Border Agents Turned Surveillance Tools Into Personal Spyware
Freedom of information records reveal a pattern of database abuse inside US Customs and Border Protection, from stalking dates to aiding smugglers

The Scope of Internal Abuse
Over 300 incidents of database misuse by US Customs and Border Protection personnel emerged from freedom of information requests covering more than a decade, painting a troubling picture of how frontline agents exploit the surveillance infrastructure they control. The cases span from 2009 to 2022 and reveal officers turning tools designed for border security into instruments of personal curiosity, romantic pursuit, and in at least one alleged case, criminal conspiracy.
Among the documented incidents: an officer used government systems to contact a flight attendant whose information passed through their hands, while another mined trusted-traveler program applications to ask individuals out on dates. One employee handed border-crossing records to someone embroiled in a divorce. Another tracked coworkers' cellphones using location data harvested from the advertising-technology ecosystem, a practice that violated internal policy even as it remained technically accessible.
The most serious allegation involves an officer accused of providing border-crossing intelligence to individuals suspected of drug trafficking. That case underscores how surveillance systems built for national security can become vectors for exactly the criminal activity they are meant to prevent.
How Enforcement Becomes Voyeurism
The databases CBP officers can access represent one of the most comprehensive surveillance assemblages in the world. Immigration arrest records, border screening logs, naturalization applications, and the SENTRI trusted-traveler program create a detailed mosaic of movement and identity. Officers also have access to Palantir's ICM and FALCON analytic platforms, which synthesize data across agencies, and the DHS Mobile Fortify facial-recognition app deployed directly on agents' phones.
These tools pull from license plate readers, facial recognition cameras, and smartphone forensic searches conducted at ports of entry. The result is a system that can reconstruct travel patterns, social networks, and personal histories with a few queries. When that power sits in the hands of thousands of officers working shifts at airports, seaports, and land crossings, the potential for misuse scales with access.
At DailyTechWire, we've tracked the expansion of border surveillance infrastructure across Asia and the Americas over the past five years. What distinguishes the US system is not the technology itself, much of which is commercially available and deployed from Seoul to São Paulo, but the breadth of data sources it federates and the relatively weak oversight mechanisms governing day-to-day access.
The Enforcement Gap
Of the 300 incidents documented, 138 were referred to CBP management for review, and 78 reached criminal investigators. Forty-three cases were not investigated at all. Many allegations were classified as minor misconduct and handled through internal channels, a designation that often means counseling or reprimand rather than termination or prosecution.
Twenty-one cases, however, remain withheld from public disclosure due to ongoing or potential law-enforcement proceedings. That category suggests criminal conduct serious enough to warrant prosecution, though the details remain sealed. The gap between the number of incidents and the number of serious consequences raises questions about how the agency weighs employee privacy violations against the operational convenience of retaining trained personnel in a workforce that is chronically understaffed.
CBP maintains that it takes misconduct allegations seriously and pursues investigatory and disciplinary action where warranted. The agency told reporters it works to uphold accountability and the rule of law. Yet the pattern revealed in the freedom of information files suggests that internal controls are either insufficient to deter abuse or too slow to catch it before damage occurs.
Why Surveillance Creep Matters at the Border
The incidents documented in these files are not outliers in a vacuum. They occur within a broader context where the Department of Homeland Security has accumulated more data on private citizens than at any point in its history. Border agencies operate in a legal gray zone where Fourth Amendment protections are attenuated, and the threshold for searches, seizures, and data collection is lower than it would be elsewhere in the country.
That creates an environment where officers have extraordinary access and minimal friction. A query that would require a warrant in another context can be executed in seconds at a border checkpoint. The same tools that identify smugglers or flag visa overstays can just as easily surface a coworker's location or a stranger's phone number.
The risk is not hypothetical. When officers use surveillance systems for personal gain or pass intelligence to criminal networks, they undermine the legitimacy of the entire apparatus. They also create operational security risks, exposing investigative methods and data sources to adversaries who can then route around them.
The Broader Implications for Tech and Policy
Border surveillance is a laboratory for technologies that eventually diffuse into other domains. Facial recognition, mobile device forensics, and ad-tech-derived location tracking all saw early adoption in immigration and customs enforcement before spreading to local policing, corporate security, and even retail. The misuse patterns documented at CBP offer a preview of what can go wrong when powerful analytic tools are deployed at scale without robust access auditing or meaningful penalties for abuse.
Palantir's platforms, which power much of CBP's data integration, are now used by governments and enterprises across Asia, Europe, and Latin America. The same smartphone forensic tools that border agents carry are sold to police forces in dozens of countries. The question is whether those deployments will learn from the accountability failures visible in the US system or repeat them.
At DailyTechWire, we've observed that jurisdictions with stronger data-protection regimes, such as the EU under GDPR or South Korea under its Personal Information Protection Act, impose more stringent logging and audit requirements on government databases. Those rules don't eliminate abuse, but they make it harder to hide and easier to prosecute. The US border surveillance system, by contrast, operates with a lighter regulatory touch and a culture that has historically prioritized operational speed over privacy safeguards.
What Happens Next
The freedom of information disclosures are likely to fuel calls for stronger oversight, both from civil liberties advocates and from lawmakers concerned about the integrity of border operations. Proposals under discussion in Congress include mandatory access logging, third-party audits of database queries, and harsher penalties for misuse, including criminal prosecution for officers who sell or share data for personal benefit.
Technology vendors, including Palantir, face pressure to build more granular access controls and audit trails into their platforms. Some of that pressure comes from customers in other regions who require those features by law. If CBP wants to maintain interoperability with allied agencies in Europe or Asia, it may need to adopt stricter standards even in the absence of domestic regulation.
For now, the cases documented in the FOIA files remain a snapshot of a system under strain. They reveal the gap between the surveillance capabilities the US government has built and the institutional discipline required to wield them responsibly. That gap is not unique to borders or to the United States, but it is unusually visible here, and the consequences extend far beyond the individuals whose privacy was violated.


