Getting rid of accounts that can be used to attack you and that you'd forgotten that you had.
They want to close accounts with poor security (i.e. no 2FA enabled). These accounts has a higher risk of being compromised and used to get access to whatever they control
yeah, correct. although no one will be able to find (at least easily) that which account or accounts were closed.
Saving space and removing hassle of managing data that is not being used (and likely will never be used)? I think 18 months is way too little but I think the decision is valid