Back to Feed
BreachesAug 13, 2026

CBP Workers Allegedly Used Government Databases to Spy on Exes, Crushes, and Colleagues

CBP employees allegedly misused government databases to spy on exes, crushes, and colleagues.

Summary

Hundreds of allegations reveal that Customs and Border Protection employees and contractors abused sensitive government databases for personal reasons, including spying on romantic interests and colleagues. These abuses, spanning from 2009 to 2022, involved querying data for non-job-related purposes, such as contacting flight attendants, asking people out, and even providing border-crossing data to individuals involved in disputes. One case involved using ad-tech-derived location data to track coworkers' cell phones, marking a potential first for DHS internal abuse of such data.

Full text

CommentLoaderSave StorySave this storyCommentLoaderSave StorySave this storyInternal records obtained by WIRED reveal how, for years, United States Customs and Border Protection employees and contractors were accused of abusing sensitive government databases for reasons that had nothing to do with their jobs. The records contain hundreds of allegations of misuse of law enforcement databases, including federal agents querying data to look up romantic interests, monitor family members, expose various personal information and, in some cases, provide intelligence to suspected smugglers or drug-trafficking organizations.Acquired through Freedom of Information Act requests to CBP’s Office of Professional Responsibility and the Department of Homeland Security’s Office of Inspector General, the records reveal the breadth of alleged database abuse by CBP employees spanning more than a decade. As immigration and border authorities expand their surveillance through facial recognition, license plate readers, mobile-device searches, and commercially purchased location information generated by ordinary apps, the sheer range of these records, which date from 2009 through 2022, highlights how US residents can be—and have been—targeted by federal government employees with access to highly sensitive data and powerful tools.In one case, a CBP officer allegedly used government databases to contact a flight attendant. In another, an officer was accused of pulling information from trusted-traveler applications to ask people out. Other CBP employees were accused of providing border-crossing data to someone involved in a “heated divorce.” And yet another DHS employee allegedly used controversial ad-tech-derived location data to track several coworkers’ cell phones—which appears to be the first known internal abuse case involving DHS use of ad-tech-derived mobile location data.“Customs and Border Protection has a long history of impunity and abuse of people's civil and human rights,” says Laura Rivera, an attorney with Just Futures Law, a civil and immigration advocacy legal organization. “Accountability for their wrongdoing has been elusive, and the dynamic involving the abuse of data is simply another aspect of that. As our society adopts more AI, data collection, and surveillance tools, each of us becomes increasingly vulnerable.”The 2009-2022 dataset shines light on what officers did with the access they already had prior to gaining even more access. According to CBP, digital surveillance tools are supposed to help officers screen travelers and investigate crimes more efficiently. The records, however, reveal how, in case after case, sensitive data collected for law-enforcement purposes was weaponized against private individuals.Breaches and QueriesAt the time these allegations were made, complaints involving CBP personnel were initially routed through the Joint Intake Center, which has since been renamed the CBP Intake Center, and the Joint Intake Case Management System, which CBP and Immigration and Customs Enforcement still use for case tracking. Analysts decided whether each allegation should be retained for information, referred to an employee’s manager, or assigned to the Office of Professional Responsibility investigators as potentially serious misconduct.Of the almost 300 data-related entries identified by WIRED, 138 were referred to CBP management for review, 78 were serious enough to be assigned to OPR criminal investigators, and 43 were classified as “Information Only,” meaning OPR did not open its own investigation. A smaller number fell into other categories: 12 misconduct allegations were sent for management review, where they were handled internally by the employees’ supervisors rather than by CBP’s central investigators; three were logged as “Law Enforcement Records” cases, meaning criminally investigated misconduct; two were logged as “Immediate Management Actions,” meaning minor misconduct resolved without opening a formal case; and only one as logged as an administrative inquiry, a formal fact-finding investigation conducted by CBP’s Office of Professional Responsibility. CBP withheld 21 cases, citing an exemption protecting active law-enforcement proceedings, suggesting criminal misconduct.WIRED identified 99 entries involving alleged breaches or unauthorized disclosures of data and 48 explicitly involving improper database queries. Many of these cases happened around 2020, when the pandemic-prompted shift to remote work led CBP employees to start emailing work files to their personal accounts.At least six entries explicitly describe employees querying themselves. According to Daniel Altman, the former head of the Office of Professional Responsibility, who left his post in 2025, the agency treats self-queries as a warning sign of future misconduct. They often surface early in corruption cases either as a way for employees to test whether searches are monitored or to check if they themselves are under investigation. From there, escalation is just a matter of degree.“Doing retroactive analysis helped us understand that pattern,” says Altman. “Historical analysis of corruption cases showed that self-querying was common across a significant number of them, pointing to it being an indicator of corruption in the future.”A Wide Range of UsesSeveral cases involve officers using database access to allegedly pursue or harass private citizens. In 2010, a customs officer allegedly pulled data on an Air New Zealand flight attendant and used it to contact them—a case that was referred to Labor and Employee Relations. In 2017, another officer faced a formal OPR investigation over allegations that he misused government databases to harass a different airline employee; the case’s resolution code was left blank in the records.In 2017, another officer was accused of querying his neighbors in federal computer databases. And in 2022, an employee allegedly used a CBP database to obtain an ex-husband’s leave schedule as part of a harassment campaign. The records show that the cases were closed but do not reveal whether the allegations were substantiated or whether anyone was disciplined.More serious allegations involved employees providing law-enforcement information to people suspected of criminal activity. In 2016, OPR investigated an allegation that a CBP employee was giving database information to a drug-trafficking organization. A separate 2021 entry accused a Border Patrol agent of querying databases to advise smugglers which lane to use at the border. The records don't disclose whether anyone was held accountable.Many cases are closed, but in most entries, CBP withheld or left blank the case resolution, making it difficult to determine how often allegations were substantiated or whether employees faced discipline at all.According to Altman, the missing resolution fields are likely due to data-entry integrity problems with the Joint Intake Case Management System. Even though completed investigations are generally supposed to include resolution codes, staff do not always fill in the required fields.In response to WIRED’s findings, a Customs and Border Protection spokesperson says the agency takes allegations regarding misconduct seriously, adding that it works to “uphold the rule of law and hold ourselves accountable.” While federal privacy laws limit CBP’s ability to comment on individual cases, the spokesperson says that both CBP and DHS “thoroughly investigate alleged or potential misconduct, on or off duty” and that “appropriate investigatory, corrective, and disciplinary action is taken,” including coordination with other law enforcement agencies when necessary.Expanding AccessThe records land at a moment when immigration authorities have more visibility into private citizens’ lives than ever before. Over the past two decades, DHS has built one of the largest surveillance systems in the world—an extensive set of databases that store everything from fingerprints

Entities

CBP (vendor)DHS (vendor)