Ask Runable forDesign-Driven General AI AgentTry Runable For Free
Runable
Back to Blog
Technology12 min read

CBP Workers Allegedly Used Government Databases to Spy on Exes, Crushes, and Colleagues | WIRED

Records obtained by WIRED detail hundreds of allegations of Customs and Border Protection workers misusing internal tools to look up romantic interests and t...

customs and border protectionimmigration and customs enforcementdepartment of homeland securitylaw enforcementimmigration+2 more
CBP Workers Allegedly Used Government Databases to Spy on Exes, Crushes, and Colleagues | WIRED
Listen to Article
0:00
0:00
0:00

CBP Workers Allegedly Used Government Databases to Spy on Exes, Crushes, and Colleagues | WIRED

Overview

CBP Workers Allegedly Used Government Databases to Spy on Exes, Crushes, and Colleagues

Internal records obtained by WIRED reveal how, for years, United States Customs and Border Protection employees and contractors were accused of abusing sensitive government databases for reasons that had nothing to do with their jobs. The records contain hundreds of allegations of misuse of law enforcement databases, including federal agents querying data to look up romantic interests, monitor family members, expose various personal information and, in some cases, provide intelligence to suspected smugglers or drug-trafficking organizations.

Details

Acquired through Freedom of Information Act requests to CBP’s Office of Professional Responsibility and the Department of Homeland Security’s Office of Inspector General, the records reveal the breadth of alleged database abuse by CBP employees spanning more than a decade. As immigration and border authorities expand their surveillance through facial recognition, license plate readers, mobile-device searches, and commercially purchased location information generated by ordinary apps, the sheer range of these records, which date from 2009 through 2022, highlights how US residents can be—and have been—targeted by federal government employees with access to highly sensitive data and powerful tools.

WIRED has made this article free for all to read because it is primarily based on reporting from Freedom of Information Act requests. Please consider subscribing to support our journalism.

Please consider subscribing to support our journalism

In one case, a CBP officer allegedly used government databases to contact a flight attendant. In another, an officer was accused of pulling information from trusted-traveler applications to ask people out. Other CBP employees were accused of providing border-crossing data to someone involved in a “heated divorce.” And yet another DHS employee allegedly used controversial ad-tech-derived location data to track several coworkers’ cell phones—which appears to be the first known internal abuse case involving DHS use of ad-tech-derived mobile location data.

“Customs and Border Protection has a long history of impunity and abuse of people's civil and human rights,” says Laura Rivera, an attorney with Just Futures Law, a civil and immigration advocacy legal organization. “Accountability for their wrongdoing has been elusive, and the dynamic involving the abuse of data is simply another aspect of that. As our society adopts more AI, data collection, and surveillance tools, each of us becomes increasingly vulnerable.”

The 2009-2022 dataset shines light on what officers did with the access they already had prior to gaining even more access. According to CBP, digital surveillance tools are supposed to help officers screen travelers and investigate crimes more efficiently. The records, however, reveal how, in case after case, sensitive data collected for law-enforcement purposes was weaponized against private individuals.

At the time these allegations were made, complaints involving CBP personnel were initially routed through the Joint Intake Center, which has since been renamed the CBP Intake Center, and the Joint Intake Case Management System, which CBP and Immigration and Customs Enforcement still use for case tracking. Analysts decided whether each allegation should be retained for information, referred to an employee’s manager, or assigned to the Office of Professional Responsibility investigators as potentially serious misconduct.

Of the almost 300 data-related entries identified by WIRED, 138 were referred to CBP management for review, 78 were serious enough to be assigned to OPR criminal investigators, and 43 were classified as “Information Only,” meaning OPR did not open its own investigation. A smaller number fell into other categories: 12 misconduct allegations were sent for management review, where they were handled internally by the employees’ supervisors rather than by CBP’s central investigators; three were logged as “Law Enforcement Records” cases, meaning criminally investigated misconduct; two were logged as “Immediate Management Actions,” meaning minor misconduct resolved without opening a formal case; and only one as logged as an administrative inquiry, a formal fact-finding investigation conducted by CBP’s Office of Professional Responsibility. CBP withheld 21 cases, citing an exemption protecting active law-enforcement proceedings, suggesting criminal misconduct.

WIRED identified 99 entries involving alleged breaches or unauthorized disclosures of data and 48 explicitly involving improper database queries. Many of these cases happened around 2020, when the pandemic-prompted shift to remote work led CBP employees to start emailing work files to their personal accounts.

At least six entries explicitly describe employees querying themselves. According to Daniel Altman, the former head of the Office of Professional Responsibility, who left his post in 2025, the agency treats self-queries as a warning sign of future misconduct. They often surface early in corruption cases either as a way for employees to test whether searches are monitored or to check if they themselves are under investigation. From there, escalation is just a matter of degree.

“Doing retroactive analysis helped us understand that pattern,” says Altman. “Historical analysis of corruption cases showed that self-querying was common across a significant number of them, pointing to it being an indicator of corruption in the future.”

Several cases involve officers using database access to allegedly pursue or harass private citizens. In 2010, a customs officer allegedly pulled data on an Air New Zealand flight attendant and used it to contact them—a case that was referred to Labor and Employee Relations. In 2017, another officer faced a formal OPR investigation over allegations that he misused government databases to harass a different airline employee; the case’s resolution code was left blank in the records.

In 2017, another officer was accused of querying his neighbors in federal computer databases. And in 2022, an employee allegedly used a CBP database to obtain an ex-husband’s leave schedule as part of a harassment campaign. The records show that the cases were closed but do not reveal whether the allegations were substantiated or whether anyone was disciplined.

More serious allegations involved employees providing law-enforcement information to people suspected of criminal activity. In 2016, OPR investigated an allegation that a CBP employee was giving database information to a drug-trafficking organization. A separate 2021 entry accused a Border Patrol agent of querying databases to advise smugglers which lane to use at the border. The records don't disclose whether anyone was held accountable.

Many cases are closed, but in most entries, CBP withheld or left blank the case resolution, making it difficult to determine how often allegations were substantiated or whether employees faced discipline at all.

According to Altman, the missing resolution fields are likely due to data-entry integrity problems with the Joint Intake Case Management System. Even though completed investigations are generally supposed to include resolution codes, staff do not always fill in the required fields.

In response to WIRED’s findings, a Customs and Border Protection spokesperson says the agency takes allegations regarding misconduct seriously, adding that it works to “uphold the rule of law and hold ourselves accountable.” While federal privacy laws limit CBP’s ability to comment on individual cases, the spokesperson says that both CBP and DHS “thoroughly investigate alleged or potential misconduct, on or off duty” and that “appropriate investigatory, corrective, and disciplinary action is taken,” including coordination with other law enforcement agencies when necessary.

The records land at a moment when immigration authorities have more visibility into private citizens’ lives than ever before. Over the past two decades, DHS has built one of the largest surveillance systems in the world—an extensive set of databases that store everything from fingerprints to travel records to case files.

DHS’s Enforcement Integrated Database stores records on everyone detained or arrested by immigration officers. CBP’s TECS system integrates watch lists that everyone gets screened against when crossing the border. The Central Index System tracks naturalization applications. SENTRI, a trusted-traveler program, moves prescreened, low-risk travelers through the border faster in exchange for their personal and travel data—the same records one officer allegedly used in 2013 to ask people out.

Then there is Palantir’s Investigative Case Management system, which serves as a case-management platform for Homeland Security Investigations. CBP taps into ICM’s shared case files data through its links to CBP’s in-house identity-management systems and joint operations with ICE. CBP also draws on data from FALCON, a Palantir analytics tool, to search and link records pulled from across government and commercial sources. (Although direct access to FALCON is officially largely restricted to ICE officers, data-sharing across DHS departments allows federal agents to access many of the same databases.) Agents also have access to commercial tools like Thomson Reuters’ Consolidated Lead Evaluation and Reporting, which repackages disparate data sources like utility records and license-plate data, originally collected by private companies, into a surveillance tool for law enforcement.

A newer tool, DHS’s Mobile Fortify, is a facial-recognition app deployed on agents’ phones and tied to a number of databases containing hundreds of millions of records, including passport photos. Released in May of 2025, Mobile Fortify has already drawn reports of being used against people engaged in constitutionally protected activity, like protest.

The databases that agents allegedly misused are only part of their toolkit; CBP also taps mobile-extraction software from Cellebrite, Grayshift, and Magnet Forensics to pull data straight off a person’s phone.

Commercial telemetry data has become one of the most controversial forms of law-enforcement surveillance because it lets the government buy access to location information generated by ordinary apps, rather than obtaining it directly from phone companies with a court-approved search warrant, effectively circumventing Fourth Amendment protections. The Wall Street Journal first revealed in 2020 that CBP and ICE were purchasing the data for immigration and border-enforcement investigations, including a case in which CBP used cell-phone-location information to help uncover a drug-smuggling tunnel that ended beneath a closed fast-food restaurant in San Luis, Arizona. “This access allows officers to track people's daily movements in ways that can expose whether someone is seeking reproductive care, their religious practice, or their sexual activity,” says Rivera, the Just Futures Law attorney.

A 2023 DHS inspector general report found that CBP, ICE, and the US Secret Service had bought and used this kind of data without fully complying with department privacy rules or developing sufficient policies for its use. When WIRED filed a FOIA request with the Office of Inspector General for the case file behind the report, the agency handed over an ICE Office of Professional Responsibility file instead. The document describes an employee who allegedly “inappropriately utilized private software to track the location of several coworkers’ cell phones.” The file, which has not previously been reported, appears to be the first known internal abuse case involving commercial location-tracking software used by DHS.

Rivera also pointed to CBP's own automated license-plate-reader (ALPR) network and to a recent Flock Safety scandal, in which law enforcement officers were found to be using their access to license plate cameras to assist ICE and CBP operations.

Although none of the records WIRED obtained explicitly involve ALPRs, several concern the alleged misuse of license plate, vehicle registration, and driver information. Some cases document officers accused of running unofficial vehicle-related queries and accessing driver records for personal reasons.

“Once the police department decides they are going to share our data,” Rivera said, “they’re effectively just opening the floodgates.” Flock initially denied that CBP and ICE had access to the network before acknowledging the agencies had obtained it through a pilot program that it says has since been discontinued. The company said it didn't have control over how local law enforcement used or shared their data.

DHS claims that CBP uses AI systems to “enhance awareness of threats at the border” helping agents make informed decisions. But that same wide access, records show, may also be open to abuse by the officers who use it. WIRED previously found that ICE employees had been investigated for abusing access to sensitive government databases to look up ex-lovers and coworkers, run searches for friends and neighbors, and in some cases share protected information with others.

A 2022 report by the nonprofit civil rights group EPIC showed that CBP had been upgrading its mobile data extraction software to centralize the information pulled from searches, with active contracts then worth at least

1.29million.In2025alone,ICEandCBPsecuredatleast13separatecontractsformobileextractiontools,accordingtothemostrecentreports.Cellebrite,whichhascontractedwithbothagenciessince2008,hastakeninmorethan1.29 million. In 2025 alone, ICE and CBP secured at least 13 separate contracts for mobile extraction tools, according to the most recent reports. Cellebrite, which has contracted with both agencies since 2008, has taken in more than
56 million in federal contracts this year.

Driven by an increasingly privatized approach, the government’s surveillance apparatus is becoming unprecedentedly omnipresent; a WIRED analysis found that in addition to smaller vendor contracts, ICE and CBP have collectively spent about $515 million on products from major tech firms, such as Microsoft, Amazon, Google, and Palantir, in recent years.

“A lot of these tech oligarchs have gone from being part of a revolving door between industry and government to having a corner office in terms of designing and enforcing a regime of violence and exclusion—and a very political one,” says Jacinta González, a leader at Mijente, a national grassroots organization advocating for racial, economic, gender, and climate justice.

Wi Fi-8 is coming—here’s everything you need to know

Wi Fi-8 is coming—here’s everything you need to know

Big Story: Young runners are becoming freakishly fast

Big Story: Young runners are becoming freakishly fast

Take our survey: Do you work in tech? We want to hear from you

Take our survey: Do you work in tech? We want to hear from you

Key Takeaways

  • CBP Workers Allegedly Used Government Databases to Spy on Exes, Crushes, and Colleagues

  • Internal records obtained by WIRED reveal how, for years, United States Customs and Border Protection employees and contractors were accused of abusing sensitive government databases for reasons that had nothing to do with their jobs

  • Acquired through Freedom of Information Act requests to CBP’s Office of Professional Responsibility and the Department of Homeland Security’s Office of Inspector General, the records reveal the breadth of alleged database abuse by CBP employees spanning more than a decade

  • WIRED has made this article free for all to read because it is primarily based on reporting from Freedom of Information Act requests

  • Please consider subscribing to support our journalism

Cut Costs with Runable

Cost savings are based on average monthly price per user for each app.

Which apps do you use?

Apps to replace

ChatGPTChatGPT
$20 / month
LovableLovable
$25 / month
Gamma AIGamma AI
$25 / month
HiggsFieldHiggsField
$49 / month
Leonardo AILeonardo AI
$12 / month
TOTAL$131 / month

Runable price = $9 / month

Saves $122 / month

Runable can save upto $1464 per year compared to the non-enterprise price of your apps.