SSNs and My Number: The Benefits and Risks of Personal Identifiers

暗いレンガ壁の前でフードをかぶり、顔を隠した人物

The first article in this series examined why security planning must extend beyond preventing data breaches to include fraud detection and recovery.

This second article looks at the U.S. Social Security number and Japan’s My Number system. The two systems have different purposes, legal frameworks, and rules governing their use, so they should not be treated as direct equivalents. Nevertheless, the United States’ long experience with the SSN offers lessons for any society building a common digital identity infrastructure.

The SSN began as a way to track earnings

The Social Security number was introduced in 1936 to track workers’ earnings, determine eligibility for Social Security benefits, and calculate benefit amounts.

Its original purpose was limited. Over time, however, government agencies and private organizations began using it as a convenient way to identify individuals across records. It became closely connected to employment, taxation, financial services, and credit reporting.

The SSN has nine digits. Historically, the first three digits had a geographic relationship, but the Social Security Administration changed the assignment process in 2011. New numbers are now randomized, and the first three digits no longer indicate a particular location.

The Social Security card remains a paper card. It is not a smart card and does not provide strong authentication.

An early U.S. Social Security card displaying the holder’s name and nine-digit Social Security number.
The Social Security card remains a paper document. The number, rather than the card, has become a widely used identifier.

Identification is not authentication

The most important distinction is between identifying a record and proving that a person is entitled to access it.

An SSN is useful for determining which individual a record belongs to. Knowing the number, however, should not prove that someone is that individual.

For many years, the SSN was sometimes treated as if it were a secret. Organizations asked for it not only to locate a record but also to verify identity. Once the number was exposed, another person could potentially use it to apply for financial products or impersonate the legitimate holder.

A permanent identifier is fundamentally different from a password. It is difficult to change and is often shared with multiple organizations for legitimate purposes. Designing a system around the assumption that the identifier will remain secret creates long-term risk.

Why children’s SSNs can be attractive targets

Many children in the United States are assigned an SSN shortly after birth, long before they need it for employment, taxation, or credit.

If a child’s number is misused, the family may not notice immediately. The problem may surface years later, when the child applies for a credit card, apartment, student loan, or other financial service.

The U.S. Federal Trade Commission advises parents to ask why a child’s SSN is needed before providing it, store documents securely, watch for warning signs, and consider freezing the child’s credit to make it harder for someone to open new accounts in the child’s name.

The problem is not the existence of the number itself. The important questions are whether organizations separate identification from authentication, whether the legitimate holder can review how the identity is being used, and whether suspicious activity can be detected early.

My Number and the My Number Card are different

Discussions in Japan often treat My Number and the My Number Card as if they were the same thing. They are not.

My Number is a 12-digit personal number assigned to each person listed in Japan’s Basic Resident Register. Its use is restricted by law, primarily to procedures involving social security, taxation, and disaster response. A private company cannot freely adopt it as a general customer identifier.

The My Number Card is a physical identification document with a photograph and an IC chip. It can also contain digital certificates used for online government procedures, electronic signatures, and identity verification for supported private-sector services.

At least three components should therefore be distinguished:

  • My Number as a personal identifier
  • The My Number Card as a photo identification document
  • The digital certificates used for online authentication and electronic signatures

This distinction is important when comparing the Japanese system with the SSN. The SSN is primarily a number that became widely used as an identifier. Japan’s system combines a legally restricted number with a physical card and a separate digital certificate infrastructure.

Convenience increases the importance of recovery

A common identity infrastructure can reduce duplicate administrative procedures and make it easier to connect the correct records across organizations.

However, reliance on a single number, card, or device also increases the impact of loss, theft, data exposure, or system failure.

A complete identity system must address more than convenience during normal use. It should also answer several operational questions:

  • Can someone be treated as the account holder simply because they know the identifier?
  • Can individuals review suspicious use of their identity?
  • Can a lost card or compromised credential be suspended quickly?
  • Is there an alternative when the primary authentication method is unavailable?
  • Is there an audit trail showing who accessed which information and for what purpose?
  • Can access be restored without weakening security?

These questions apply not only to government identity systems but also to companies that connect customer information across multiple services.

What companies can learn from the SSN

Businesses routinely use email addresses, phone numbers, account numbers, and customer IDs to connect data across internal systems.

Those identifiers are necessary for managing records. They should not, however, be treated as sufficient proof of identity.

If a customer can authorize a sensitive transaction by providing only an account number, date of birth, address, or other information that may have been exposed elsewhere, a data breach can become a direct path to impersonation.

Higher-risk activities require separate authentication methods appropriate to the transaction. Depending on the context, these may include passkeys, digital certificates, trusted devices, multi-factor authentication, or in-person verification.

Identifiers should not be treated as authenticators

The lesson from the SSN is not that societies should avoid common identifiers. The lesson is that an identifier should not be treated as a secret authenticator.

Japan’s My Number system and broader digital identity infrastructure can improve access to public and private services. To realize that value safely, organizations must design identification, authentication, authorization, monitoring, and recovery as separate functions.

A number can tell a system which person’s record to find. It should not, by itself, prove that the person requesting access is entitled to use it.


Shinya Fujimoto | Founder / Chief Strategist, Silicon Valley Japan Lab

Based in the United States for more than 25 years, Shinya draws on his experience as both an engineer and a business leader to examine how Silicon Valley technology trends can be applied to management and business development in Japanese companies.