicks.
