How to Find and Delete Files Owned by a Specific User in Ubuntu (find -delete)

The Offboarding Deletion Protocol

When permanently removing a compromised user account (or a terminated employee) from an Ubuntu Linux server, simply executing userdel is often insufficient. If that user operated outside their home directory, they may have left hundreds of orphaned files scattered across /tmp/, /var/www/, or shared project drives. Leaving these files behind poses a massive security risk, as the numerical UID associated with those files might eventually be reassigned to a new user, accidentally granting them access to the old data. You must execute a complete, server-wide search-and-destroy mission targeting their exact ownership footprint.

Using the find Command with -user and -delete

The Linux find command allows you to chain the ownership filter (-user) directly to the highly destructive -delete flag to permanently purge a specific user’s files.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To scan the entire /var/ directory and permanently delete every single file owned by the user old_admin, type the following command exactly:
  3. sudo find /var/ -type f -user old_admin -delete
  4. Press Enter.

Execution Order and Devastation

The syntax order is an absolute operational requirement. The engine first applies -type f to ensure it is only looking at files (not critical structural directories). It then applies -user old_admin to build the target list. Finally, it executes -delete. If you reverse this order, the command will instantly begin deleting everything it touches before checking who owns it. This compound command is a mandatory tool for system administrators ensuring absolute data sanitation during a hostile account offboarding process.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.