Governance & Risk Management,
Identity & Access Management,
Risk Assessments
DHS Inspector General Finds CBP Left Privileged Account Open to All Network Users

A recent report by the Department of Homeland Security Office of Inspector General (DHS OIG) has raised significant concerns regarding security practices at U.S. Customs and Border Protection (CBP). The audit, initiated in late 2024, aimed to evaluate the agency’s implementation of information technology access controls designed to safeguard sensitive systems and information. The findings reveal that CBP is failing to enforce fundamental cybersecurity measures, leaving its network vulnerable to potential breaches that could disrupt essential operations.
The DHS OIG discovered that every employee within CBP, numbering over 76,000, possessed access to a service account that carried elevated privileges. This lack of proper access control poses a severe security risk, allowing unauthorized users to manipulate credentials and security settings. According to the report, “We identified multiple access control vulnerabilities, which could allow an attacker to compromise CBP’s network, gain access to sensitive information, and disrupt mission-critical operations.”
Service accounts, utilized for automated processes, are generally scrutinized less rigorously than human accounts, contributing to an atmosphere of lax oversight. Thus, a single compromised service account could provide an entry point for cybercriminals to cause significant disruption within the network. Alarmingly, the investigation revealed that CBP often struggled to identify which accounts had elevated privileges, further complicating monitoring and risk assessment.
The report also highlighted the failure of CBP to adequately revoke access privileges when personnel transitioned out of the agency or changed roles. This oversight resulted in former employees retaining access to systems for which they no longer had a valid need, thereby increasing the potential for insider threats. The DHS OIG traced more than 100 possible attack vectors throughout the organization and instructed CBP to effectively analyze and mitigate unnecessary access vulnerabilities.
The audit, which concluded in December 2025, included extensive technical evaluations and penetration tests. CBP attributed these critical lapses to human error and an inability to track modifications in account access over time, showcasing glaring deficiencies in internal oversight and operational procedures.
CBP oversees a broad range of IT applications—over 100 major systems across 4,500 facilities. Many of these applications contain sensitive law enforcement and biometric data that could be compelling targets for cyber attackers aiming to disrupt essential functions or acquire confidential information. The report emphasized the gravity of the situation, noting that these systems qualify as “high-visibility targets” for cyber threats.
In response to the audit findings, CBP indicated that it had initiated efforts to rectify some identified issues even while the review was ongoing. The agency reported that it had started to revoke excessive privileges associated with certain accounts and conducted scans to identify other instances of similar misconfigurations. Although the Inspector General acknowledged these measures and closed one recommendation, it left another open for further evaluation, pending evidence of effective implementation of new monitoring and alerting protocols.
CBP reassured stakeholders of its commitment to ensuring that only authorized users are granted access to vital systems and information. However, the issue of inadequate access control is not isolated; similar findings were reported concerning U.S. Citizenship and Immigration Services (USCIS) in a prior audit, highlighting systemic deficiencies that extend beyond CBP.
The USCIS review from September 2022 pointed out that the agency also failed to consistently revoke access for departing personnel and lacked robust processes for monitoring service accounts. These recurring issues suggest a pressing need for comprehensive reforms and tighter internal controls within CBP and its affiliated agencies.
Additionally, the scrutiny of CBP’s traveler-facing technologies has reported past failings as well. A 2021 IG review found that CBP had not adequately secured its Mobile Passport Control applications, exposing travelers’ personal information to potential misuse—a sign that the agency’s cybersecurity practices require immediate enhancement at multiple levels.

