Let\u2019s face it. The credit bureau data used by financial services organizations for identity verification and risk assessments is also in the hands of fraudsters. It\u2019s been stolen. So how do we protect businesses and consumers against the effects of fraud that leverages compromised personally identifiable information (PII)?From a financial standpoint, stolen PII is generally used one of two ways: to access an existing online account or to open a new account online. Accessing an existing account is generally more difficult even if the victim\u2019s username and password has been compromised. This is primarily due to the layered protections most financial institutions have in place. For example, biometric authentication technologies are being used in place of older technologies like device intelligence and rules-based anomaly detection, which are becoming less effective.\u00a0Stolen data and new account fraudFor cybercriminals, the most expedient use of stolen PII is for opening new accounts online. Since the organization being targeted has never done business with the victim being spoofed, these attacks pose several unique challenges.First, the personal information requested in most online applications is exactly the same as what credit bureaus then use to validate the application. Recently, Equifax reported that another 2.4 million Americans were impacted by that enormous data breach, bringing the total number of affected American businesses and consumers to 145.5 million. Meanwhile, according to the Privacy Rights Clearinghouse, more than 4,500 data breaches have been made public since 2005, with more than 816 million individual records breached. This doesn\u2019t include the breaches that have not been reported.Second, a large swath of the millennial, generation Z, and recent immigrant populations do not have sufficient financial and credit history to be verified, leading to erroneous denials. For example, millennials own 22% fewer credit cards than Gen Xers did at the same age (21-34), according to a TransUnion survey. In addition, a Fed survey found that 18- to 24-year-olds prefer to pay cash more than other age groups. Meanwhile, if they do have a credit card, millennials prefer prepaid or debit cards, according to TD Bank. New account applications using stolen, but known, PII are more likely to slip past fraud filters than \u201cthin file\u201d applicants, even if they are qualified.Third, advanced authentication technologies, while highly accurate, do not work for new clients whose identity has not been verified by the company. It\u2019s a chicken and egg problem. To protect a new account using biometrics, the applicant\u2019s identity must first be verified. If stolen PII is used (and accepted) to open a new account online, then advanced authentication tools only serve to provide another layer of validation for fraudulent accounts.\u00a0Credit bureau data in is the crosshairsAs mentioned earlier, most businesses rely on the three largest credit bureaus \u2013 TransUnion, Experian and Equifax \u2013 for verifying online identities. This complicates matters, since most of the information housed by these companies has already been compromised in innumerable data breaches over the past few years. In fact, virtually every type of business, government agency, or educational institution has been affected. Since many breaches have gone unreported or even undetected, the problem is much greater than the estimates.While we want to believe that the personal information contained in the credit bureaus\u2019 databases is safe and secure, much of it is openly available in online black markets.The government has taken notice. Proposed government legislation is in the works to make companies accountable if they expose consumers\u2019 data to hackers. The bills are focusing on what happens after the data is stolen, not prevention. Nevertheless, it\u2019s a step in the right direction.Digital footprints harder to spoofWhat has become apparent, however, is the approach of using centralized, static \u2013 and largely compromised \u2013 credit bureau data for identity verification has outlived its useful life.A more dynamic approach, based on a wider range of data including online, offline and social sources that are difficult to steal and replicate, is needed such as email, phone number, IP address, etc., provided by the applicant.The technology to do this is available. In fact, many financial services organizations are using artificial intelligence and machine learning techniques to detect fraud after an account is opened. These same techniques can be applied to mine a wider set of data sources than static credit bureau databases, to verify an applicant\u2019s identity when they apply to open a new account.Supplementing traditional information sources with digital footprint data provides more accurate and reliable digital identity verification. Reducing our reliance on \u201cStolen PII\u201d can not only reduce account opening fraud, but also boost acceptance rates for so-called \u201cthin file\u201d applicants with little or no credit history, like millennials.Bringing identity verification into the digital age is long overdue. It\u2019s good for corporate profitability, good for consumers and ultimately, good for the economy.