A 41-year-old man was found dead in a Missouri field in 1999. Two notes in his pockets were written in a code the FBI has never broken. His family says he could barely read. Here is what we know.
A 41-year-old man was found dead in a Missouri cornfield on June 30, 1999. He had been murdered. In his pockets were two handwritten notes filled with a jumble of letters, numbers, and parentheses. The FBI's Cryptanalysis and Racketeering Records Unit (CRRU), which reportedly solves 99 percent of the ciphers it receives, could not break them. In 2011, the FBI published the notes and asked the public for help. Nobody has solved them.
Ricky McCormick's family said he had used his own coded writing since boyhood and that no one had ever been able to read it. His mother said he "didn't write in no code." The FBI believes he did. Dan Olson, chief of the CRRU, stated: "We look at a lot of things that are gibberish, arbitrary strikes on a keyboard. This is not that case."
The McCormick notes are a leading example of what cryptanalysts call an idiolectic cipher: a system invented and used by a single person, where the key is not a string but a lifetime of personal associations. You can try analyzing the notes yourself with our Cipher Identifier and Cryptogram Solver.
On June 30, 1999, sheriff's officers in St. Charles County, Missouri, discovered the partially decomposed body of Ricky McCormick in a field. He had been murdered and dumped. The cause of death was not publicly released in detail, but investigators determined he had been killed elsewhere and transported to the field.
The only clues were two notes found in his pants pockets. The notes contain approximately 30 lines of mixed letters and numbers, organized into apparent paragraphs with parenthetical asides. The text includes letter clusters like "WLDNCBE," "PRSEON," "MR DE LUSE," and "XL," interspersed with number groups like 71, 74, 75, 194, 26, 35, 651, and 99.84.52.
McCormick was developmentally disabled, had limited literacy, and had spent time in prison. He worked intermittently and traveled around downtown St. Louis on buses. The FBI's CRRU, the same unit that worked the Unabomber and Zodiac materials, spent over a decade analyzing the notes. They concluded the notes are "almost certainly genuine cipher" rather than random scribbling, based on statistical analysis showing repeated bigrams, periodic capitalization, and paragraph breaks.
In March 2011, the FBI published the notes on its website and asked the public for help. The response was overwhelming. The FBI received so many submissions that they had to ask people to stop calling and emailing, and they set up a dedicated page for public theories. None of the submissions produced a solution.
The McCormick notes do not match any known cipher system. The FBI tested standard ciphers including Vigenere, Playfair, Hill, columnar transposition, and Polybius square variants. None fit.
The statistical properties are unusual. The notes show real linguistic structure: repeated bigrams, consistent capitalization patterns, and paragraph organization. But the structure does not match any known language or cipher. The repeated sequence "WLDNCBE" appears eight times across the two notes, sometimes with an apostrophe as "WLD'S NCBE." The sequence "NCBE" frequently appears preceded by a number. The word-like structure suggests a real encoding system, but the system is entirely private.
Nick Pelling, a cipher historian who studied the notes extensively, published his analysis in 2024. He observed that the notes contain short number groups that could be references to places in and around St. Louis, rendered in McCormick's idiosyncratic and possibly dyslexic style. Pelling noted that McCormick's life was centered on downtown St. Louis, where he grew up, worked, and traveled on buses. The notes may be a personal shorthand for locations, addresses, and people in that area.
The leading hypothesis, as described by the Cipher Museum, is that the notes are an idiolectic cipher: a system invented and used by a single person, where the "key" is not a mathematical value but a lifetime of personal associations. From the cryptanalyst's perspective, such a cipher is functionally equivalent to a one-time pad. Even with all the ciphertext in the world, recovering the plaintext requires recovering the author's mental model.
The FBI's CRRU follows a four-step process for cipher analysis, described by Dan Olson in the FBI's public appeal:
1. Determine the language: Identify what language the plaintext is in. For McCormick's notes, the characters are from the English alphabet, suggesting English plaintext.
2. Determine the system: Identify the cipher type. Is it a substitution cipher (letters replaced by other letters), a transposition cipher (letters rearranged), or something else? The FBI could not get past this step for McCormick's notes. The system does not match any known cipher classification.
3. Reconstruct the key: Once the system is identified, determine the specific key used. For a Caesar cipher, this is the shift value. For a Vigenere cipher, this is the keyword. For McCormick's notes, this step is unreachable without solving step 2.
4. Reconstruct the plaintext: Apply the key to the ciphertext to produce the plaintext.
The FBI's failure at step 2 is what makes the McCormick case unique. Most ciphers the CRRU receives can be classified into a known system within hours. McCormick's notes have resisted classification for over 25 years.
The McCormick notes illustrate a counterintuitive principle in cryptography: a weak cipher invented by an individual with no cryptographic training can be harder to break than a strong cipher designed by experts.
The reason is that standard cryptanalysis relies on knowing the cipher system. Frequency analysis works because we know the cipher is a monoalphabetic substitution. The Kasiski examination works because we know the cipher is Vigenere. Even brute force works because we know the algorithm and just need to find the key.
When the cipher system itself is unknown and unique to one person, none of these techniques apply. The cryptanalyst has no framework to work within. This is why the McCormick notes, written by a man with limited literacy using a personal shorthand, have defeated the same FBI unit that breaks 99 percent of the ciphers it receives.
The parallel in modern cryptography is security through obscurity. If you design your own cipher and keep the algorithm secret, you may believe it is secure because no one knows how it works. This is the opposite of Kerckhoffs' principle, which states that security must depend only on the key, not on the secrecy of the algorithm. The McCormick case shows why keeping the algorithm secret can work in practice (nobody can break it), but it also shows why it is bad practice: the legitimate users (investigators trying to solve a murder) cannot decode the message either.
For CTF challenges and puzzle hunts, the McCormick notes are a reminder that not every ciphertext has a clean, algorithmic solution. Some require context, personal knowledge, or information outside the ciphertext itself.
As of 2026, the Ricky McCormick case remains unsolved. No one has been charged with his murder. The FBI continues to list the notes as one of CRRU's top unsolved cases. The public submission page remains open.
Nick Pelling's 2024 analysis suggested that solving the notes may require not cryptographic techniques but geographical and linguistic knowledge of downtown St. Louis in the 1990s. The number groups could be bus routes, building numbers, or local shorthand that only McCormick understood. Without someone who shared McCormick's environment and mental associations, the notes may be permanently unreadable.
The FBI has stated that even determining the notes are a grocery list or a love letter would be valuable, as it would help understand the cipher system. "Even if we found out that he was writing a grocery list or a love letter," Olson said, "we would still want to see how the code is solved. This is a cipher system we know nothing about."
No. As of 2026, the two notes found in Ricky McCormick's pockets remain undeciphered. The FBI's Cryptanalysis and Racketeering Records Unit and the American Cryptogram Association have both failed to break them. The FBI published the notes in 2011 and asked the public for help, but no solution has been accepted.
Ricky McCormick was a 41-year-old man from St. Louis, Missouri, who was found murdered in a field in St. Charles County on June 30, 1999. He was developmentally disabled, had limited literacy, and had spent time in prison. His family said he had used his own coded writing since boyhood.
The notes do not match any known cipher system. The FBI's four-step process requires identifying the cipher system (step 2) before reconstructing the key (step 3), but the system cannot be identified. The leading hypothesis is that the notes are an idiolectic cipher, a personal shorthand system invented by McCormick that only he could read.
An idiolectic cipher is a cipher system invented and used by a single person, where the key is not a mathematical value but a lifetime of personal associations. From the cryptanalyst's perspective, it is functionally equivalent to a one-time pad: recovering the plaintext requires recovering the author's mental model, not just applying mathematical techniques.
The FBI published images of both notes on its website in March 2011. The notes are also documented on the Cipher Museum and Cipher Mysteries websites. The FBI continues to accept public theories through its website.
Code Identifier
Identify the cipher or encoding used in a piece of text. Paste encoded or encrypted data and the code identifier returns ranked candidates with confidence scores.
Cryptogram Solver
Automated solving of substitution ciphers using frequency analysis and pattern recognition.
Letter Frequency Analyzer
Count and analyze letter frequencies in text for cryptogram solving.
The Zodiac Killer Ciphers: How Z340 Was Solved After 51 Years
For 51 years, a 340-character cipher sat in FBI files. It was solved in December 2020 by three amateur codebreakers working from home. Z13 and Z32 remain unsolved. Here is how it was done.
How to Decipher Any Code: A Beginner's Step-by-Step Guide
You have a string of characters. You do not know what cipher produced them. You have 15 minutes. Here is the systematic process that works every time for classical ciphers and encodings.