Internal records obtained by WIRED reveal years of allegations that U.S. Customs and Border Protection (CBP) employees and contractors misused confidential government databases for purposes unrelated to their official duties. The records include hundreds of allegations involving unauthorized law enforcement database searches. In some cases, federal agents allegedly used sensitive information to investigate romantic partners, monitor family members, expose personal details, or provide information to suspected smugglers and drug traffickers.
The records were obtained through Freedom of Information Act requests to CBP’s Office of Professional Responsibility and the Department of Homeland Security’s Office of Inspector General. They document allegations of database abuse by CBP employees over more than a decade, from 2009 through 2022. The records show how people in the United States may be targeted by federal officials with access to sensitive data and powerful surveillance tools, including facial recognition systems, license plate readers, mobile device searches, and commercial location data collected through popular apps.
In one case, CBP officers allegedly used a government database to contact flight attendants. In another, a police officer was accused of using information from a trusted traveler application to solicit dates. Other CBP officers allegedly shared cross-border data with people involved in a contentious divorce. In a separate case, a DHS employee was accused of tracking the cellphones of several colleagues using location data obtained through controversial advertising technology. The internal abuse case appears to be among the first publicly documented examples of DHS personnel allegedly using mobile location data derived from advertising technology.
“Customs and Border Protection has a long history of impunity and abuse of people’s civil and human rights,” said Laura Rivera, an attorney with the civil and immigration advocacy organization Just Futures Law. “Accountability for their wrongdoings is elusive, and power dynamics that involve the misuse of data are just one aspect of that. As our society deploys more AI, data collection, and surveillance tools, each of us becomes increasingly vulnerable.”
The 2009–2022 dataset provides insight into how law enforcement personnel used existing database access before gaining access to even more advanced surveillance systems. CBP says digital surveillance tools help officers screen travelers and investigate crimes more efficiently. However, the records describe repeated allegations that sensitive information collected for law enforcement purposes was used against private individuals.
CBP Database Breaches and Unauthorized Queries
At the time the allegations were reported, complaints involving CBP officers were initially sent to the Joint Intake Center, later renamed the CBP Intake Center. The allegations were tracked through the Joint Intake Case Management System, which CBP and Immigration and Customs Enforcement continue to use. Analysts determined whether each complaint should remain open as a potentially serious misconduct case, be referred to the employee’s supervisor, or be assigned to an investigator with the Office of Professional Responsibility.
WIRED identified approximately 300 data-related entries. Of those, 138 were referred to CBP management for review, while 78 were serious enough to be assigned to OPR criminal investigators. Another 43 were classified as “information only,” meaning OPR did not open its own investigation. The remaining allegations were placed in other categories. Twelve misconduct complaints were referred to management and handled internally by the employees’ supervisors rather than CBP’s central investigative office. Three cases were recorded as “law enforcement record” matters, indicating that the alleged activity was investigated as a potential crime. Two cases were classified as “immediate administrative action,” meaning the alleged minor misconduct was resolved without formal litigation. One case was listed as an administrative investigation, a formal fact-finding process conducted by CBP’s Office of Professional Responsibility. CBP suspended 21 cases involving alleged criminal activity, citing immunity protections connected to law enforcement proceedings.
WIRED identified 99 entries involving suspected data breaches or unauthorized disclosures, along with 48 entries that explicitly described inappropriate database queries. Many of the incidents occurred around 2020, when CBP employees began sending work files to personal email accounts after the COVID-19 pandemic forced a shift to remote work.
At least six entries explicitly indicate that an employee searched for information about themselves. Daniel Altman, the former head of the Office of Professional Responsibility who left the agency in 2025, said CBP considers self-searches a potential warning sign of future misconduct. Such activity can emerge in the early stages of corruption investigations, when employees test whether their actions are being monitored or attempt to determine whether they are under investigation. From there, Altman said, misconduct can escalate.
Source: www.wired.com


