CBP Workers Allegedly Used Government Databases to Spy on Exes, Crushes, and Colleagues
CBP Workers Allegedly Used Government Databases to Spy on Exes, Crushes, and Colleagues
美国海关及边境保卫局(CBP)员工被指利用政府数据库监视前任、暗恋对象及同事
Internal records obtained by WIRED reveal how, for years, United States Customs and Border Protection employees and contractors were accused of abusing sensitive government databases for reasons that had nothing to do with their jobs. The records contain hundreds of allegations of misuse of law enforcement databases, including federal agents querying data to look up romantic interests, monitor family members, expose various personal information and, in some cases, provide intelligence to suspected smugglers or drug-trafficking organizations.
《连线》(WIRED)获得的内部记录显示,多年来,美国海关及边境保卫局(CBP)的员工和承包商被指控滥用敏感的政府数据库,而这些行为与他们的工作毫无关系。这些记录包含了数百起关于滥用执法数据库的指控,其中包括联邦探员查询数据以搜索恋爱对象、监视家庭成员、泄露各种个人信息,甚至在某些情况下,为涉嫌走私者或贩毒组织提供情报。
Acquired through Freedom of Information Act requests to CBP’s Office of Professional Responsibility and the Department of Homeland Security’s Office of Inspector General, the records reveal the breadth of alleged database abuse by CBP employees spanning more than a decade. As immigration and border authorities expand their surveillance through facial recognition, license plate readers, mobile-device searches, and commercially purchased location information generated by ordinary apps, the sheer range of these records, which date from 2009 through 2022, highlights how US residents can be—and have been—targeted by federal government employees with access to highly sensitive data and powerful tools.
通过向CBP职业责任办公室和国土安全部监察长办公室提交《信息自由法》请求,这些记录揭露了CBP员工在过去十多年间滥用数据库的广泛程度。随着移民和边境管理部门通过人脸识别、车牌识别、移动设备搜索以及从普通应用程序购买的商业位置信息来扩大监控范围,这些记录(时间跨度从2009年到2022年)充分凸显了美国居民是如何——并且确实已经——成为那些拥有高度敏感数据访问权限和强大工具的联邦政府雇员的目标。
In one case, a CBP officer allegedly used government databases to contact a flight attendant. In another, an officer was accused of pulling information from trusted-traveler applications to ask people out. Other CBP employees were accused of providing border-crossing data to someone involved in a “heated divorce.” And yet another DHS employee allegedly used controversial ad-tech-derived location data to track several coworkers’ cell phones—which appears to be the first known internal abuse case involving DHS use of ad-tech-derived mobile location data.
在一个案例中,一名CBP官员被指利用政府数据库联系了一名空乘人员。在另一个案例中,一名官员被指控从“可信旅客”申请中提取信息以约会他人。其他CBP员工则被指控向处于“激烈离婚”纠纷中的人提供边境过境数据。还有一名国土安全部(DHS)员工被指利用极具争议的广告技术衍生位置数据来追踪几名同事的手机——这似乎是首例已知的涉及国土安全部使用广告技术衍生移动位置数据的内部滥用案件。
“Customs and Border Protection has a long history of impunity and abuse of people’s civil and human rights,” says Laura Rivera, an attorney with Just Futures Law, a civil and immigration advocacy legal organization. “Accountability for their wrongdoing has been elusive, and the dynamic involving the abuse of data is simply another aspect of that. As our society adopts more AI, data collection, and surveillance tools, each of us becomes increasingly vulnerable.”
“海关及边境保卫局长期以来一直存在有罪不罚以及侵犯公民和人权的行为,”民权与移民倡导法律组织“Just Futures Law”的律师劳拉·里维拉(Laura Rivera)表示。“对他们不当行为的问责一直难以实现,而涉及数据滥用的动态只是其中的另一个方面。随着我们的社会采用更多的人工智能、数据收集和监控工具,我们每个人都变得越来越脆弱。”
The 2009-2022 dataset shines light on what officers did with the access they already had prior to gaining even more access. According to CBP, digital surveillance tools are supposed to help officers screen travelers and investigate crimes more efficiently. The records, however, reveal how, in case after case, sensitive data collected for law-enforcement purposes was weaponized against private individuals.
这份2009年至2022年的数据集揭示了官员们在获得更多权限之前,是如何利用他们已有的权限进行操作的。据CBP称,数字监控工具旨在帮助官员更有效地筛查旅客和调查犯罪。然而,这些记录揭示了在多起案件中,为执法目的而收集的敏感数据是如何被武器化并针对普通个人的。
Breaches and Queries
违规与查询
At the time these allegations were made, complaints involving CBP personnel were initially routed through the Joint Intake Center, which has since been renamed the CBP Intake Center, and the Joint Intake Case Management System, which CBP and Immigration and Customs Enforcement still use for case tracking. Analysts decided whether each allegation should be retained for information, referred to an employee’s manager, or assigned to the Office of Professional Responsibility investigators as potentially serious misconduct.
在这些指控提出时,涉及CBP人员的投诉最初通过联合接收中心(现已更名为CBP接收中心)以及联合接收案件管理系统进行处理,该系统目前仍被CBP和移民及海关执法局(ICE)用于案件追踪。分析人员会决定每项指控是应作为信息保留、转交给员工的主管,还是作为潜在的严重不当行为分配给职业责任办公室的调查员。
Of the almost 300 data-related entries identified by WIRED, 138 were referred to CBP management for review, 78 were serious enough to be assigned to OPR criminal investigators, and 43 were classified as “Information Only,” meaning OPR did not open its own investigation. A smaller number fell into other categories: 12 misconduct allegations were sent for management review, where they were handled internally by the employees’ supervisors rather than by CBP’s central investigators; three were logged as “Law Enforcement Records” cases, meaning criminally investigated misconduct; two were logged as “Immediate Management Actions,” meaning minor misconduct resolved without opening a formal case; and only one as logged as an administrative inquiry, a formal fact-finding investigation conducted by CBP’s Office of Professional Responsibility. CBP withheld 21 cases, citing an exemption protecting active law-enforcement proceedings, suggesting criminal misconduct.
在《连线》确定的近300条与数据相关的记录中,138条被转交给CBP管理层进行审查,78条因情节严重被分配给职业责任办公室(OPR)的刑事调查员,43条被归类为“仅供参考”,意味着OPR未启动独立调查。另有少数案件属于其他类别:12起不当行为指控被送交管理层审查,由员工主管内部处理,而非由CBP中央调查员处理;3起被记录为“执法记录”案件,意味着涉及刑事调查的不当行为;2起被记录为“立即管理行动”,意味着无需立案即可解决的轻微不当行为;仅有1起被记录为行政调查,即由CBP职业责任办公室进行的正式事实调查。CBP扣留了21起案件,理由是保护正在进行的执法程序,这暗示了其中涉及刑事不当行为。
WIRED identified 99 entries involving alleged breaches or unauthorized disclosures of data and 48 explicitly involving improper database queries. Many of these cases happened around 2020, when the pandemic-prompted shift to remote work led CBP employees to start emailing work files to their personal accounts.
《连线》确定了99条涉及数据泄露或未经授权披露的记录,以及48条明确涉及不当数据库查询的记录。其中许多案件发生在2020年前后,当时疫情促使工作模式转向远程办公,导致CBP员工开始将工作文件通过电子邮件发送到个人账户。
At least six entries explicitly describe employees querying themselves. According to Daniel Altman, the former head of the Office of Professional Responsibility, who left his post in 2025, the agency treats self-queries as a warning sign of future misconduct. They often surface early in corruption cases either as a way for employees to test whether searches are monitored or to check if they themselves are under investigation. From there, escalation is just a matter of degree.
至少有6条记录明确描述了员工查询自己的信息。据2025年离职的前职业责任办公室负责人丹尼尔·奥特曼(Daniel Altman)称,该机构将“自我查询”视为未来不当行为的预警信号。它们通常在腐败案件的早期出现,要么是员工为了测试搜索是否受到监控,要么是为了检查自己是否正在接受调查。从那以后,事态的升级只是程度问题。
“Doing retroactive analysis helped us understand that pattern,” says Altman. “Historical analysis of corruption cases showed that self-querying was common across a significant number of them, pointing to it being an indicator of corruption in the future.”
“进行回顾性分析帮助我们理解了这种模式,”奥特曼说。“对腐败案件的历史分析表明,自我查询在相当多的案件中很常见,这表明它是未来腐败的一个指标。”
A Wide Range of Uses
广泛的用途
Several cases involve officers using database access to allegedly pursue or harass private citizens. In 2010, a customs officer allegedly pulled data on an Air New Zealand flight attendant and used it to contact them—a case that was referred to Labor and Employee Relations. In 2017, another officer faced a formal OPR investigation over allegations that he misused government databases to harass a different airline employee; the case’s resolution code was left blank in the records.
有几起案件涉及官员利用数据库访问权限骚扰或追求普通公民。2010年,一名海关官员被指提取了一名新西兰航空空乘人员的数据并利用其进行联系——该案件被转交给了劳工与员工关系部门。2017年,另一名官员因被指控滥用政府数据库骚扰另一名航空公司员工而面临OPR的正式调查;该案件在记录中的处理结果代码为空白。
In 2017, another officer was accused of querying his neighbors in federal computer databases. And in 2022, an employee allegedly used a CBP database to obtain an ex-husband’s leave schedule as part of a harassment campaign.
2017年,另一名官员被指控在联邦计算机数据库中查询其邻居的信息。2022年,一名员工被指利用CBP数据库获取前夫的休假时间表,作为骚扰活动的一部分。