CBP agents used federal databases to stalk exes and ask out flight attendants — leaked records reveal years of abuse

12 Min Read

A Customs and Border Protection officer ran a government database search on a woman he’d met at a bar. Another used federal tools to track his ex-girlfriend’s cell phone location. A third shared intelligence with a smuggler in exchange for cash. These weren’t isolated incidents—they were part of a pattern spanning years, documented in hundreds of internal allegations that WIRED obtained and reviewed.

The leaked records paint a picture of a federal agency where access to some of America’s most sensitive surveillance databases went largely unchecked, where romantic rejection could trigger a background investigation, and where the same tools meant to catch criminals at the border were repurposed as personal tracking instruments. For a decade or more, CBP workers exploited their privileged access to look up romantic interests, monitor colleagues, and in at least one documented case, share classified intelligence with criminal networks.

Key Findings:
  • The Scale of Abuse: Hundreds of internal allegations document CBP officers using federal surveillance databases to track romantic interests, monitor ex-partners, and conduct unauthorized personal searches over a period spanning at least a decade.
  • The Database at Risk: TECS, CBP’s primary law-enforcement system, integrates data from the FBI, DEA, Interpol, and international intelligence partners — giving any officer with access a comprehensive profile of any individual who has crossed a U.S. border.
  • The Accountability Gap: Internal audit trails existed but were not systematically reviewed; some officers were fired, others suspended, and many cases appear to have resulted in no documented disciplinary action at all.

The scale is staggering. WIRED’s review of the records details hundreds of allegations — cases where CBP employees accessed the Treasury Enforcement Communications System (TECS), the agency’s primary law-enforcement database, to pull personal information on people they knew. One agent searched for a flight attendant he wanted to ask out. Another looked up an ex-partner’s travel records. A third ran queries on a woman after she rejected his advances at a social gathering.

What makes these abuses possible is the structure of federal surveillance infrastructure itself. TECS contains decades of border crossing records, travel history, financial transactions, and intelligence reports. CBP officers need access to investigate smuggling, money laundering, and national security threats. But the system, according to the leaked records, relied on audit trails and internal discipline rather than technical restrictions. An officer could pull up anyone’s travel history. The system would log it. And then, in many cases documented in these records, nothing happened. This structural vulnerability — broad access paired with weak enforcement — is precisely the kind of systemic failure that surveillance infrastructure critics have warned about for years.

Why Does Access Without Accountability Enable Systemic Abuse?

The pattern echoes a structural vulnerability that defined the Cambridge Analytica scandal: access without accountability. In 2018, it emerged that Cambridge Analytica had harvested personal data on millions of Facebook users without consent, using behavioral and demographic information to build psychological profiles and target voters with micro-tailored messages. The scandal wasn’t just about the data theft — it was about the absence of meaningful friction between access and misuse. Facebook’s developers could see the vulnerability; the company’s incentive structure didn’t penalize exploitation. Similarly, CBP officers had access to TECS queries; the agency’s audit and discipline systems apparently didn’t deter misuse at scale. The technology enabled the abuse, but the organizational culture permitted it. A detailed examination of how that dynamic continues to shape digital systems is explored in Cambridge Analytica’s legacy.

One case in the leaked records is particularly stark. A CBP officer at the southern border shared classified intelligence with a smuggler — a direct breach of national security protocol. The officer received cash in return. This wasn’t curiosity or romantic interest; it was corruption enabled by access. But it also suggests something deeper: if officers felt comfortable sharing intelligence with criminals for profit, what friction existed to stop them from running queries on exes or crushes?

By the Numbers:
• TECS integrates records from the FBI, DEA, Interpol, and multiple international intelligence partners — making it one of the most comprehensive personal data repositories accessible to front-line federal officers
• Hundreds of internal allegations were documented across multiple CBP field offices spanning at least a decade, according to WIRED’s review of the leaked records
• Disciplinary outcomes were inconsistent: some officers were terminated, others suspended, and many cases show no documented consequence

The records obtained by WIRED span multiple years and multiple CBP field offices. They include internal investigation summaries, disciplinary notices, and case files. Some officers were fired. Others received suspensions. Many cases appear to have resulted in no documented action at all. The leaked documents don’t specify exact dates for all incidents, but they cover a period of at least a decade, suggesting the problem was neither recent nor isolated.

What Information Can a CBP Officer Actually See?

What’s particularly revealing is the type of information officers accessed. TECS isn’t just a border crossing log. It integrates data from the FBI, DEA, Interpol, and international intelligence partners. An officer looking up a romantic interest could theoretically see financial records, prior arrests, travel patterns, and intelligence reports. The tool is designed for law enforcement. It’s not designed for personal surveillance. But once an officer has legitimate access, the database doesn’t distinguish between a query that’s investigating a smuggling ring and one that’s tracking an ex-partner’s location.

CBP has not publicly released a comprehensive statement about the scope of the abuse or the reforms implemented in response. The agency did not respond to WIRED’s requests for comment on the leaked records. What we know comes from the internal documents themselves — a paper trail of misconduct that was documented, in some cases investigated, but apparently not systematized into agency-wide policy reform.

What Security Standards Require:
NIST Special Publication 800-53, the federal government’s primary security and privacy control framework, mandates access enforcement, least-privilege principles, and audit log review — controls that the CBP incidents suggest were not consistently applied
• The framework explicitly requires agencies to restrict information system access to authorized users and to the types of transactions and functions those users are permitted to execute
NIST’s Computer Security Resource Center identifies insider threat detection and privileged access management as foundational requirements for federal systems handling sensitive law-enforcement data

Is Your Border Crossing Data Exposed to Unauthorized Searches?

For any reader who has crossed a U.S. border, the implications are direct. Your travel record is in TECS. Your financial transactions, if they triggered any law-enforcement interest, may be flagged there. Your cell phone location, if you were traveling internationally, could be logged. And if a CBP officer with access to that database decides to look you up — whether because they know you, want to know you, or simply feel curious — the technical barriers to that search are minimal. The only real barrier is organizational discipline and the risk of getting caught.

The leaked records suggest that organizational discipline was inconsistent at best. Some officers were caught and fired. Others appear to have operated for years without documented consequences. The audit trail existed, but it wasn’t being reviewed systematically. It’s the surveillance equivalent of a security camera that records everything but is never watched. The broader question of how personal databases become high-value targets for both internal abuse and external attack is examined in depth in the analysis of voter databases as hacking targets — a parallel case where sensitive personal records outpaced the security frameworks meant to protect them.

What Technical Controls Could Actually Stop This?

This is where the Cambridge Analytica parallel becomes urgent. That scandal revealed how data access without accountability creates a moral hazard. When the cost of misusing data is low — when the chance of detection is uncertain, when penalties are inconsistent, when the culture normalizes “just looking” — people misuse data. Facebook’s engineers could access user data; some did, and the company’s response was slow. CBP officers could access TECS; many did, for reasons that had nothing to do with law enforcement, and the agency’s response was scattered.

The question now is whether CBP will implement technical controls — requiring supervisory approval for certain queries, restricting access to specific fields based on the officer’s assigned duties, real-time alerting when searches match personal contacts. Some agencies have implemented these. CBP apparently has not, at least not at scale, based on the incidents documented in these leaked records. Research on cybersecurity frameworks for government systems consistently identifies privileged access management and automated anomaly detection as the most effective deterrents against insider misuse — precisely the controls that appear absent from CBP’s documented response.

Expert Analysis:
• Security researchers and policy analysts consistently identify the insider threat as the most underaddressed vulnerability in government database systems — not because the technical solutions are unavailable, but because implementing them requires acknowledging the scale of the problem
• Least-privilege access architecture — where officers can only query data fields directly relevant to their assigned duties — is a well-established mitigation that federal standards bodies have recommended for years
• Without real-time audit review and automated flagging of anomalous query patterns, audit logs function as a forensic tool after harm has occurred rather than a deterrent against it

Until that changes, every border crossing you make, every international flight you take, every financial transaction that triggers law-enforcement interest, becomes a data point that a federal officer can access on a whim. The tools are there. The access is there. The only thing standing between your travel history and a stranger’s curiosity is a policy that, according to leaked internal records, hasn’t been enforced consistently for over a decade.

Share This Article
Miora Danielle Raveloarison is a journalist at CA Privacy Watch covering surveillance, data privacy and the human impact of technology. A graduate of the Catholic University of Madagascar with a background in the social sciences, she has spent over a decade turning complex subjects into clear, engaging reporting, and brings a humanistic lens to questions of privacy, AI and digital rights.