Internal records acquired by WIRED through Freedom of Information Act requests reveal that United States Customs and Border Protection employees and contractors were accused of abusing sensitive government databases for personal purposes over more than a decade. The documents contain hundreds of allegations in which federal agents queried law enforcement systems to look up romantic interests, track family members, expose personal information, and in some instances provide intelligence to suspected smugglers or drug-trafficking organizations. Spanning from 2009 through 2022, the records expose how US residents have been targeted by federal government employees with access to highly sensitive data and powerful surveillance tools.

Out of almost 300 data-related entries identified by WIRED, 138 were referred to CBP management for review, while 78 were serious enough to be assigned to Office of Professional Responsibility criminal investigators. Another 43 were classified as "Information Only," meaning OPR didn't open its own investigation. Twelve misconduct allegations were sent for management review and handled internally by the employees' supervisors rather than by CBP's central investigators, three were logged as "Law Enforcement Records" cases involving criminally investigated misconduct, and two were logged as "Immediate Management Actions" for minor misconduct resolved without opening a formal case. Only one was logged as an administrative inquiry, a formal fact-finding investigation conducted by CBP's Office of Professional Responsibility. CBP withheld 21 cases, citing an exemption protecting active law-enforcement proceedings, suggesting criminal misconduct. WIRED identified 99 entries involving alleged breaches or unauthorized disclosures of data and 48 explicitly involving improper database queries, with many of these cases happening around 2020 when the pandemic-prompted shift to remote work led CBP employees to start emailing work files to their personal accounts.

The records detail specific instances of abuse: in one case, a CBP officer allegedly used government databases to contact a flight attendant, while in another, an officer was accused of pulling information from trusted-traveler applications to ask people out. Other CBP employees were accused of providing border-crossing data to someone involved in a "heated divorce," according to the documents. In what appears to be the first known internal abuse case involving DHS use of ad-tech-derived mobile location data, a DHS employee allegedly used controversial ad-tech-derived location information to track several coworkers' cell phones. At least six entries explicitly describe employees querying themselves, which Daniel Altman, the former head of the Office of Professional Responsibility who left his post in 2025, told WIRED the agency treats as a warning sign of future misconduct. According to Altman, self-queries often surface early in corruption cases either as a way for employees to test whether searches are monitored or to check if they're under investigation themselves.

The dataset shines light on what officers did with the access they already had before gaining even more access, as immigration and border authorities expand their surveillance through facial recognition, license plate readers, mobile-device searches, and commercially purchased location information generated by ordinary apps. While CBP states that digital surveillance tools are supposed to help officers screen travelers and investigate crimes more efficiently, the records reveal how, in case after case, sensitive data collected for law-enforcement purposes was weaponized against private individuals. Laura Rivera, an attorney with Just Futures Law, a civil and immigration advocacy legal organization, says "Customs and Border Protection has a long history of impunity and abuse of people's civil and human rights," adding that "accountability for their wrongdoing has been elusive, and the dynamic involving the abuse of data is simply another aspect of that."

The records expose a pattern of database misuse that stretches across more than a decade, raising questions about oversight as surveillance capabilities continue to expand. As border authorities gain access to increasingly sophisticated tracking technologies and commercially available data streams, the historical pattern of abuse documented in these cases suggests existing safeguards haven't been sufficient to prevent personal misuse of sensitive information. For organizations evaluating partnerships with federal agencies or deploying their own surveillance infrastructure, these findings illustrate how even purpose-built enforcement tools can be redirected toward ends that undermine both institutional credibility and individual privacy. The tension between operational necessity and oversight capacity will likely sharpen as data access becomes both easier and more consequential.