Lisa Riley applied for a US Esta through what appeared to be a legitimate website found via Google search. The site was a near-perfect replica of the official US Customs and Border Protection portal, complete with convincing domain names and professional design. She entered her passport details, bank information, and personal data, paid £16, and waited. The confirmation never came. The initial financial loss was trivial. The structural damage was not. In the 17 months since, Riley has received scam calls at least once a week — sometimes twice — plus even more frequent text messages. The callers impersonate her bank, reference plausible-sounding money transfers, and leverage the exact personal details she unwittingly handed over. The original fraud was not the product — it was the supply chain. Nationwide building society research puts the scale of the problem at 15% of the UK population having given personal information to someone who turned out to be fraudulent. That is roughly one in seven adults walking around with their identity details circulating in criminal marketplaces, each entry a permanent lead for future social engineering attacks. The data does not expire. The mechanics are straightforward and industrialized. Criminals build replica government websites using AI, bid on search keywords like "Esta" to appear high in Google results, and harvest credentials at scale. The stolen data is then either used directly for bank impersonation campaigns or sold to other fraud networks. Each victim becomes a recurring revenue source, contacted repeatedly across months and years. US Customs and Border Protection acknowledges the problem but offers only defensive guidance: use only the official .gov site or mobile app, protect your Esta confirmation number, review financial statements. In the UK, victims are directed to their bank and the Report Fraud service. None of this addresses the upstream failure — that Google's ad and search systems consistently surface fraudulent sites above or alongside legitimate government portals. The countermeasures available to individuals are reactive by design. Once your data is in the pipeline, there is no recall mechanism. Nationwide's advice — don't feel pressured, verify callers independently, never move money on instruction — is sound but places the entire burden of defense on the person whose information was already stolen. The structural incentives remain: building fake sites is cheap, harvesting data is profitable, and the resale market for verified personal details is liquid. This is not a story about one actor losing £16. It is a story about a permanently extractive data pipeline where a single moment of misplaced trust converts a person into an indefinite target. The fraud economy has moved from one-off theft to subscription-model exploitation, and neither platforms nor regulators have matched the shift.