Technology

FOIA Records Detail 300 Incidents of CBP Officers Misusing Government Surveillance Databases

Martin HollowayPublished 24h ago5 min readBased on 10 sources
Reading level
FOIA Records Detail 300 Incidents of CBP Officers Misusing Government Surveillance Databases
Photo by Brett Sayles on Pexels

US Customs and Border Protection officers systematically misused government surveillance databases to spy on family members, pursue romantic interests, track coworkers, and furnish intelligence to suspected drug traffickers, according to FOIA files obtained by Wired and reported on August 13, 2026. The records document roughly 300 incidents spanning from 2009 to 2022 Engadget.

The databases at issue draw on license plate readers, facial recognition systems, and smartphone search data, among other sources. Specific incidents detailed in the files include a CBP officer using a government database to contact a flight attendant, another exploiting trusted-traveler application data to ask people out, one employee providing border-crossing data to an individual involved in a divorce proceeding, and another tracking coworkers' cellphones using ad-tech-derived location data Wired.

Of the 300 incidents Wired tracked, 138 were referred to CBP management and 78 were assigned to criminal investigators. Twenty-one incidents were withheld from release due to potential law-enforcement proceedings, suggesting criminal misconduct. Forty-three incidents were not investigated at all Engadget.

The scope of data accessible to CBP officers is substantial. Wired noted that the Department of Homeland Security has built one of the largest surveillance systems in the world, aggregating immigration arrest records, border screening records, naturalization applications, and the SENTRI trusted-traveler program. The department also has access to Palantir's ICM and FALCON systems and the DHS Mobile Fortify facial-recognition app deployed directly on agents' phones Engadget.

CBP told Wired it takes misconduct allegations seriously and works to uphold the rule of law and take appropriate investigatory, corrective, and disciplinary action. The agency also maintains a public "Stats and Summaries" page whose stated purpose is to increase transparency and awareness of CBP's efforts to prevent, detect, and investigate misconduct CBP.

The pattern these FOIA files expose is not new within DHS. A 2009 DHS OIG report established that the department has a duty to protect personally identifiable information from loss and misuse, noting that compromise of Automated Targeting System data can have severe consequences. A 2016 DHS OIG report defined serious misconduct to include misuse of government databases, abuse of position for personal gain, and association with known criminals or illegal activity. That same year, Inspector General John Roth reported that an investigation had revealed personnel and database resources were misused by Washington Field Office "Prowler" teams DHS OIG.

Auditability remains a structural weakness. A DHS OIG report issued in September 2023 (OIG-23-61) found that CBP was unable to provide audit logs from one Counterterrorism Division database provider. A CBP official told investigators the provider simply did not respond to the request. Without log data, retroactive investigation of individual database access is effectively impossible DHS OIG.

The Brennan Center for Justice documented in 2020 that law enforcement agencies have a history of misusing license plate surveillance to monitor First Amendment-protected activity. That research focused on automatic license plate readers, one of the same data sources feeding the CBP databases at issue in the current FOIA release Brennan Center.

CBP's own budget testimony from April 2024 requested funding for an additional 150 CBP officers and 121 mission support personnel to address "dynamic threats and increasing workload" in port-of-entry operations. The FOIA files, covering a 13-year window, cast the question of what oversight infrastructure exists for the workforce already in place CBP.

Looking at what this means in practice, the incidents span more than a decade and range from petty personal misconduct to potential criminal collusion with drug traffickers. That breadth matters. A handful of rogue officers abusing access is an enforcement problem. Hundreds of incidents over thirteen years, with forty-three never investigated and audit logs unobtainable from at least one database provider, is an architecture problem. The data collection layer of DHS's surveillance stack, built from license plate readers, facial recognition, smartphone extraction, and commercial ad-tech location data, feeds into systems whose access controls and audit trails evidently cannot reliably detect or prevent misuse by their own operators.

Worth flagging: the 2023 OIG finding that a database provider failed to respond to an audit-log request is, in this author's view, the most technically consequential detail in the record. If audit logs cannot be produced on demand, then every assurance about access controls, least-privilege enforcement, and post-incident accountability rests on an unverifiable foundation. The FOIA incidents may represent only the cases where misuse was detected despite that gap; cases that went undetected would, by definition, not appear in the files.

CBP's stated commitment to disciplinary action addresses the back end of the problem. The front end, access governance and independent auditability of every query against these databases, is where the technical and policy work remains.