Built Wrong

Richard Bird has spent decades inside the cybersecurity industry and has questions about the results. A seven-time C-level executive, author and speaker, he writes about security, AI, identity, privacy and the uncomfortable gap between what the cybersecurity ecosystem promises and what actually happens. Built Wrong is where he works through what we got wrong, why it matters, and what we should build instead.

Sep 30 • 4 min read

The "Remedy" Nobody Measures Part 2: The Crime Moved


The "Remedy" Nobody Measures - Part 2

The real fraud grows inside a file built around someone who does not exist.


The crime moved

There is a common belief that new-account fraud is too much work: one identity, one application, one payday at a time, when ransomware offers a single wholesale demand.

That instinct is deeply mistaken, for two reasons.

The first is the division of labor. The crew that steals the data rarely does the retail work. When a ransomware victim refuses to pay, some groups sell or auction the stolen data to other criminals.¹³ The extortionist takes the wholesale payday, and the records become inventory for a separate fraud business, where the Federal Reserve’s 2019 white paper lists a Social Security number value at about $1.¹⁴

The second is industrialization. Synthetic identity fraud pairs a real Social Security number with an invented name and date of birth, builds a credit history for a person who does not exist, and then cashes out. The Federal Reserve documented a single ring that built more than 7,000 synthetic identities and obtained more than 25,000 credit cards, stealing more than $200 million.¹⁵

The Federal Reserve Bank of Boston put total losses at an estimated $20 billion in 2020 and noted that children are targeted because the theft can go undetected for years.¹⁶ TransUnion puts U.S. lender exposure to suspected synthetic identities at $3.3 billion at the end of 2024, a figure worth reading with the knowledge that TransUnion sells the detection.¹⁷ An industry estimate cited by the Fed holds that 85 to 95 percent of applicants identified as likely synthetic identities are not flagged by traditional fraud models.¹⁸

Now follow the mechanism.

The Fed explains that when a fraudster applies for credit with a synthetic identity, the credit bureau creates a new credit file for that identity, even if the lender rejects the application.¹⁹ The real fraud grows inside a file built around someone who is an actual fiction.

Monitoring the real person’s file is a poor tripwire for a crime designed to live somewhere else, represented by someone who doesn’t even exist. And to be fair to the argument, the GAO notes that a freeze does not stop synthetic identity fraud either.²⁰

The monitoring product watches the front door of a house that the burglar isn’t even interested in entering. He’s got more money to make elsewhere.

The key that is also the lock

Why does a nine-digit number enable any of this? Because the American credit system asks the SSN to do two incompatible jobs.

It is the identifier.

The Fed’s white paper traces how a number created in 1936 solely to track earnings became the near-universal identifier across private industry and government, and lists that near-universal use among the factors driving synthetic fraud.²¹

It is also the verifier.

Credit bureaus and lenders generally presume that the first person to establish credit under a given SSN is its rightful holder. When the real holder shows up later, the burden is on them to prove who they are.²²

Knowing the number and using it first stands in as proof of existence. For the non-existent.

An identifier has to be shared to work. A verifier stops working the moment it is shared.

After two decades of breaches, the SSN is thoroughly shared, and the system still treats it as if both of these are still reliable and bankable credentials. TransUnion's and the Federal Reserve's billions of dollars of economic losses per year clearly show that they shouldn't be.

In 2018, Congress responded to synthetic identity fraud by ordering the Social Security Administration to build eCBSV, a fee-based service that lets financial institutions check whether a name, SSN, and date of birth match SSA’s records.²³ SSA’s own materials state that eCBSV “does not verify an individual’s identity.”²⁴

Congress answered SSN-driven fraud with federal infrastructure to confirm that the SSN matches. That was the same law that made credit bureau freezes free.²⁵

The bureaus sit at the center of this design. Their files lean on the number, their fraud products are sold against their failure, and their breach-response business is paid every time it fails again.


Notes

[13] DarkOwl, “What are Ransomware Leak Sites?,” undated web page (vendor publication), accessed September 2026. https://www.darkowl.com/blog-content/what-are-ransomware-leak-sites/​

[14] Federal Reserve System, Synthetic Identity Fraud in the U.S. Payment System: A Review of Causes and Contributing Factors, Payments Fraud Insights, July 2019, pp. 2–17. The 85 to 95 percent figure is an ID Analytics estimate cited in the paper; the $1 SSN price is an Experian estimate cited in the paper. https://fedpaymentsimprovement.org/wp-content/uploads/frs-synthetic-identity-payments-fraud-white-paper-july-2019.pdf​

[15] Federal Reserve System, Synthetic Identity Fraud in the U.S. Payment System.

[16] Federal Reserve Bank of Boston, “Synthetic identity fraud is not a victimless crime,” August 2022. https://www.bostonfed.org/news-and-events/news/2022/08/synthetic-identity-fraud-is-not-a-victimless-crime-costs-billions-damages-lives.aspx​

[17] TransUnion, “TransUnion Research Highlights Power of Public Data in Uncovering $3.3B Synthetic Identity Threat,” press release, September 2025. https://newsroom.transunion.com/transunion-research-highlights-power-of-public-data-in-uncovering-33b-synthetic-identity-threat/​

[18] Federal Reserve System, Synthetic Identity Fraud in the U.S. Payment System.

[19] Federal Reserve System, Synthetic Identity Fraud in the U.S. Payment System.

[20] GAO, Data Breaches.

[21] Federal Reserve System, Synthetic Identity Fraud in the U.S. Payment System.

[22] Federal Reserve System, Synthetic Identity Fraud in the U.S. Payment System.

[23] Social Security Administration, “eCBSV Home,” Data Exchange. https://www.ssa.gov/dataexchange/eCBSV/​

[24] Social Security Administration, “Electronic Consent Based Social Security Number Verification,” public meeting talking points, May 2020. https://www.ssa.gov/dataexchange/eCBSV/documents/eCBSV%20Public%20Meeting%20Talking%20Points%20Final.pdf​

[25] Federal Trade Commission, “Economic Growth, Regulatory Relief, and Consumer Protection Act,” statute summary (Pub. L. No. 115-174, Title III and § 215). https://www.ftc.gov/legal-library/browse/statutes/economic-growth-regulatory-relief-consumer-protection-act​


Richard Bird has spent decades inside the cybersecurity industry and has questions about the results. A seven-time C-level executive, author and speaker, he writes about security, AI, identity, privacy and the uncomfortable gap between what the cybersecurity ecosystem promises and what actually happens. Built Wrong is where he works through what we got wrong, why it matters, and what we should build instead.


Read next ...