DHS watchdog finds numerous problems with Customs and Border Protection's data security, including leaving data copied from traveler's devices on thumb drives
Matt Novak / Gizmodo :
Context & Ripple Effects
The December 2018 DHS inspector general finding that CBP left data copied from travelers' devices sitting on thumb drives lands nine months after an earlier watchdog report flagged agency computers running outdated operating systems without patches for years — a documented pattern of basic hygiene failures at the same agency expanding biometric collection at the border.
That pattern hardened into consequence: in mid-2019 CBP disclosed that traveler photos were accessed through a hacked subcontractor, sensitive DHS documents leaked alongside them, and the agency eventually admitted 184,000 facial-recognition pilot photos were stolen from that same subcontractor, with some surfacing on the dark web. The thumb-drive finding is the internal-controls half of a story whose external half played out over the following two years.
First-order effects
- Travelers whose devices were searched at the border are directly exposed: copied device contents left on unencrypted thumb drives means seizure data was handled outside any audited system, with no stated scope of who was affected.
- CBP leadership inherits concrete remediation work — device-copying procedures, media handling, and patching — under an inspector general already tracking whether promised fixes land.
Second-order effects
- The breach chain runs through vendors, not CBP itself: the subcontractor whose systems leaked traveler photos was later barred from federal contracting, so every border-surveillance contractor now faces procurement-level scrutiny of its own security as a condition of doing border work.
- Each new OIG finding raises the evidentiary bar for CBP's biometric expansion — Congress and privacy litigants can cite a documented controls record when weighing whether more traveler data should be collected at all.
Third-order effects
- If the cycle holds — collection expands, a watchdog finds gaps, a vendor leaks — DHS's structural problem is that data custody is distributed across subcontractors faster than oversight can certify them, making third-party assurance the binding constraint on border-tech programs rather than CBP's own systems.
- The recurring OIG reports into the 2020s, including later findings on unmanaged apps on ICE devices, point toward inspector-general findings becoming the de facto audit regime for DHS technology — shaping budgets and program approvals even where formal regulation lags.
The trend: DHS's border-data programs are expanding biometric collection faster than the agency and its subcontractors can secure it, with inspector-general findings serving as the main check on that gap.