Critical Access Control Gaps at CBP Expose Sensitive Data, Risk Mission Operations
A Department of Homeland Security Inspector General report reveals critical access control failures at U.S. Customs and Border Protection, including a privileged service account accessible to all employees.

U.S. Customs and Border Protection (CBP) is grappling with significant cybersecurity deficiencies, including a critical failure in access control that left a privileged service account accessible to all of its over 76,000 employees. This alarming finding, detailed in a recent Department of Homeland Security (DHS) Office of Inspector General (OIG) report, exposes the agency to substantial risks that could disrupt its mission-critical operations and compromise sensitive data.
The DHS OIG initiated an audit in late 2024 to scrutinize CBP's implementation of IT access controls, aiming to identify weaknesses that could permit unauthorized access. The investigation uncovered that every employee within CBP's vast network possessed the ability to operate a service account with elevated privileges. This meant that any user could potentially alter credentials and security settings, a fundamental breach of secure access management principles.
Service accounts, often used for automated processes, are typically subject to stringent monitoring. However, the report highlights that CBP's oversight of these accounts was insufficient. The overprovisioning of even a single service account can serve as a lucrative entry point for attackers who have already gained a foothold in the network, enabling them to escalate privileges and cause widespread damage.
Further compounding the issue, the audit revealed that CBP struggled to accurately identify which of its accounts carried elevated privileges. This lack of a comprehensive inventory makes effective monitoring and management of privileged access virtually impossible, creating blind spots for security teams. The agency also failed to reliably revoke access for personnel who had departed the agency or moved to different roles, leaving dormant entitlements that could be exploited.
Investigators mapped over 100 potential attack paths within CBP's network environment, stemming from these access control vulnerabilities. The OIG has since mandated that CBP thoroughly analyze each identified path and eliminate unnecessary access privileges. The audit, which concluded in December 2025, involved extensive technical assessments and penetration testing.
CBP acknowledged that the lapses were attributed to human error and difficulties in tracking account access changes over time. The agency operates more than 100 major IT applications across 4,500 facilities, many of which handle sensitive law enforcement and biometric data crucial for border operations. These systems are prime targets for adversaries seeking to disrupt operations or steal valuable information.
While CBP stated it began addressing some of these issues during the audit, revoking excessive privileges and scanning for similar misconfigurations, the OIG kept one recommendation open. This pending recommendation requires CBP to demonstrate the practical implementation of new monitoring and response protocols. The agency reiterated its commitment to ensuring only authorized users access its systems.
This situation echoes similar findings from a September 2022 OIG report on U.S. Citizenship and Immigration Services, which also identified failures in access revocation, transfer verification, and service account management. The recurring nature of these findings underscores a persistent challenge in maintaining adequate internal controls and oversight within federal agencies, even years apart.