Advertisement

Customs says hack exposed traveler and license plate images

Customs and Border Protection said photos of travelers and license plates have been exposed in a malicious cyberattack.
(Gerald Herbert / Associated Press)
Share via

Customs and Border Protection is reporting that photos of travelers and license plates collected at a single U.S. border point have been exposed in a malicious cyberattack in what a leading congressman called a “major privacy breach.”

The federal agency did not name the subcontractor whose computer network was hacked, but the announcement Monday followed news that a Tennessee-based company that bills itself as the sole provider of stationary license plate readers at U.S. borders had been compromised.

A Customs and Border Protection spokesman said initial reports indicated that the images involved fewer than 100,000 people; photographs were taken of travelers in vehicles entering and exiting the United States at a single land-border port of entry over one and a half months.

Advertisement

Automated license-plate readers are used for “detecting, identifying, apprehending, and removing individuals illegally entering the United States at and between ports of entry or otherwise violating U.S. law,” the Department of Homeland Security says in a December 2017 privacy document. Recorded license plates are checked in real time against DHS databases to which 13 federal agencies have access.

The British computer security website The Register, which said the hacker responsible alerted it to the breach in late May, identified the company as Perceptics. A spokesman for the company did not immediately respond to an email from the Associated Press seeking comment.

Customs and Border Protection said none of the data had surfaced on the internet or dark web. The Register said the hacker provided it with a list of files exfiltrated from the Perceptics corporate network and said a company spokesperson had confirmed the hack.

Advertisement

“Initial information indicates that the subcontractor violated mandatory security and privacy protocols outlined in their contract,” Customs and Border Protection said in a statement.

The agency said it learned of the data breach May 31. It said the subcontractor had transferred copies of the images to its company network in violation of government policies and without the agency’s authorization.

No Customs and Border Protection networks or databases were breached, the agency spokesman said.

Advertisement

The chairman of the House Homeland Security Committee, Rep. Bennie Thompson (D-Miss.), noted with alarm that this is the “second major privacy breach at DHS this year.”

“We must ensure we are not expanding the use of biometrics at the expense of the privacy of the American public,” he said in a statement.

In March, the Homeland Security Department’s inspector general announced that another of its subdivisions, the Federal Emergency Management Agency, had wrongly released to a contractor the personal information of 2.3 million survivors of devastating 2017 hurricanes and wildfires, potentially exposing those affected to identity theft and fraud.

Advertisement