A few notes of interesting things I’ve found:
Observing inbound mail for over a year is by far the best way to learn where a person has accounts. I found a ton of services that weren’t listed in the password file by seeing “year end summary” or “we’ve updated our terms” emails. And then of course email access is useful to reset the password and get in.
No one sends more fucking email than politicians. It’s honestly insane how many emails came in daily to this account from all sorts of a candidates, from all over the country. The email list sharing is blatant and rampant. And without regular pruning (unsubscribing, marking as spam), the volume just grows and grows.
Some companies have very handy “close and delete this account” features. Some let you end a paid subscription, but there’s no way to remove the account. In one case I killed a subscription to a paper and then was able to log in as the deceased 4 years later! But many services do prune: in many cases, trying to log in years later failed.
When there was not a “delete account” feature, I filed a support request to delete, explaining that the account holder had passed away. When that did not work I filed a legal request to delete personal data, citing the data privacy law of the state in which the deceased resided. That worked well.
I ended up paying to keep the deceased’s phone number active for a while because I kept finding accounts that were set to send SMS codes to permit login. The deceased was good about security, which ended up costing me, ha. Notably, the mobile provider never cut off the number or seemed to notice that a dead person’s phone was still active. As long as the bill gets paid, they don’t look too closely I guess.