Tech

Irish developer denied App Store access after false match with fictitious US sanctions entry

Apple, Nasdaq and DHL have all triggered false positives against Byrne, highlighting risks in automated compliance tools when government data contains non-existent entities.

Editorial persona
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: Hacker News · View original source
Tech
No image available
Sean Byrne’s identity flagged by automated screening systems linked to a 2009 indictment alias

Sean Byrne, an Irish information security professional, has been denied access to Apple’s App Store Connect after the company’s automated screening systems matched his identity to a US government restricted-party list entry. The match refers to a non-existent individual, also named Sean Byrne, who was a fabricated employee of the Irish aircraft-parts company Mac Aviation.

The fictitious name appeared in a 2009 US Department of Justice indictment regarding illegal exports to Iran. It was later removed from the defendants list in a superseding indictment as an alias used by co-conspirators, yet the entry remains on the US Bureau of Industry and Security Entity List. The record lacks personal identifiers such as a date of birth or passport number, containing only the common name and an address in County Sligo.

Byrne has experienced repeated false positives from major entities over the past six years. Nasdaq halted a stock tender offer after a background check matched his name, while DHL, shipping on behalf of SpaceX, requested his passport before releasing orders. In both instances, providing additional documentation resolved the issue. Apple, however, maintained the match after reviewing Byrne’s driver’s license and explanation, refusing to escalate the matter to a proper non-match determination.

The incident underscores broader concerns regarding remote-hiring fraud and the proliferation of automated screening tools. With the rise of identity fraud involving remote workers, new recruiting products such as Tofu and Brainner are being deployed to screen applicants early in the process. These systems run checks across applicant tracking systems before human review, potentially exacerbating false positives for individuals with common names matched against flawed government data.

Byrne has submitted an appeal to the Bureau of Industry and Security’s End-User Review Committee to review the original Entity List entry. He notes that the listing persists sixteen years after the original prosecution, creating a scenario where automated systems flag legitimate applicants against records of invented persons. The normal removal process is designed for listed individuals, complicating efforts to correct data for entities that never existed.

Continue reading

More from Tech

Read next: EuroBirdPortal maps bird movements across Europe
Read next: WIRED names Bose earbuds its top pick for noise cancellation in 2026 guide
Read next: Three University of Florida students charged over alleged cyber-harassment of Maddie Kowalski