CBP Workers Used Government Databases to Spy on Exes and Colleagues

Internal records reveal hundreds of cases where CBP employees misused sensitive databases for personal purposes over more than a decade.

By Central
CBP personnel abused law enforcement databases for spying on exes and colleagues, as documented by WIRED.
Highlights
  • Between 2009 and 2022, CBP employees were accused of hundreds of incidents of database misuse.
  • The abuse included spying on romantic interests, tracking spouses, and exposing colleagues' data.
  • The records raise concerns about CBP's expansion of digital surveillance tools.

The United States Customs and Border Protection, the federal agency tasked with securing the nation’s borders, has for more than a decade been the site of a silent crisis of trust: its own employees and contractors repeatedly used sensitive government databases to spy on romantic interests, track estranged spouses, expose the personal information of colleagues, and, in the most egregious cases, feed intelligence to suspected drug traffickers. Internal records obtained by WIRED through Freedom of Information Act requests reveal that between 2009 and 2022, CBP personnel were accused of hundreds of separate incidents involving the abuse of law enforcement databases, turning tools designed for national security into instruments of personal vendetta and surveillance.

The records, pulled from CBP’s Office of Professional Responsibility and the Department of Homeland Security’s Office of Inspector General, paint a stark picture of what happens when powerful data tools are placed in the hands of individuals without adequate oversight. As CBP expands its digital surveillance apparatus—deploying facial recognition at ports of entry, scanning license plates, searching mobile devices, and purchasing location data harvested from ordinary smartphone apps—the historical record of internal abuse raises urgent questions about whether the agency can be trusted with even more data.

Hundreds of Allegations Spanning More Than a Decade

The FOIA-released dataset, covering allegations from 2009 through 2022, contains nearly 300 entries specifically related to data misuse. Of these, 138 were referred to CBP management for review, meaning the agency deemed them serious enough to require formal supervisory attention. Another 78 cases were classified as serious enough to be assigned to criminal investigators within the Office of Professional Responsibility. Forty-three entries were logged as “Information Only,” indicating that OPR did not open its own investigation but retained the record. The remaining cases fell into smaller categories: 12 misconduct allegations were sent for management review and handled internally by supervisors; three were logged as “Law Enforcement Records” cases, indicating criminally investigated misconduct; two were categorized as “Immediate Management Actions” for minor misconduct resolved without a formal case; and one was logged as an administrative inquiry, a formal fact-finding investigation conducted by CBP’s Office of Professional Responsibility. CBP withheld 21 cases entirely, citing an exemption that protects active law-enforcement proceedings, a withholding that itself suggests criminal misconduct was being investigated.

Of these entries, WIRED identified 99 that involved alleged breaches or unauthorized disclosures of data, and 48 that explicitly involved improper database queries. A notable cluster of cases occurred around 2020, when the pandemic-prompted shift to remote work led some CBP employees to email work files to personal accounts—a pattern that security experts view as a high-risk behavior for data exfiltration.

What the Abuse Actually Looked Like

The records read as a catalog of broken trust and misused authority. In one case, a CBP officer used government databases to contact a flight attendant, transforming a routine travel screening into the starting point for a personal pursuit. In another instance, an officer pulled information from trusted-traveler applications—programs designed to expedite border crossing for pre-vetted individuals—and used that data to ask people out on dates. A third employee was accused of providing border-crossing data to a party involved in a “heated divorce,” effectively weaponizing the government’s travel records in a private legal battle.

Perhaps most alarming is a case involving a DHS employee who used controversial ad-tech-derived location data—commercially purchased information generated by ordinary mobile apps—to track several coworkers’ cell phones. This appears to be the first known internal abuse case involving DHS use of this type of data, marking a troubling milestone as the department increasingly relies on commercially sourced surveillance tools that operate outside traditional legal frameworks.

The Trusted Traveler Connection

The abuse of trusted-traveler applications is particularly significant because these programs—such as Global Entry and TSA PreCheck—are marketed to the public as secure, streamlined processes that reward low-risk travelers with expedited screening. Participants submit extensive personal information, including employment history, travel patterns, and biometric data, under the implicit promise that their data will be used exclusively for vetting and border security. The allegations that CBP employees mined this database for personal purposes—asking out individuals they encountered through the system—represents a direct betrayal of that trust and raises the question of how many other travelers’ private information has been accessed without a legitimate law enforcement purpose.

Self-Queries as a Precursor to Corruption

A pattern emerges from the records that security experts find especially worrying: at least six entries explicitly describe employees running queries on themselves. Daniel Altman, the former head of CBP’s Office of Professional Responsibility who left his post in 2025, told WIRED that the agency treats self-queries as a significant warning sign of future misconduct. According to Altman, self-queries often surface early in corruption cases, either as a way for employees to test whether their searches are being monitored or to check if they themselves are under investigation. From that point, Altman noted, escalation is “just a matter of degree.”

The self-query phenomenon highlights a fundamental weakness in database oversight: if employees can easily determine whether they are being watched, they can calibrate their behavior accordingly. This cat-and-mouse dynamic suggests that the officially reported numbers of abuse cases almost certainly undercount the true scope of the problem, since only those employees who made mistakes—or whose queries were flagged by automated systems—would appear in the records.

What Is the Office of Professional Responsibility and How Does It Investigate?

The Office of Professional Responsibility is CBP’s internal watchdog, responsible for investigating allegations of misconduct by agency personnel, including database abuse, corruption, and civil rights violations. When a complaint is filed—whether by a whistleblower, a member of the public, or through internal reporting channels—it is first routed through the Joint Intake Center, now renamed the CBP Intake Center, and logged into the Joint Intake Case Management System, which is still used by CBP and Immigration and Customs Enforcement for case tracking. Analysts then decide the disposition of each allegation: it may be retained for information only, referred to the employee’s manager for handling, or assigned to OPR investigators for a full probe if the allegation involves potentially serious misconduct. The system is designed to triage cases by severity, but the records obtained by WIRED suggest that a significant number of serious allegations—78 cases assigned to criminal investigators—may not have resulted in meaningful discipline or public accountability.

Laura Rivera, an attorney with Just Futures Law, a civil and immigration advocacy organization, told WIRED that the agency’s track record of accountability is poor. “Customs and Border Protection has a long history of impunity and abuse of people’s civil and human rights,” Rivera said. “Accountability for their wrongdoing has been elusive, and the dynamic involving the abuse of data is simply another aspect of that. As our society adopts more AI, data collection, and surveillance tools, each of us becomes increasingly vulnerable.”

The Data Goldmine and Its Dangers

The breadth of databases accessible to CBP employees is staggering. In addition to the agency’s own records—which include travel histories, biometric data, and inspection reports—CBP personnel can access Department of Homeland Security-wide systems, law enforcement databases from other federal agencies, and commercially purchased data streams. The latter category has grown explosively in recent years. CBP now uses facial recognition technology to scan travelers at border crossings, license plate readers to track vehicle movements, mobile-device search tools to examine the contents of phones and laptops, and commercially purchased location data generated by everyday mobile apps—the same kind of data involved in the coworker-tracking case.

These tools are sold to the public as efficiency measures and crime-fighting aids. The records from 2009 to 2022, however, provide a sobering counter-narrative: each tool can be, and has been, turned against private individuals. The same database that allows an officer to quickly vet a traveler’s identity can also be used to look up an ex-partner’s new address. The same system that flags suspicious vehicles can be used to trace the movements of a colleague. The same location data that helps investigators find smuggling routes can be used to stalk a coworker.

How Does Database Abuse by Government Employees Affect Ordinary People?

Database abuse by government employees exposes ordinary people to a range of harms: stalking, harassment, identity exposure, and, in divorce or custody proceedings, the manipulation of government records to gain leverage. When a CBP officer looks up a romantic interest or an ex-spouse using law enforcement systems, they are accessing information that the individual had no choice but to share with the government—travel itineraries, passport details, addresses, employment information, and biometric data. The victim may never know that their data was accessed without authorization, because query logs are not always reviewed unless a complaint is filed. The chilling effect is profound: if citizens cannot trust that their private information will remain private when shared with law enforcement, the entire system of voluntary cooperation—including participation in trusted-traveler programs—begins to erode.

The Remote Work Surge and Its Consequences

The 2020 pandemic brought a shift to remote work across the federal government, and CBP was no exception. The records show a notable uptick in cases around this time, with employees emailing work files to personal accounts—a classic data-exfiltration technique that can be hard to detect unless automated monitoring is in place. This pattern is particularly concerning because remote access creates new vectors for abuse: employees can query databases from home, at odd hours, without the social oversight of working in an office environment. The pandemic-era cases serve as a reminder that data security is not just a technical challenge but a cultural and managerial one. When oversight is lax and consequences are uncertain, the temptation to misuse access grows.

The Ad-Tech Location Data Case: A New Frontier

The case involving ad-tech-derived location data marks an important precedent. DHS has been aggressively purchasing commercially available location data—information collected by mobile apps that users install for purposes like weather, maps, or games, which is then sold to data brokers and ultimately to government agencies. This practice has drawn increasing scrutiny from civil liberties advocates, who argue that it allows the government to circumvent the warrant requirement of the Fourth Amendment. The internal abuse case, in which a DHS employee used this exact type of data to track coworkers’ cell phones, demonstrates that the same loophole that undermines constitutional protections for the public can also be exploited internally. If employees can use commercial data to target their colleagues, the argument that this data is inherently less sensitive than government-collected data collapses.

The location-tracking case also raises the question of whether DHS has adequate policies to govern employee access to commercial data. Unlike government records, which are subject to Privacy Act protections and internal audit requirements, commercially purchased data often comes with fewer legal guardrails. An employee who queries a government database leaves a log entry; an employee who queries a commercial data broker’s portal may leave a much fainter trace.

The Numbers Behind the Crisis

The 300-entry dataset is not a complete accounting of all database abuse at CBP—it represents only the allegations that were formally logged and that survived the FOIA review process. Within that dataset, the distribution of case dispositions tells a story of its own. The largest category—138 cases sent to management review—suggests that the agency saw reason to take these allegations seriously but did not classify them as criminal-level misconduct. The 78 cases assigned to OPR criminal investigators, however, indicate that a substantial minority of allegations involved behavior that investigators considered potentially criminal. The 43 cases classified as “Information Only” suggest that some allegations were deemed not worth pursuing, while the 21 withheld cases hint at active investigations that the agency did not want to expose.

Only one case in the entire dataset was logged as an administrative inquiry—a formal, fact-finding investigation by the Office of Professional Responsibility. This figure is striking: it suggests that even when allegations were serious enough to warrant referral to OPR, the agency rarely conducted the kind of deep-dive administrative investigation that could lead to systemic changes or policy improvements. Instead, most cases appear to have been handled at the management level or shunted to criminal investigators who may or may not have had the resources to pursue them.

Impunity Looms over the Agency

The records do not reveal how many of these cases resulted in disciplinary action, termination, or criminal prosecution. CBP, like many law enforcement agencies, has resisted public disclosure of disciplinary outcomes, arguing that they are personnel matters protected by privacy laws. The result is a system in which allegations are logged and investigated to varying degrees, but the public rarely learns whether an officer who spied on an ex-partner kept their job, lost their security clearance, or faced prosecution. This opacity is itself a form of impunity: when the consequences of misconduct are invisible, the deterrent effect weakens.

Civil rights attorneys and government accountability advocates have long argued that CBP’s internal oversight mechanisms are insufficient. The Office of Professional Responsibility, while empowered to investigate, has historically been understaffed relative to the size of the agency, which employs roughly 60,000 people. The Joint Intake Center processes thousands of complaints per year across CBP and ICE, covering everything from use-of-force incidents to database misuse. In practice, database abuse allegations may not receive the same priority as physical misconduct, even though the potential for harm is substantial.

Self-Queries as an Indicator of Broader Problems

The six cases involving self-queries—employees looking up their own records—are particularly telling. Security professionals often refer to the “insider threat” as one of the hardest cybersecurity problems to solve, because insiders have legitimate access and can abuse it in subtle ways. The self-query is a classic behavior in the early stages of insider threat: the employee tests the system to see if anyone is watching. If the query goes undetected, the employee may escalate to querying others—friends, family members, romantic partners, or, eventually, targets of bribery or coercion. Altman’s observation that the agency treats self-queries as a “warning sign” is consistent with this security framework, but it also implies that a proactive monitoring system is essential. The question is whether CBP’s monitoring systems are sophisticated enough to catch self-queries in real time and distinguish them from legitimate self-vetting (which might occur if an employee is updating their own security clearance or travel profile).

The fact that at least six such cases were documented over a 13-year period suggests that some self-queries are being flagged, but the low number also raises questions about detection rates. If the monitoring system is only catching the most obvious or egregious self-queries, there could be many more that go unnoticed. Moreover, the records do not indicate whether the self-queries in question resulted in disciplinary action or whether they were merely noted as suspicious behavior that did not escalate.

The Broader Implications for Surveillance Policy

The CBP database abuse crisis is more than a story about a single agency’s internal failings. It is a case study in the risks of expanding government surveillance without corresponding investments in oversight, accountability, and cultural change. As CBP adopts more artificial intelligence tools, automated decision-making systems, and real-time data streams, the potential for misuse grows exponentially. A facial recognition system that can be queried from a mobile phone is not just a tool for catching criminals—it is also a tool for an officer to check whether an ex-partner has entered the country. A license plate reader network that tracks vehicles across state lines is not just a way to find smuggling routes—it is also a way to monitor the movements of a coworker involved in a personal dispute.

The records from 2009 to 2022 are a historical document, but the trends they reveal are accelerating. The 2020 remote-work surge, the increasing reliance on commercial data brokers, and the expansion of AI-driven analytics all point toward a future in which more data is available to more people within the agency. Without a robust overhaul of oversight mechanisms, the history of abuse documented in these records may be just the beginning.

The legal framework governing employee access to law enforcement databases has not kept pace with technological change. The Privacy Act of 1974, which restricts how federal agencies can disclose personal information, was written decades before smartphones, cloud computing, and commercial data markets existed. It imposes some constraints on database misuse, but its enforcement relies heavily on agency self-reporting and individual lawsuits. For a victim of database abuse—someone whose ex-partner who works for CBP looked up their home address using a government system—the legal remedy is often unclear: filing a Privacy Act claim requires proving that the misuse was intentional and that it caused actual damages, a high bar that few plaintiffs can clear.

Can the System Be Fixed?

Some reforms are within reach. Stronger audit logging—ensuring that every query is recorded, timestamped, and associated with a specific user—is a technical fix that most large database systems already support. The challenge is cultural and managerial: audits are only effective if someone reviews them regularly and if violations carry meaningful consequences. Automated anomaly detection, which flags unusual query patterns such as off-hours access or queries on oneself, can help, but it requires investment in software and personnel. A zero-trust approach to database access, in which employees are given only the minimum data they need to perform their specific duties and queries are automatically verified against a purpose-code, would dramatically reduce the attack surface. None of these measures are secret; they are standard practices in the private sector and in intelligence agencies. Their absence at CBP is a matter of organizational priority, not technical feasibility.

The records obtained by WIRED also highlight the importance of whistleblower protections. In several cases, it appears that the abuse was reported by colleagues or supervisors—meaning that insiders are often the first line of defense. If those insiders fear retaliation or believe their reports will vanish into a black hole, the system loses its early-warning capability. Strengthening protections for whistleblowers and creating clear, confidential channels for reporting database misuse are essential components of any reform effort.

The Department of Homeland Security and CBP have been aware of these patterns for years. The fact that the records span from 2009 to 2022, with no sign of a downward trend in allegations, suggests that previous internal efforts have not been sufficient. The agency has periodically announced new initiatives to improve data security and combat corruption—enhanced training programs, updated policies, new technology deployments—but the steady stream of misconduct documented in these records indicates that the problem persists.

For the American public, the lesson is sobering. Every traveler who submits to a biometric scan, every Global Entry applicant who hands over a decade of address history, every driver whose license plate is captured by a CBP camera, every phone searched at a border crossing—all of that data enters a system that has a documented history of being accessed by employees for dating, stalking, personal grudges, and, in some cases, criminal profit. The integrity of that system depends not just on the technology but on the people who operate it, and the records show that not all of those people can be trusted. As the agency acquires more data and more powerful tools, the risks will only grow, unless the culture of accountability changes from within.

Share This Article