CBP database misuse allegations documented in internal records describe employees and contractors allegedly using sensitive government information for personal purposes, including pursuing romantic interests, monitoring relatives and tracking coworkers. The files matter because they record allegations across more than a decade, while leaving a conspicuous gap on how often Customs and Border Protection proved misconduct or imposed penalties.
WIRED obtained the materials through Freedom of Information Act requests to CBP’s Office of Professional Responsibility and the Department of Homeland Security Office of Inspector General. The records cover 2009 through 2022 and reflect complaints, referrals and case classifications, not findings that each reported act occurred.
WIRED identified almost 300 entries concerning data-related allegations. Of those, 99 involved alleged data breaches or unauthorized disclosures, while 48 expressly concerned improper database searches. The supplied records do not identify the databases used in every allegation, name the people involved, or provide an overall substantiation rate.
What do the CBP database misuse records show?
The allegations range from personal snooping to possible disclosures of law-enforcement information. In one case described by WIRED, a CBP officer allegedly used government systems to get in touch with a flight attendant. Other personnel were accused of obtaining information from trusted-traveler applications to seek dates.
Another allegation involved sharing border-crossing information with a person caught up in a hostile divorce. A separate DHS employee was accused of using location data derived from advertising technology to follow several coworkers’ phones. WIRED reported that this appears to be the first known internal abuse case involving DHS use of that kind of location data.
At least six entries explicitly described employees searching for their own records. Daniel Altman, who led CBP’s Office of Professional Responsibility until leaving in 2025, told WIRED that the agency views self-searches as a potential early warning of misconduct, including possible testing of search monitoring or checking for an investigation. That is an agency assessment of risk, not proof that any self-query escalated.
How were the allegations handled?
At the time, complaints involving CBP personnel first went through the Joint Intake Center, now called the CBP Intake Center, and a shared CBP-Immigration and Customs Enforcement case-management system. Analysts could retain a complaint for information, send it to a manager, or refer it to Office of Professional Responsibility investigators.
- 138 entries were referred to CBP management for review.
- 78 were assigned to Office of Professional Responsibility criminal investigators.
- 43 were marked “Information Only,” meaning the office did not open its own investigation.
- 21 cases were withheld under an exemption for active law-enforcement proceedings.
Those routing decisions are not verdicts. A management referral does not establish wrongdoing, an assignment to criminal investigators does not establish a crime, and a withheld file does not disclose its outcome. The records also include smaller categories handled through management, law-enforcement-records cases, immediate management actions and one administrative inquiry.
Laura Rivera, an attorney with Just Futures Law, told WIRED that the allegations raise accountability concerns as border agencies use more surveillance tools. The disclosure establishes the breadth of allegations and the paths CBP used to handle them. It does not establish how many accusations were sustained, what discipline followed, or whether internal controls detected the alleged misuse before complaints reached the system.
This story draws on original reporting from WIRED.