Apple won't clear a security researcher wrongly flagged by a fake Entity List name

Earlier this year Apple denied Sean Byrne, an Irish information-security professional, access to App Store Connect, telling him his information "fully matches one or more restricted parties on the U.S. government consolidated screening list or another government's sanctions list." Apple already held his passport. He replied with his full legal name, uploaded his driver's license, pointed out that he had never lived at the Sligo address the record matched him against, and asked Apple to escalate the case to sanctions compliance for a proper non-match determination. Apple has not replied since.
Searching the Consolidated Screening List for "Sean Byrne" returns exactly one entry: an address at Cloonmull House, Drumcliffe, County Sligo, Ireland, sourced to the Commerce Department's Bureau of Industry and Security Entity List, added July 21, 2009, with a license requirement of "All items subject to the EAR" and a license policy of "Presumption of denial." That means any application for a licence to export goods to this person defaults to a denial; the listing says nothing about who can be employed or who can sell shares.
The entry traces back to the prosecution of Mac Aviation, a small Irish aircraft-parts business run by a father and son, Thomas and Sean McGuinn, out of a cottage in Drumcliffe. In 2009 the Department of Justice described Sean Byrne as Mac Aviation's commercial manager and charged him alongside the McGuinns over the illegal export of U.S. aircraft equipment to Iran. But Mac Aviation had invented staff, including "Sean Byrne," to look larger than it was, signing documents under the false name to impress suppliers. Journalist John Mooney reported in the Sunday Times that the name appeared on so much paperwork that American authorities "became convinced Byrne existed and tried to indict him." When the DOJ filed a superseding indictment in 2010, Sean Byrne was dropped as a defendant; the indictment instead describes "Sean Byrne" as an alias used by one or more co-conspirators, a phrase that appears more than fifteen times. The Entity List entry itself was never removed. Sixteen years later it still carries no date of birth, passport number or middle name, only a common Irish name and the address of Cloonmull House, which was Thomas McGuinn's home, not Byrne's.
Apple is not the first company to flag him this way. Years earlier, Nasdaq froze a stock sale during a tender offer after a background check matched his name to "Mac Aviation"; supplying his California address resolved it. More recently, DHL, shipping on behalf of SpaceX, held a Starlink mounting pole over a restricted-party match and required his passport before releasing it, and separately withheld a hat shipped from the U.S. without a passport copy. That makes four flags in six years: Nasdaq, DHL for SpaceX, DHL again, and Apple. In the first three cases, providing documentation resolved the false positive. Apple, given the same documentation, has not resolved it.
Byrne places his case alongside earlier, litigated instances of exactly this failure mode. In October 2006, 60 Minutes brought together twelve American men named Robert Johnson who all had trouble boarding flights because their name matched a known alias of a man convicted of plotting to bomb a Hindu temple and a cinema in Toronto. The FBI's Terrorist Screening Center said at the time that the name would never come off the list and that anyone sharing it would be inconvenienced indefinitely. On the consumer side, in 2005 TransUnion matched Sandra Cortez, by first and last name only, against a woman on the Treasury Department's sanctions list born 27 years after her; a jury awarded Cortez damages and the Third Circuit upheld it, calling the failure to compare birth dates reprehensible. Sergio Ramirez had a similar experience, and his case reached the Supreme Court in 2021. In both cases the courts called for comparing dates of birth and middle names. Byrne has no such recourse: the Entity List record has neither, because the person it describes does not exist.
Byrne argues the stakes are rising because a new class of hiring-screening products is being built on exactly this weakness, driven by a real problem: North Korean IT workers obtaining remote U.S. jobs through stolen or fabricated identities and U.S.-based "laptop farms," a scheme the DOJ has prosecuted after it placed workers at more than 100 U.S. companies. Vendors such as Tofu, which says it screens applicants across more than forty signals before a recruiter opens a résumé and propagates any sanctions match across its entire customer network via its API, argue that screening at the background-check stage is already too late and should happen at application submission instead. Tofu's homepage claims its database is built from more than 18 million analysed applicant profiles, while most of its other pages cite more than 5 million. Brainner makes a similar pitch, checking applicants against 3.5 billion data points. Byrne notes the list these vendors screen against is OFAC's Specially Designated Nationals list, the correct one for their stated risk, not the Entity List he keeps being matched to, and that he has no evidence either vendor queries the Entity List or that any employer he applied to uses either product.
His conclusion is that these tools are built to catch false negatives, a fraudster passing an SDN check cleanly on a stolen identity, but nothing in their design accounts for the opposite failure: a real applicant matching a listing for a person who was invented. Mac Aviation fabricated an employee to look like a bigger company; that fabricated employee ended up in an authoritative U.S. government database; sixteen years later, an industry is being built to catch fabricated employees applying for jobs. Byrne, now applying for security roles from Ireland after a career largely spent in the U.S., says he does not know whether the misidentification has cost him a job, since unexplained hiring rejections are common regardless. But given four confirmed flags in six years, he argues that contesting each company's screening result individually is the wrong approach.
Key facts
- Apple denied Sean Byrne, an Irish security professional, App Store Connect access, saying his information "fully matches" a US Consolidated Screening List entry, and has not replied since despite receiving his passport, driver's license and an explanation.
- The matched Entity List entry, added July 21, 2009 with a "presumption of denial" license policy, traces to Mac Aviation, an Irish firm whose owners invented a "Sean Byrne" employee to sign paperwork while illegally exporting US aircraft parts to Iran; a 2010 superseding indictment calls "Sean Byrne" an alias used by co-conspirators more than fifteen times and dropped him as a defendant, but the Entity List entry, which still has no date of birth or passport number, was never removed.
- This is the fourth flag in six years: Nasdaq froze a stock sale and DHL, shipping for SpaceX, twice demanded his passport over a mounting pole and a hat; unlike those three cases, Apple has not resolved the match despite identical documentation.
- Byrne compares his case to 60 Minutes' 2006 report on twelve men named Robert Johnson delayed at airports, and to TransUnion misidentification cases (Sandra Cortez in 2005, Sergio Ramirez, reaching the Supreme Court in 2021) where courts ordered comparing birth dates, a fix unavailable here since the Entity List record has no such details.
- He warns that ATS-embedded screening vendors, Tofu (more than forty signals, claiming 18 million or 5 million analysed profiles depending on the page) and Brainner (3.5 billion data points), built partly to catch North Korean workers using stolen identities at more than 100 US companies, push sanctions screening earlier and across shared customer networks with no apparent safeguard against flagging a real applicant against a fabricated one.
Why it matters
The piece documents a specific, verifiable failure mode in government-adjacent screening: a name invented to pad a small company's headcount during an export-fraud case became a permanent, unfixable entry on an authoritative U.S. list, one with no birth date, passport number or middle name to disambiguate it from a real person who happens to share the name. Because the entry cannot be corrected against a person who does not exist, anyone named Sean Byrne from Ireland is exposed to it indefinitely, and the essay shows that exposure recurring across four unrelated companies over six years.
Who it affects
Directly, Sean Byrne, and by extension anyone whose name coincides with an Entity List, SDN, or similar restricted-party entry that carries thin identifying detail. More broadly, it affects remote job applicants being screened by ATS-embedded vendors before a recruiter ever sees them, and any company, from Apple to shipping carriers to financial platforms, that runs restricted-party name matching as part of onboarding or compliance.
How to use it
For someone hit by a similar false positive, the essay's throughline is to demand a documented non-match determination rather than accept an unresolved denial, and to note that the applicable list matters: an Entity List export-control hit is a different legal instrument from an OFAC SDN hit, and companies conflating the two, as Apple's boilerplate response does, are applying the wrong standard. For companies deploying or buying name-screening products, the takeaway is that matching on name and country alone, without birth date or other identifiers, is the exact defect courts have already penalized in the TransUnion cases.
How solid is it
The account is a first-person essay, but its central claims are checkable against public record: the Consolidated Screening List entry itself, the Bureau of Industry and Security's Entity List sourcing, the 2010 superseding indictment language describing "Sean Byrne" as an alias, and John Mooney's Sunday Times reporting on the case. The cited precedents, the 2006 60 Minutes segment on the Robert Johnson name and the Cortez and Ramirez TransUnion litigation through the Third Circuit and Supreme Court, are independently documented cases, not the author's own claims. The interactions with Nasdaq, DHL and Apple rest on the author's own correspondence and are not independently verifiable from the text alone.
Risks and caveats
The author is explicit that he has no evidence Tofu or Brainner query the Entity List specifically, and no knowledge of whether any employer he applied to uses either product; the connection between the screening industry he describes and his own job search is his inference, not a documented fact. He also states plainly that he does not know whether the misidentification has cost him a job, since hiring rejections are frequently unexplained for unrelated reasons. The piece should be read as a documented pattern of false positives plus a warning about where the industry is headed, not as proof of a specific hiring loss.
“The information you provided fully matches one or more restricted parties on the U.S. government consolidated screening list or another government's sanctions list.”
— Apple, in its response to Sean Byrne