The New ID Theft: Millions of Credit Applicants Who Don’t Exist
wsj.com
wsj.com
So, the credit reporting companies cannot verify if the SSN is real or not? That sounds like the worst identity verification system.
Their customers already trust them, the trust is basically implicit, does anyone actually check what they do?
https://www.ssa.gov/employer/ssnv.htm
The root problem here is that they're using a public number which was never designed for identification purposes and has no security. The solution would be a national ID, or expansion of the US Passport with in-built security measures. Although that goes over like a lead balloon whenever it's brought up.
This is just finance industry whining that their system sucks and they want to offload the costs onto the government to manage the fraud.
EDIT: "In January, Accenture PLC listed synthetic-identity fraud as one of the biggest threats facing banks in 2018, saying it would be “costing banks billions of dollars and countless hours as they chase down people who don’t even exist.”
That pays for a lot of passports!
Disclaimer: Am in finance industry, but not credit issuance.
Although I don't think they're trying to pass the cost to the government. By calling it "identity theft" instead of what it is, fraud, they're trying to pass the cost of fraud to the consumer.
Agree with the rest of your comment.
EDIT: After coffee, I'm even more convinced this is a good idea. Better to issue the passport and have the identifier of who you don't want to travel vs not issuing it and then losing that person in the noise....because of not having a national ID card system.
A passport should be freely provided to you by your government as part of being a citizen.
I'd venture to guess that if you were making minimum wage and living in a place that was either a 700 mile drive or a $1000 airplane ticket from an international border, you might understand why it seems unnecessary. (Do you honestly believe that most non-traveling Americans are doing it because they don't have a passport?)
Less than half of the eligible population of the US votes also. That doesn't mean that it's a bad idea, just that it's not taken advantage of.
EDIT: a word.
Coming with a country that has a national ID, the US issue with it always caused me laughter. But on the other hand, identification by the state is one of the highest forms of privacy. Its pretty incredible the US has managed to be without that.
[+] https://news.ycombinator.com/item?id=16531817 | [+] http://locusmag.com/2018/03/cory-doctorow-lets-get-better-at...
Particularly when you voted against and a measure was still infringed upon you.
http://www.projectvote.org/wp-content/uploads/2015/06/AMERIC...
And not having one often puts people at a disadvantage. So it's a little fuzzier than managing to be without them.
No identifier can ever be used as method to express authorization. This is not a matter of security design.
It's up to the card issuer whether "the customer might not even exist" is a risk they are up for taking.
So they can verify it. Apparently they don’t which somehow doesn’t surprise me at all
FWIW there is a boolean "deceased" flag on credit reports (internally). I don't know by what means or how often it gets updated.
They get a lot of denormalized data. Just because an SSN:name pair presented to them isn't legit doesn't mean there isn't a real person associated with it.
There's a limit to the accuracy of credit reporting given the nature of their inputs. 123-45-6789 for Janice Smith, 123-45-6789 for Jane Smith and 123-46-6789 for Janice Deer are all the same person, but there's value in maintaining even the inconsistencies-- when an inquiry comes in at 123-46-6789 for Tran Nguyen, it's obvious something is up with one of the two parties, but without further investigation we don't know if it's a typo or fraud. Then the manual review process starts.
Entity resolution is a very complex problem to do correctly at scale. Phone numbers and addresses are shared across entities over time and can be typoed. Social security numbers can be typed incorrectly, or the name (and nowadays, gender!) associated with them changes freely. For all we know Tran and Jane are the same person; there are circumstances that have led to such oddness. Foreign passports or IDs may not match up to anything seen before, and they can't exactly hit a Romanian government API to validate numbers presented, yet they can't deny the existence of an applicant based on metrics they don't know about-- they can only share what they know.
It is creditor’s responsibility to verify the safety of their investments.
1. Unlike with ID theft, there's no consumer victim. With ID theft, eventually the victim will find out about it, (by getting a call from a collections agent or seeing the trade on their credit report). They'll then contact the lender or the bureau, and contest the validity of the loan. The end result is that the lender gets a stream of loans that are labeled as identity theft losses. Since there's no consumer victim with synthetic fraud, though, lenders don't get this stream of labeled data and have a hard time knowing which of their losses are synthetic fraud (and which are just ordinary credit losses).
2. Synthetic fraud cuts right through typical ID theft prevention systems. ID theft prevention is about checking whether the applicant is the same as the identity they're using to apply for credit. So you check if the email the applicant uses matches the identity, (e.g. don't want john.doe@gmail.com used as the email for Jane Smith), you check the phone number, you check if the applicant can complete KBA (knowledge based authentication, e.g. questions about previous addresses), you check the billing address, and so forth. But synthetic identities have their own aged phone numbers, emails, addresses, and credit histories, and so all of these verifications go through without any flags raised. Essentially the ID theft prevention system was checking whether the applicant is the same as the identity that they're using, but with synthetic fraud the applicant created the identity.
Source: my startup focuses heavily on preventing synthetic fraud for lenders, (PM me for details).
You're not solving the problem of ID Theft, you're just making it more likely that the criminals who are going to do it are going to use it are going to use ID's of real people.
Congrats and all for figuring it out how to do it, and for developing a market around it. But to me, encouraging banks to continue to make loans with just a web site or app seems like a really bad idea.
Edited to add:
Data is not a person. A person is a person.
Hit me up with the unintended downsides :-)
[1] - https://www.thebalance.com/how-to-freeze-your-credit-report-...
"Pay $10 and follow onerous procedures to unfreeze" and "receive a notification on my phone when my file is opened" are really not in the same class of interaction.
I would like to be able to alert the company that just issued fraudulent credit account in my name, directly, that they have done a bad job at KYC, to tell them they have just interacted with a person who wasn't me ASAP after the event. The best I can get right now is to check with the credit report provided by my CC issuer once a week, and hope they get the signal, and that I read it on time.
A week later on-demand is still not anything like a notification on my phone when the file is opened. If this loop is tight enough, I might even be able to call the company who has been contacted by the phony applicant and get them to stop the process before any loss occurs!
By comparison I really have no desire to freeze my credit through the agencies, if it means I'll have to go through an extra hassle and pay a fee (and fwiw to some companies I really consider to be bad actors and not trustworthy at all) every time I move, or sign up for a utility account, or open a credit card.
It's not really the job of credit reporting agencies to verify identities, and just like that it's not my job to "own" the credit file. Even though it's ostensibly my personal information, that is actually the fact in question here, and next step in the dispute resolution process is up to the credit issuer to verify the debt (which they won't be able to do properly, if they have done a poor job at KYC.)
If they were consumer focused, like say a bank, they would make it easier to control. If the credit bureaus had to pay for the fraud, they'd try to control it more intelligently, like banks. If they did that it would hurt their business somewhat, because it would make it harder for people using their services, businesses trying to sell me a car or whatever.
The banks are their customers, and I would think that market forces would drive banks to choose the CRA that will enable this workflow, but I know that market forces don't always work out the way you'd expect. Banks should be driven (by the cost of fraud) to ensure that they don't open fraudulent accounts, where CRAs probably just report on it when it happens (whether or not it is fraud.)
If none of the CRAs will do this, the banking companies don't really have a choice, other than to choose not to participate (AKA to choose to go out of business...)
Those banks are all heavily insured too, so they are probably not really incentivized to make waves in order to lower the fraud rates. This is really where my informed opinion ends, but ultimately we, the consumers, are the paying customers of the system. The debt system cannot exist without debtors.
It does seem a bit baffling that this major secondary industry springs up to service the other major industry of lenders and credit services, and then so many actors are in a position to grant or deny credit based on hidden calculations, ... but there's just no way for the consumer to come in, step up and self-identify, and become a willing participant and part of that process (so I could simply receive, and optionally deny, a request for credit to be established in my name.)
Maybe it wouldn't actually scale, or maybe it would invite fraudsters. How many businesses are going to risk losing the sale by deferring to close the deal, until after this loop has been completed? I could sign up, meet a bad actor, and coordinate attacks with them. There are probably some ways this system could go wrong. (It would certainly be expensive to find out how, and we are not their customers.)
If someone takes out a loan from Foo Bank while pretending to be me, the borrower has committed a crime and Foo Bank has foolishly let themselves be robbed. It's got nothing to do with me, and I don't want an unpaid job correcting other people's mistakes.
The right solution would be a "innocent until proven guilty" approach to debt. If Foo Bank says I owe them money that I didn't borrow, I should be able to say "nope that wasn't me" and unless they have proof otherwise, that should be the last I hear of it.
It shouldn't be my responsibility to prove I didn't borrow the money; it should be theirs to prove I did.
Put that into law, and identity theft would no longer exist. Banks could decide whether they want to actually verify identity in a way that stands up in court ("well actually here's video of you standing in our office and stating that you want to borrow this money in your own voice, reading aloud the SHA of the contract you signed and giving us your fingerprints"), or just let their money be stolen. Either way, not my problem.
Unfortunately, that appears not to be consistent with the dreary reality we find ourselves in :-(
"Don't let banks ruin people's finances via incompetence" is a good goal.
I remember there was a program for the Commodore 64 that would pull random information from a data array to create fake identities, complete with addresses and ZIP codes.
http://www.paywallnews.com/life/The-New-ID-Theft--Millions-o...