Nearly 300 allegations. Thirteen years. One agency holding access to some of the most powerful surveillance tools on the planet—and reportedly, some staff who treated those tools as personal research portals, querying romantic interests, coordinating with traffickers, and running surveillance on former partners.
WIRED obtained internal CBP misconduct records through FOIA requests, revealing a pattern that stretches well beyond a few isolated officers. CBP sits at the center of a surveillance apparatus that screens every border crosser, stores biometric data on millions of travelers, and pulls commercial location data from everyday apps. That’s the context behind the numbers—and the numbers are striking.
The Databases, the Misuse, and the Missing Accountability
The FOIA records expose not just individual misconduct, but structural gaps that left alleged abuses unresolved for years.
Of the roughly 300 data-related entries spanning 2009 to 2022:
- 99 involved alleged unauthorized data disclosures
- 48 documented explicit improper database queries
- 78 were serious enough to reach OPR criminal investigators
- 43 were logged as “Information Only”—meaning no investigation was even opened
- 21 cases were withheld entirely by CBP, citing active law-enforcement exemptions
Countless records carry no resolution code, so whether anyone faced real consequences remains, frustratingly, unknown.
The alleged misuse runs the full spectrum of human dysfunction:
- 2010: A customs officer pulled an Air New Zealand flight attendant’s data from government systems to contact them romantically
- 2013: An officer queried SENTRI—a trusted-traveler program storing detailed personal profiles of pre-screened border crossers—to ask people on dates
- 2016: OPR investigated allegations that a CBP employee was feeding database information directly to a drug-trafficking organization
- 2021: A Border Patrol agent allegedly queried which lane smugglers should use to avoid detection
- 2022: An employee reportedly used CBP databases to obtain an ex-husband’s leave schedule during a harassment campaign
At least six entries describe employees querying themselves—a behavior former OPR head Daniel Altman flags as a classic corruption precursor, historically used to test whether searches are being monitored.
That’s not curiosity. That’s reconnaissance.
“Customs and Border Protection has a long history of impunity and abuse of people’s civil and human rights… As our society adopts more AI, data collection, and surveillance tools, each of us becomes increasingly vulnerable.” — Laura Rivera, Just Futures Law.
A Surveillance Stack Built for Border Security – and Apparently Everything Else
The tools implicated in these allegations form one of the most expansive law-enforcement data ecosystems ever assembled.
CBP agents had access to:
- TECS — the watch-list system screening every border crosser
- FALCON — Palantir’s analytics platform connecting government and commercial records
- CLEAR — Thomson Reuters’ tool aggregating utility records and license-plate data
- Cellebrite — phone-extraction software that pulls data directly from seized devices, receiving over $56 million in federal contracts
- Mobile Fortify — a facial-recognition app released May 2025, deployed on agents’ phones and tied to databases containing hundreds of millions of passport photos
ICE and CBP have collectively spent roughly $515 million on products from Microsoft, Amazon, Google, and Palantir.
A 2023 DHS Inspector General report found CBP, ICE, and the Secret Service purchased commercial geolocation data—location information quietly harvested from everyday apps—in violation of their own privacy policies, with no DHS-wide governing policy in place as of April 2023. CBP told WIRED it “thoroughly investigates alleged or potential misconduct” and takes “appropriate investigatory, corrective, and disciplinary action.” Privacy laws, the agency noted, limit what it can say about individual cases.
The next time you hand over your passport, surrender your phone at the border, or open an app that pings your location—that data flows into systems which, for over a decade, were reportedly accessed for reasons that had nothing to do with national security.






























