Anyone who has used the internet for a while has left a long trail behind them: accounts created for a single purchase, a trial, a forum, an app tried once, a service that seemed useful and was then forgotten. Each of these sign-ups created an account that, in almost every case, still exists - holding whatever personal details were given at the time, protected by whatever password was set, and sitting unused and unwatched on a service the person has not thought about in years. This accumulation feels harmless, because a forgotten account is doing nothing. But a dormant account is not gone; it is just unattended, and unattended is precisely the problem.
Every one of those old accounts is a small store of personal information and a set of login credentials somewhere out on the internet, and it adds to what security people call a person's attack surface - the total number of places where something could go wrong. If one of those forgotten services suffers a data breach, the details held in your dormant account are exposed along with everyone else's, and because you no longer watch that account, you will likely never know. That matters most when the old password was reused elsewhere: a password from a long-abandoned account, leaked in that service's breach, becomes a key that criminals try against your other, still-important accounts, and a forgotten account is the one you are least likely to have given a unique password.
The quiet danger, then, is not that a dormant account does something, but that it sits there as an unmonitored liability: holding data that can leak, guarded by a password that may unlock other things, on a service whose security you have no visibility into and whose breach notices you may not even receive any more. The more such accounts accumulate, the more scattered pieces of a person's identity and credentials lie around in places they have stopped paying attention to. None of it is visible in day-to-day life, which is exactly why it grows unchecked.
The remedy is unglamorous housekeeping that pays off out of proportion to the effort. Periodically, it is worth taking stock of the online accounts you have accumulated and actively closing the ones you no longer use - properly deleting the account where the service allows it, rather than just abandoning it again, so the data it holds is removed and the login can no longer be used against you. For accounts you want to keep but rarely touch, making sure each has its own unique password contains the damage if that service is ever breached. Reducing the number of forgotten doors, and making sure the ones that remain each have a different lock, shrinks the quiet, invisible risk that a service you last thought about years ago is the one that eventually causes you trouble.