The Employee Who Already Left Still Has Your Password

Caiber August 12, 2026

Here's an uncomfortable one. In a recent industry survey, 83% of former employees admitted they still had access to at least one account from a previous job after they left. More than half of them said they'd used that access specifically to do something that would hurt their old employer.

Sit with that for a second. This isn't a hacker in another country running a phishing campaign. This is someone whose badge you already took back, whose laptop you already collected, who still has a login that nobody remembered to kill.

Offboarding is where PAM quietly falls apart

Most companies are decent at onboarding. New hire starts Monday, accounts are ready, everyone's happy. Offboarding doesn't get the same care. It's a Friday afternoon task squeezed between meetings, and it usually means deactivating the obvious stuff — email, Slack, the badge. Service accounts, shared logins, that one admin panel three people know about but nobody documented? Those slip through.

We've seen this pattern enough times to know it's not a people problem. It's a visibility problem. You can't revoke access you don't know exists.

The fix isn't more paperwork, it's fewer standing accounts

The organizations that handle this well aren't the ones with the longest offboarding checklist. They're the ones where privileged access was never "standing" in the first place — access is granted for a task, expires on its own, and gets reviewed regularly instead of assumed to be fine. When access naturally expires, a departing employee walking out the door with lingering credentials stops being a possibility.

If you're not sure what access is currently active across your organization — including the accounts nobody's thought about in months — that's usually the very first thing worth finding out.