Widespread internal misuse of sensitive digital surveillance tools by US border and homeland security personnel has been uncovered through federal records. Analysis of documents obtained via Freedom of Information Act (FOIA) requests submitted to the Customs and Border Protection (CBP) Office of Professional Responsibility and the Department of Homeland Security (DHS) Office of Inspector General reveals a decade-long pattern of database abuse spanning from 2009 through 2022. Federal agents equipped with powerful surveillance access repeatedly weaponized law-enforcement data against private citizens, including flight attendants, ex-spouses, neighbors, and coworkers. As immigration authorities expand their reliance on artificial intelligence, automated license plate readers, facial recognition, and commercial location tracking, these findings highlight severe systemic vulnerabilities in government data governance.
Comprehensive Breakdown of Misconduct Records and Internal Processing
The dataset covering the 2009 to 2022 period contains nearly 300 data-related misconduct entries. Complaints involving CBP personnel were routed through the Joint Intake Case Management System, a shared database tracking framework utilized by both CBP and Immigration and Customs Enforcement (ICE). Internal analysts assessed each allegation to determine whether it should be logged for information, referred to localized management, or escalated to criminal investigators within the Office of Professional Responsibility (OPR).
Out of the nearly 300 identified entries, 138 cases were referred directly to CBP management for internal review, while 78 were deemed grave enough to be assigned to OPR criminal investigators. A total of 43 entries were classified as 'Information Only', resulting in no formal investigation opened by OPR. Among smaller categories, 12 misconduct allegations were assigned for management review handled internally by supervisors, 3 were logged as 'Law Enforcement Records' cases involving criminal investigation, 2 were marked as 'Immediate Management Actions' for minor infractions resolved informally, and exactly 1 case was opened as a formal administrative inquiry. Furthermore, CBP withheld 21 cases under legal exemptions protecting ongoing law-enforcement proceedings, indicating active criminal inquiries. In total, 99 entries involved alleged unauthorized disclosures or data breaches, while 48 explicitly involved improper database queries. A significant surge in breaches occurred around 2020, driven by remote-work shifts during the pandemic when staff emailed work files to personal accounts.
Personal Spying, Dating Misuse, and Harassment Campaigns
Specific case entries detail how federal employees exploited government access to pursue personal interests or harass individuals. In 2010, a customs officer pulled confidential records of an Air New Zealand flight attendant and used the information to establish personal contact, leading to a referral to Labor and Employee Relations. In 2013, an officer abused data collected through SENTRI, a trusted-traveler program designed to expedite border crossings for prescreened individuals, to ask people out on dates.
In 2017, a formal OPR investigation was launched after an officer was accused of misusing government databases to harass another airline employee; the official record leaves the case resolution code blank. That same year, another officer was cited for querying personal neighbors within federal law-enforcement systems. In 2022, an employee accessed a CBP database during a contentious divorce to obtain an ex-husband's work leave schedule for harassment purposes. In the majority of these entries, resolution fields remain blank or withheld, obscuring whether disciplinary actions were ever enforced.
Collusion with Drug Cartels and Border Smuggling Operations
Beyond personal harassment, several entries detail alarming instances where law-enforcement databases were compromised to assist criminal syndicates. In 2016, OPR investigated allegations that a CBP employee leaked sensitive database records directly to a drug-trafficking organization. In 2021, a Border Patrol agent was accused of running database queries to inform smugglers which specific inspection lane to use at the border to evade detection. The released records do not specify whether the agents involved were prosecuted or dismissed.
The 'Self-Query' Warning Indicator and Oversight Deficits
At least six entries in the dataset explicitly document employees running database queries on themselves. According to Daniel Altman, former head of the Office of Professional Responsibility who departed his post in 2025, self-queries serve as an early red flag for corruption. Personnel often run their own names to test whether database monitoring systems are active or to check if they are currently under internal investigation. Historical reviews of corruption cases confirmed that self-querying frequently precedes severe misconduct.
Daniel Altman noted that historical corruption analysis established self-querying as a primary indicator of future illicit activity. Regarding missing resolution codes across the records, he attributed the gaps to data-entry flaws within the Joint Intake Case Management System, where personnel routinely failed to fill out required fields upon case completion. In response to these findings, a CBP spokesperson stated that the agency takes all misconduct allegations seriously, works to uphold the rule of law, and thoroughly investigates potential policy violations on or off duty.
The Expanding DHS Surveillance Apparatus
Over the past two decades, DHS has constructed one of the most comprehensive surveillance networks in the world. Key components include the Enforcement Integrated Database, which tracks individuals detained or arrested by immigration authorities, and CBP's TECS system, which cross-references travelers against watchlists. The Central Index System maintains records on naturalization applications, while Palantir's Investigative Case Management (ICM) serves as a centralized platform for Homeland Security Investigations. CBP also utilizes Palantir's FALCON analytics tool to link disparate records from commercial and government databases.
Commercial tools such as Thomson Reuters' Consolidated Lead Evaluation and Reporting (CLEAR) aggregate utility records and vehicle data into searchable law-enforcement dossiers. In May 2025, DHS deployed Mobile Fortify, a mobile facial-recognition application tied to hundreds of millions of records, including passport photos. Reports indicate Mobile Fortify has already been used to identify individuals participating in constitutionally protected public protests.
Commercial Location Tracking and Telemetry Misuse
Commercial telemetry data represents one of the most controversial surveillance mechanisms utilized by federal agencies. By purchasing location information harvested from ordinary mobile applications, government agencies circumvent Fourth Amendment warrant requirements. A 2020 disclosure showed that CBP and ICE purchased location data to uncover a drug-smuggling tunnel ending beneath a closed fast-food restaurant in San Luis, Arizona. A 2023 DHS Inspector General report confirmed that CBP, ICE, and the US Secret Service purchased and used commercial location tracking without complying with privacy standards or establishing proper policy frameworks.
Laura Rivera, an attorney with Just Futures Law, emphasized that commercial location tracking exposes sensitive daily habits, including medical visits, religious practices, and personal relationships. She also highlighted concerns regarding automated license plate readers (ALPR) and a scandal involving Flock Safety, where local police camera networks shared data feeds with federal immigration authorities. Jacinta González, a leader at Mijente, warned that major tech conglomerates have effectively integrated into state surveillance operations to enforce exclusionary policies.
Private Tech Infrastructure and Mobile Extraction Contracts
To extract data directly from physical devices, federal agents utilize specialized mobile extraction software manufactured by firms including Cellebrite, Grayshift, and Magnet Forensics. A 2022 report by civil rights organization EPIC revealed that CBP upgraded its extraction software to centralize collected data, supported by contracts valued at over $1.29 million. In 2025 alone, ICE and CBP executed at least 13 distinct contracts for mobile extraction tools. Cellebrite, which has contracted with federal agencies since 2008, secured over $56 million in federal contracts this year.
Analysis indicates that ICE and CBP have collectively spent approximately $515 million on products and services provided by major technology corporations, including Microsoft, Amazon, Google, and Palantir in recent years. This massive financial investment underscores the scale of federal surveillance expansion and heightens concerns regarding the lack of binding oversight and accountability mechanisms.



















