One CBP agent used a government database to look up a flight attendant's contact information. Another leveraged trusted-traveler application data just to ask someone out. This isn't office gossip fiction—it's real, according to internal Freedom of Information Act (FOIA) files obtained by Wired from U.S. Customs and Border Protection (CBP).
Spanning from 2009 to 2022, these files reveal that CBP agents repeatedly abused internal systems capable of pulling license plate recognition, facial recognition, and smartphone data—for purposes both wildly varied and deeply personal. Some handed over entry/exit records to individuals in the middle of divorce proceedings, while others used location data derived from ad-tech to track coworkers' phone movements.
Of the 300 related incidents Wired tracked, 138 were referred to CBP's internal management for handling, 78 were passed to criminal investigators, and 43 were never investigated at all. Most cases were ultimately classified as minor misconduct and handled internally, but 21 were flagged as reserved cases due to potential involvement of law enforcement proceedings—meaning these were the only ones truly considered to carry possible criminal liability.
Wired notes this report matters because the Department of Homeland Security (DHS) now holds a scale of personal data unprecedented in its history, with a surveillance apparatus ranking among the largest in the world. Data sources span immigration arrest records, border screening data, naturalization applications, and the SENTRI trusted-traveler program. CBP agents also have access to Palantir's ICM and FALCON systems, and front-line agents carry the DHS Mobile Fortify facial recognition app on their phones.
In response, CBP told Wired that the agency takes all misconduct allegations seriously, stating it is "committed to maintaining the rule of law and holding itself accountable... and takes appropriate investigative, corrective, and disciplinary action."






