Internal records obtained by WIRED reveal how, for years, United States Customs and Border Protection employees and contractors were accused of abusing sensitive government databases for reasons that had nothing to do with their jobs. The records contain hundreds of allegations of misuse of law enforcement databases, including federal agents querying data to look up romantic interests, monitor family members, expose various personal information and, in some cases, provide intelligence to suspected smugglers or drug-trafficking organizations.
Acquired through Freedom of Information Act requests to CBP’s Office of Professional Responsibility and the Department of Homeland Security’s Office of Inspector General, the records reveal the breadth of alleged database abuse by CBP employees spanning more than a decade. As immigration and border authorities expand their surveillance through facial recognition, license plate readers, mobile-device searches, and commercially purchased location information generated by ordinary apps, the sheer range of these records, which date from 2009 through 2022, highlights how US residents can be—and have been—targeted by federal government employees with access to highly sensitive data and powerful tools.
In one case, a CBP officer allegedly used government databases to contact a flight attendant. In another, an officer was accused of pulling information from trusted-traveler applications to ask people out. Other CBP employees were accused of providing border-crossing data to someone involved in a “heated divorce.” And yet another DHS employee allegedly used controversial ad-tech-derived location data to track several coworkers’ cell phones—which appears to be the first known internal abuse case involving DHS use of ad-tech-derived mobile location data.
“Customs and Border Protection has a long history of impunity and abuse of people’s civil and human rights,” says Laura Rivera, an attorney with Just Futures Law, a civil and immigration advocacy legal organization. “Accountability for their wrongdoing has been elusive, and the dynamic involving the abuse of data is simply another aspect of that. As our society adopts more AI, data collection, and surveillance tools, each of us becomes increasingly vulnerable.”
The 2009-2022 dataset shines light on what officers did with the access they already had prior to gaining even more access. According to CBP, digital surveillance tools are supposed to help officers screen travelers and investigate crimes more efficiently. The records, however, reveal how, in case after case, sensitive data collected for law-enforcement purposes was weaponized against private individuals.
Breaches and Queries
At the time these allegations were made, complaints involving CBP personnel were initially routed through the Joint Intake Center, which has since been renamed the CBP Intake Center, and the Joint Intake Case Management System, which CBP and Immigration and Customs Enforcement still use for case tracking. Analysts decided whether each allegation should be retained for information, referred to an employee’s manager, or assigned to the Office of Professional Responsibility investigators as potentially serious misconduct.
Of the almost 300 data-related entries identified by WIRED, 138 were referred to CBP management for review, 78 were serious enough to be assigned to OPR criminal investigators, and 43 were classified as “Information Only,” meaning OPR did not open its own investigation. A smaller number fell into other categories: 12 misconduct allegations were sent for management review, where they were handled internally by the employees’ supervisors rather than by CBP’s central investigators; three were logged as “Law Enforcement Records” cases, meaning criminally investigated misconduct; two were logged as “Immediate Management Actions,” meaning minor misconduct resolved without opening a formal case; and only one as logged as an administrative inquiry, a formal fact-finding investigation conducted by CBP’s Office of Professional Responsibility. CBP withheld 21 cases, citing an exemption protecting active law-enforcement proceedings, suggesting criminal misconduct.
WIRED identified 99 entries involving alleged breaches or unauthorized disclosures of data and 48 explicitly involving improper database queries. Many of these cases happened around 2020, when the pandemic-prompted shift to remote work led CBP employees to start emailing work files to their personal accounts.
At least six entries explicitly describe employees querying themselves. According to Daniel Altman, the former head of the Office of Professional Responsibility, who left his post in 2025, the agency treats self-queries as a warning sign of future misconduct. They often surface early in corruption cases either as a way for employees to test whether searches are monitored or to check if they themselves are under investigation. From there, escalation is just a matter of degree.




