A contractor leaves U.S. Customs and Border Protection with a password and access to a database full of biometric information, border patrol reports, and personally identifiable information. Because of a systemic process failure, that contractor can still log in months later. And CBP didn’t catch it—a federal audit did.
Fifteen percent of contractors who separated from CBP retained active access to the agency’s computer systems after leaving, according to a Department of Homeland Security Office of Inspector General audit released September 4, 2026. Among federal employees who transferred to new positions within CBP, 17 percent kept access they no longer needed.
The most alarming finding: 86 percent of the transferred employees with unneeded access came from CBP’s most sensitive offices—the Office of Intelligence, U.S. Border Patrol, Office of Field Operations, and Office of Air and Marine Operations—meaning they retained access to systems containing “highly sensitive systems containing national security and personally identifiable information.”
The audit, titled “CBP’s IT Access Control Deficiencies Introduced Critical Risk to IT Systems and Sensitive Information” (OIG-26-28), reveals a cascading failure in CBP’s account management process where supervisors and contracting officers fail to properly document separations and transfers, leaving hundreds of people with passwords to systems they should no longer be able to access.
How the System is Supposed to Work
CBP’s established process for account disablement after an employee or contractor leaves is straightforward: A supervisor or contracting officer should create a separation notification record in the Employee Separation System or Contractor Tracking System once they’re aware of the separation. That system then automatically notifies CBP’s centralized Access Management System (AMS), which disables the account on the separation effective date.
DHS policy requires accounts be disabled within 3 days of separation.
For transferred employees, the process is similar. The departing supervisor creates a transfer record, and the AMS automatically removes the employee’s old system access on the transfer date, while preserving access needed for their new position.
On paper, it works. In practice, it collapses under the weight of CBP’s size and bureaucratic friction.
Where the Process Breaks Down
The audit examined separations and transfers that occurred in fiscal years 2023 and 2024. The findings show systematic non-compliance at nearly every step.
For separated employees: Supervisors didn’t create separation notifications in a timely manner. The OIG sampled 365 employees who separated in FY 2023-2024 and found 72 (20 percent) had accounts that were not disabled promptly after they left. Among contractors, the problem was worse: 1,208 of 8,013 identified contractors (15 percent) had accounts not disabled in a timely manner.
For separated contractors specifically: The data reveals a stunning breakdown. Of 1,208 contractor separations, 623 (52 percent) had separation records created more than 30 days *after the contractor had already left CBP*.
Think about that timeline: A contractor walks out the door on day one. The supervisor doesn’t create a separation record. Days pass. Weeks pass. Thirty days later—well after the contractor should have been disabled—the separation record finally gets created. In the intervening month, that person could have been accessing databases from anywhere in the world.
For transferred employees: Of 3,697 identified employee transfers, 615 (17 percent) retained unneeded access after moving to new positions. When supervisors entered transfer records late—after the employee had already transferred—the AMS didn’t automatically remove the old system access. The employees retained unnecessary access, likely without supervisor awareness.
The OIG report notes that CBP configured its systems to remove existing access on the transfer date but not after. Why? To avoid inadvertently removing any newly granted access needed for the transferred employee’s new position. The result: Employees who transfer keep their old access indefinitely.
Why CBP’s Backup Plan Doesn’t Work
When the primary process failed, CBP relied on “backup controls” to eventually catch the problem: account inactivity. If an account wasn’t used for a certain period, the system would eventually disable it.
This is not adequate. The DHS requirement is 3 days. Account inactivity can take weeks or months.
“Although these backup controls helped reduce the risk of separated personnel retaining unnecessary access, they did not allow CBP to disable the accounts within 3 days of an employee’s separation, as required,” the OIG found.
CBP also relied on data from the National Finance Center to identify separated employees. This creates a lag—payroll data isn’t real-time—meaning accounts could remain active longer than policy allows.
The National Security Angle
Of the 615 transferred employees who retained unneeded access, 531 (86 percent) came from CBP’s most sensitive offices.
The significance of this cannot be overstated. These are not administrative workers losing access to email or shared drives. These are personnel from the Office of Intelligence, Border Patrol, Office of Field Operations, and Office of Air and Marine Operations retaining access to systems with “national security and personally identifiable information.”
Transferred employees with access to information without a need-to-know and legitimate business purpose weaken operational security and integrity of the programs and systems, the OIG noted. Such access “could result in using the access for improper purposes.”
This raises personnel security questions: Is CBP conducting counterintelligence reviews to determine *why* someone transferred and whether they retained access? Are there cases where an employee transferred after disciplinary action or under suspicious circumstances and retained sensitive access?
The OIG audit doesn’t address this question. It’s one worth investigating further.
The June 2025 Breach Question
In June 2025, multiple DHS components, including CBP, experienced a cybersecurity incident that allowed hackers to steal CBP employee data. The OIG report mentions this incident as context for why CBP needs strong access controls—attackers regularly target CBP systems.
The audit does not state whether the June 2025 breach involved separated or transferred personnel accounts. But given that CBP had hundreds of accounts that should have been disabled but weren’t, it’s a logical question: Did hackers use a former contractor’s credentials to gain access?
Bureaucracy Times submitted that question to CBP. The agency has not responded.
CBP’s Response and Timeline
CBP concurred with all 12 OIG recommendations related to this finding. The agency’s planned corrective actions include:
- Updating supervisor training by August 31, 2026
- Implementing a new “Submit” tab on separation forms that automatically emails supervisors with reminders and direct links to the Employee Separation System (also by August 31)
- Issuing formal notification memorandums to contracting officer representatives (by August 31)
- Developing a process to periodically review contractor separations for compliance (by August 31)
- Evaluating and formalizing the process for managing access when CBP personnel transfer internally (by August 31)
- Implementing controls to monitor and review transferred personnel’s access (by August 31)
All of these were due by August 31, 2026. Whether CBP met those deadlines has not been confirmed. This article will be updated as new information becomes available. But the core problem—that CBP is attempting to manage account security through human process compliance rather than automated enforcement—remains unaddressed.
The Real Issue: Process, Not Technology
CBP’s explanation for the failure places blame on “human error and challenges associated with monitoring account access changes over time.” But this framing misses the point.
The problem isn’t that supervisors are careless. The problem is that CBP built a system that depends on thousands of supervisors remembering to file paperwork within 3 days of separation, across an organization with 67,000 personnel, 4,500 facilities nationwide, and constantly shifting staffing.
A modern access management system should detect separations from HR records automatically. A supervisor forgetting to file a form shouldn’t be able to delay account disablement. These are solvable technical problems, not inherent human failures.
Instead, CBP has implemented “backup controls” and relies on account inactivity as a de facto enforcement mechanism. This is reactive security, not proactive security.
The OIG recommendation to “update supervisor training” may help marginally, but it doesn’t address the structural problem: CBP’s access management process is fundamentally broken at the design level.
What’s at Stake
CBP protects America’s borders and manages biometric data on millions of people. The agency processes travel documents, law enforcement information, and intelligence. Contractors working for CBP—software developers, IT managers, security consultants—have access to some of the most sensitive information in the federal government.
If CBP can’t reliably remove their access when they leave, the agency can’t reliably protect that information.
The OIG audit found this problem in September 2026. CBP is promising fixes by August 2026. If the timeline holds and the fixes work, accounts should be disabled more reliably going forward.
But accounts that should have been disabled in 2023 and 2024—the subject of this audit—remain within CBP’s systems today. CBP has not said whether it has gone back and cleaned up those historical accounts, or what it found when it reviewed the access logs.
Those are questions worth asking.
—
References and Links
Full OIG Report (OIG-26-28): CBP’s IT Access Control Deficiencies Introduced Critical Risk to IT Systems and Sensitive Information (OIG-26-28-Sep26.pdf) — Released September 4, 2026 by the DHS Office of Inspector General
DHS OIG Homepage: www.oig.dhs.gov
Relevant DHS Policy (referenced in audit):
- DHS 4300A: Information Technology System Security Program, Sensitive Systems (v. 13.4, December 2024)
- NIST SP 800-53, Revision 5: Security and Privacy Controls for Information Systems and Organizations
CBP Policy Directives (referenced in audit):
- CBP Directive 51715-006: Separation and Reassignment Directive for CBP Employees (August 2023)
- CBP Directive 1210-007B: Tracking of Contractor Employees (August 2023)
- CBP Identity Credential and Access Management Directive (IPL-2022-05-0253, May 2023)
—
Editor’s Notes
– CBP was contacted for additional details on the June 2025 cybersecurity incident and whether separated/transferred personnel accounts were involved. The agency has not responded as of September 9, 2026.
– The report notes that “CBP provided timely responses to our requests for information and did not delay or deny access to information we requested” during the audit. This OIG notation is standard language confirming agency cooperation.
– All 12 recommendations in the audit were concurred with by CBP, meaning the agency agreed with the findings and committed to corrective action.
