Hundreds of Customs and Border Protection employees allegedly exploited government databases to conduct unauthorized lookups on romantic interests and colleagues, according to records obtained by WIRED.
The alleged misconduct involved CBP workers accessing internal tools to search personal information on individuals without legitimate law enforcement purposes. Some cases detailed tracking of cell phone locations and monitoring of colleagues' activities.
The records reveal a pattern of abuse spanning multiple CBP facilities, with incidents involving romantic surveillance, personal disputes, and workplace monitoring. The scope of the problem—documented in hundreds of allegations—suggests systemic issues in how access to sensitive databases is monitored and enforced.
CBP maintains extensive databases containing sensitive personal and biometric information collected at borders and through immigration processes. The allegations raise significant privacy and security concerns about internal controls governing employee access to these systems.
The discovery underscores ongoing challenges federal agencies face in preventing unauthorized database access, despite existing policies prohibiting misuse of law enforcement tools for personal reasons. The incident highlights the need for stronger oversight mechanisms and accountability measures within CBP operations.
WhatsApp has begun rolling out an optional "Scam Alert" feature that uses machine learning to detect and warn users about potential scam messages targeting them.
Taiwan's Ministry of Digital Affairs detected AI-assisted cyber-attacks targeting government agencies beginning July 20, marking what officials describe as a new threat category. The attacks reportedly originated overseas and have been characterized as a first-of-a-kind breach.
A data theft campaign exploits misconfigured Salesforce Experience Cloud and ServiceNow customer portals to harvest sensitive information. The attackers use custom tools to access data exposed to anonymous users.
A compromised AI package exposed credentials from 2,500 users in a large-scale supply-chain attack. Attackers scraped and exfiltrated terabytes of sensitive data.