HomeMalware & ThreatsWatchdog Discovers Major Access Control Gaps at CBP

Watchdog Discovers Major Access Control Gaps at CBP

Published on

spot_img

Governance & Risk Management,
Identity & Access Management,
Risk Assessments

DHS Inspector General Finds CBP Left Privileged Account Open to All Network Users

Watchdog Discovers Major Access Control Gaps at CBP
Image: Tada Images/Shutterstock

A recent report by the Department of Homeland Security Office of Inspector General (DHS OIG) has raised significant concerns regarding security practices at U.S. Customs and Border Protection (CBP). The audit, initiated in late 2024, aimed to evaluate the agency’s implementation of information technology access controls designed to safeguard sensitive systems and information. The findings reveal that CBP is failing to enforce fundamental cybersecurity measures, leaving its network vulnerable to potential breaches that could disrupt essential operations.

The DHS OIG discovered that every employee within CBP, numbering over 76,000, possessed access to a service account that carried elevated privileges. This lack of proper access control poses a severe security risk, allowing unauthorized users to manipulate credentials and security settings. According to the report, “We identified multiple access control vulnerabilities, which could allow an attacker to compromise CBP’s network, gain access to sensitive information, and disrupt mission-critical operations.”

Service accounts, utilized for automated processes, are generally scrutinized less rigorously than human accounts, contributing to an atmosphere of lax oversight. Thus, a single compromised service account could provide an entry point for cybercriminals to cause significant disruption within the network. Alarmingly, the investigation revealed that CBP often struggled to identify which accounts had elevated privileges, further complicating monitoring and risk assessment.

The report also highlighted the failure of CBP to adequately revoke access privileges when personnel transitioned out of the agency or changed roles. This oversight resulted in former employees retaining access to systems for which they no longer had a valid need, thereby increasing the potential for insider threats. The DHS OIG traced more than 100 possible attack vectors throughout the organization and instructed CBP to effectively analyze and mitigate unnecessary access vulnerabilities.

The audit, which concluded in December 2025, included extensive technical evaluations and penetration tests. CBP attributed these critical lapses to human error and an inability to track modifications in account access over time, showcasing glaring deficiencies in internal oversight and operational procedures.

CBP oversees a broad range of IT applications—over 100 major systems across 4,500 facilities. Many of these applications contain sensitive law enforcement and biometric data that could be compelling targets for cyber attackers aiming to disrupt essential functions or acquire confidential information. The report emphasized the gravity of the situation, noting that these systems qualify as “high-visibility targets” for cyber threats.

In response to the audit findings, CBP indicated that it had initiated efforts to rectify some identified issues even while the review was ongoing. The agency reported that it had started to revoke excessive privileges associated with certain accounts and conducted scans to identify other instances of similar misconfigurations. Although the Inspector General acknowledged these measures and closed one recommendation, it left another open for further evaluation, pending evidence of effective implementation of new monitoring and alerting protocols.

CBP reassured stakeholders of its commitment to ensuring that only authorized users are granted access to vital systems and information. However, the issue of inadequate access control is not isolated; similar findings were reported concerning U.S. Citizenship and Immigration Services (USCIS) in a prior audit, highlighting systemic deficiencies that extend beyond CBP.

The USCIS review from September 2022 pointed out that the agency also failed to consistently revoke access for departing personnel and lacked robust processes for monitoring service accounts. These recurring issues suggest a pressing need for comprehensive reforms and tighter internal controls within CBP and its affiliated agencies.

Additionally, the scrutiny of CBP’s traveler-facing technologies has reported past failings as well. A 2021 IG review found that CBP had not adequately secured its Mobile Passport Control applications, exposing travelers’ personal information to potential misuse—a sign that the agency’s cybersecurity practices require immediate enhancement at multiple levels.

Source link

Latest articles

Why Hostile State Cyber Activity Is Now a Daily Business Risk

Growing Cyber Security Threats Linked to Geopolitical Escalation: A Wake-Up Call for Businesses Christopher Clark,...

Microsoft Breaks Patch Tuesday Record with 974 CVE Fixes in September

Microsoft recently unveiled a significant update during its September 2026 Patch Tuesday, which included...

State CIOs Require an Enterprise Identity Strategy

Balancing Security, Privacy, and Citizen Access: Insights from NASCIO’s Eric Sweden In an era where...

Jellyfin 12.0 Introduces Security Fixes

Jellyfin Unveils Version 12.0, Addressing Major Security Vulnerabilities Jellyfin, the open-source media server platform, has...

More like this

Why Hostile State Cyber Activity Is Now a Daily Business Risk

Growing Cyber Security Threats Linked to Geopolitical Escalation: A Wake-Up Call for Businesses Christopher Clark,...

Microsoft Breaks Patch Tuesday Record with 974 CVE Fixes in September

Microsoft recently unveiled a significant update during its September 2026 Patch Tuesday, which included...

State CIOs Require an Enterprise Identity Strategy

Balancing Security, Privacy, and Citizen Access: Insights from NASCIO’s Eric Sweden In an era where...