Your Old Accounts Do Not Simply Disappear
03 August 2026A total of 14 breach events were found and analysed resulting in 7,437,025 exposed accounts containing a total of 43 different data types of personal datum. The breaches found publicly and freely available included Neemans, Houston City College, SplitVPN, Homzmart and WildStar. Sign in to view the full
library of breach events which includes, where available, reference articles relating to
each breach.
Categories of Personal Data Discovered
Contact, National Identifiers, Technology, Finance, Digital Behaviour, Sociodemographic, Academic, Career, Commerce, Human Behaviour, Audio and Visual, Health and Environment, Unstructured, Geolocation.
The signal this week
The 14 breach events analysed this week contained 7,437,025 exposed accounts and 43 distinct types of personal data. The selected breaches cover active retailers, a public college, a privacy service and an online game that closed several years ago. Together, they highlight a frequently overlooked part of the data lifecycle: organisations, products and customers move on, but identity records may remain.A customer may make one purchase and never return. A student eventually leaves a college. A subscription expires. A company changes its name, and an online service may close completely. None of these events automatically removes the information created during the relationship.
For businesses, retention and decommissioning are therefore security controls, not simply administrative or storage decisions.
What the selected breaches tell us
The selected breaches represent ecommerce, education, online privacy and gaming:- Neeman’s is an Indian footwear brand selling through online and physical retail channels.
- Houston City College is a public community-college system that changed its name from Houston Community College in 2025.
- SplitVPN provides virtual private network services across mobile and desktop devices.
- Homzmart is an ecommerce platform specialising in furniture, homeware and related products.
- WildStar was a massively multiplayer online game whose official service closed in November 2018.
The BreachAware team has recorded and reviewed the provenance of this material. The descriptions shared here are intentionally limited, providing defenders with relevant context without publishing source locations, detailed contents or information that could encourage misuse.
The WildStar entry is a particularly useful illustration of the difference between an active service and data associated with its former users. Its appearance does not establish when the underlying information was first exposed or how long it was retained by the original service. It does demonstrate that account material can continue circulating after the product itself is no longer available.
Houston City College provides a different lifecycle example. A change in institutional name does not necessarily change every historic email domain, system label, archived record or reference used in an external dataset. Organisations monitoring for exposure need to recognise both current and former identities.
[Neeman’s describes its development as an Indian footwear brand founded in 2017](https://neemans.com/pages/neemans-story). [Houston City College records its 2025 name change from Houston Community College](https://www.hccs.edu/about-us/). [SplitVPN provides privacy and encrypted-network services across several device types](https://splitvpn.io/). [Homzmart operates an ecommerce platform for furniture and home goods](https://homzmart.com/en/). [WildStar’s official service closed in November 2018](https://steamcommunity.com/app/376570/announcements/).
Why inactive identities remain relevant
An inactive account is not necessarily an erased account. The associated information may remain in a production database, customer-support platform, marketing system, analytics environment, backup, exported spreadsheet or external provider. Different copies may also be subject to different retention rules and deletion processes.Keeping an inactive account indefinitely can create several problems:
- The person may no longer expect the organisation to hold the information.
- Contact details may have been reassigned or become inaccurate.
- Old passwords may still match credentials used elsewhere.
- Former domains and brands may be missing from current monitoring.
- Ownership of an archived system may be unclear.
- Security updates may no longer reach software supporting a retired product.
These are potential lifecycle issues rather than conclusions about any particular breach in this week’s summary.
The 43 distinct data types found across 14 events also demonstrate that account retirement involves more than deleting an email address. A single relationship can generate order, support, device, preference, communication and authentication records across multiple systems.
Unless the organisation maps those records, closing the visible account may leave much of the underlying data untouched.
Rebrands create a monitoring blind spot
Exposure monitoring commonly begins with a list of current company names and email domains. That list can become incomplete when an organisation rebrands, acquires another business or retires a product.Historic data may continue to use:
- A former company or product name.
- An old email domain.
- A legacy mobile application identifier.
- The name of an acquired subsidiary.
- An earlier customer portal or database label.
A match against one of these identifiers may still relate to people, systems or obligations within the current organisation.
Security teams should therefore maintain a searchable history of brands, domains, products and legal entities. This allows older exposure material to reach the correct owner instead of being dismissed as unrelated.
Three defensive checks
1.Define what happens when an account becomes inactive. Establish when access is disabled, when the record is deleted or anonymised and which information must be retained for a legitimate business purpose. Apply the process to customers, employees, students and contractors.2.
Maintain an identity history for the organisation. Record former company names, brands, products, domains and acquired entities. Include them in exposure monitoring and document which current team owns any findings.3.
Make secure decommissioning part of product closure. When a service is retired, revoke accounts and tokens, remove unused integrations, assess retained data, close unnecessary infrastructure and assign ownership for any archives or backups that remain.Perspective
The selected examples do not demonstrate that ecommerce, education, VPN providers or gaming services are being targeted more heavily than other sectors. They are not a representative sample from which to calculate an industry trend.The account total should not automatically be interpreted as 7,437,025 unique or currently active people. The material may include duplicate, historical or overlapping records. Similarly, the 43 data types describe the variety found across all 14 events and were not necessarily present in every event or account.
The inclusion of WildStar does not establish that its former operator retained information unnecessarily after the game closed. The material may pre-date the closure or have been republished later.
Likewise, Houston City College’s name change does not indicate a security issue. It illustrates why exposure monitoring must recognise historical organisational identifiers.
The useful conclusion is that data can remain relevant after the relationship, brand or product that created it has changed. A responsible retention and decommissioning process reduces that long-term exposure while ensuring any necessary records remain protected and owned.
BreachAware does not publish source locations, complete breach inventories or unnecessary operational details that could facilitate misuse.