New spying threats force rethink of biometric identity checks The Five Eyes intelligence alliance’s warning this month that Chinese intelligence services are using fake recruiters on LinkedIn and other job platforms to cultivate people with access to sensitive information is a reminder that the most consequential security failures often begin before a system ever performs a check. Made up of Australian, Canadian, New Zealand, UK, and U.S. intelligence agencies, their joint bulletin, Safeguarding Our Secrets, describes how Chinese intelligence officers or their affiliates pose as recruiters, consultants, and representatives of credible-appearing companies to identify people with access to government, military, economic, or policy information. Publicly available information can also be coupled to the de-anonymization of information obtained through data brokers. De-anonymization occurs when data that has been stripped of direct identifiers, such as names or email addresses, is combined with other datasets to re-identify individuals. All of which is designed to turn a real person into an insider. A job offer provides the opening. A remote interview creates rapport, and the request for something like a trial analytical report tests the target’s willingness to provide information. The demands then become more sensitive. But the episode also illustrates a wider problem emerging across digital identity systems. Security may be built around sophisticated facial recognition, document authentication, and biometric matching, yet these tools can do only so much when the person, the credential, or the digital stream reaching the system has already been manipulated. A biometric scanner can compare a face with a stored image, determine whether a fingerprint resembles a template on file, and can confirm that the person in front of a camera resembles the person associated with a passport or account, but what it cannot automatically establish is whether the identity entered into the system was genuine at the