Skip to main content

U.S. border agency says photos of travelers stolen in cyberattack

A “malicious cyberattack” on a U.S. Customs and Border Protection subcontractor compromised photographs of travelers going into and out of the country, along with license plates, the agency said Monday.

Customers and Border Protection has known about the attack since May 31. According to agency, a subcontractor transferred the images to its network “in violation of CBP policies and without CBP’s authorization or knowledge.”

The images include fewer than 100,000 people in vehicles entering and exiting the United States “through a few specific lanes at a single land border Port of Entry over a 1.5 month period,” according to a CBP spokesperson.

Officials claim that the stolen information hasn’t shown up on the internet or dark web. The Register found files from CBP contractor Perceptics, which makes license plate readers, on the dark web last month.

CBP hasn’t confirmed which of its contractors was attacked, so it’s not clear if the two incidents are connected.

The breach drew condemnation from privacy advocates, including the Electronic Frontier Foundation (EEF).

“EFF is disappointed by reports of the theft from CBP of photos of travelers’ faces and license plates,” said the organization’s senior staff attorney Adam Schwartz. “The inherent risk of such theft is among the reasons why the government should not be amassing this sensitive information in the first place.”

Initial reports reports were unclear about whether photos of travelers entering through airports were involved in the breach, but the CBP says passport and other travel document photos were not compromised, nor were images of airline passengers. When you arrive in the U.S. after an international flight, your stop at customs may include an agent snapping a photo of you. Using facial recognition technology, the agent can then match it with a “biometric template.” That template is a string of numbers representing, say, your passport photo.

“These templates are irreversible and cannot be reverse-engineered by anyone outside of CBP to reconstruct the photo,” according to the CBP.

Customers and Border Protection says it discards” photos of U.S. citizens and exempt aliens within 12 hours of verifying their identity. It can take 14 days to delete other travelers’ photographs. According to agency rules, airports and other partners aren’t allowed to keep any traveler photos they take for identification purposes.

The breach comes at a time when some airlines are planning on using facial recognition not just at customs but for flight check-in and baggage drop, The Washington Post reports.

There are some protections if your license plate information is stolen. While the Driver’s Privacy Protection Act makes it difficult to track down someone’s personal information just from a license plate, some privacy advocates have raised concerns about the amount of data automated plate readers suck up. 

The image quality will depend on whether vehicles at the border crossing had to stop and wait for long stretches due to lots of traffic, Dr. Jennifer King, director of privacy at Stanford’s Center for Internet and Society, told Digital Trends. As for how the images could be used, “It all depends on who stole it,” she said. Criminal hackers and foreign governments would have different motives and uses for the data.

“Having more data to feed into a facial recognition system is always useful, sadly, especially high-quality images taken for that purpose, to really try to focus on identifying people,” said King.

“We’re at the point where training data is hard to find, and getting good training data is invaluable in and of itself, even if it doesn’t ultimately lead to identification of individuals, for example, in the short term,” she added.

The CBP and federal authorities are investigating the breach and monitoring for the stolen information.

Update 6/11/2019: This story was updated to include new details about the amount and type of photographs stolen and to include remarks by Dr. Jennifer King. 

Jenny McGrath
Former Digital Trends Contributor
Jenny McGrath is a senior writer at Digital Trends covering the intersection of tech and the arts and the environment. Before…
These new chips could be good news for Copilot+ PCs
The Qualcomm Snapdragon X Plus

The first Copilot+ laptops are already out, powered by Qualcomm's impressive new Snapdragon X chip. The first batch of reviews were delayed, and early impressions have observed the hits and misses of the current chips. But a new leak tells us that Qualcomm might have another ace up its sleeve, and there may be hope for these Arm-based Copilot+ PCs yet. What's new? There might be more models of the chip than what we've been privy to so far.

So far, we've seen reviews of the Asus Vivobook S 15, but that's just one of several chips that fall under the Snapdragon X Elite umbrella. According to files for the Adreno GPU driver, there may be not just six, but 10 different models of the Snapdragon X -- and three of those are Plus chips, which we've previously only seen one of.

Read more
Hacker claims to have hit Apple days after hacking AMD
The Apple logo is displayed at the Apple Store June 17, 2015 on Fifth Avenue in New York City

Data breaches happen all the time, but when the giants get hit, it's impossible not to wonder what kind of critical data may become exposed. Earlier this week, notorious cybercriminal Intelbroker reported that they managed to hack AMD. Now, they followed up with claims about hacking Apple, and went as far as to share some internal source code on a hacking forum.

As Apple has yet to comment, all we have to go off is the forum post, first shared by HackManac on X (formerly Twitter). In the post, Intelbroker states that Apple suffered a data breach that led to the exposure of the source code for some of its internal tools. The tools include AppleConnect-SSO, Apple-HWE-Confluence-Advanced. There's been no mention of any customer data being leaked, which is good news, but there could still be some impact on Apple if this proves to be true.

Read more
OLED laptops are about to get brighter, thinner, and more expensive
A woman holds a laptop with the LG Tandem OLED logo on it.

LG's new Tandem OLED panel is entering mass production, which is good news for upcoming AI laptops. Today, LG announced that it's the first manufacturer to produce the Tandem OLED panel in a 13-inch variant, and the displays are said to be much thinner and lighter while delivering better performance. The catch? This screen upgrade, which is already available in the latest Dell XPS 13 Copilot+ PC, is going to cost you a pretty penny.

Tandem OLED is a display panel design that has mostly been used in cars up until now, and LG is breaking new ground by producing it for laptops. However, it's not the first time we've seen this design applied to consumer electronics, as Apple's M4 iPad Pros utilize Tandem OLED displays.

Read more