incident-responsetrade-pressNewsThe Broadside2 min read

CBP gave 76,000 users privileged access, OIG finds

Any user on the network could reset passwords, change permissions, and modify security configurations, and CBP couldn't reliably identify which accounts were privileged in the first place.


TL;DR

A DHS Office of Inspector General audit found that all 76,000-plus CBP network users (employees, contractors, and other personnel) had access to a highly privileged service account, letting anyone alter passwords, change system access permissions, and modify security configurations. The agency also failed to review and remove access when personnel separated or transferred, and couldn't reliably identify which accounts were privileged. CBP has revoked the excessive privileges, validated no similar misconfigurations remain, and implemented new monitoring, but the OIG left one recommendation open, awaiting evidence that over 100 identified attack paths were analyzed and unnecessary accesses adjusted.

The DHS OIG audit found that every CBP network user (more than 76,000 employees, contractors, and others) had access to a highly privileged service account. From that position, any user could reset account passwords, change system access permissions, modify security configurations, or take over accounts with access to sensitive data.

"We identified multiple access control vulnerabilities, which could allow an attacker to compromise CBP's network, gain access to sensitive information, and disrupt mission-critical operations," the OIG said in its report.

The agency also wasn't reviewing or removing access when personnel separated or transferred (a standard account-lifecycle control) and had difficulty even determining which accounts were privileged in the first place. CBP told the OIG the problems stemmed from human error and an inability to track account access changes over time.

The stakes are structural: CBP operates more than 100 major IT applications, some storing sensitive law enforcement and biometric information used at ports of entry. The OIG described CBP's systems as "high-visibility targets for attackers who aim to disrupt mission-essential operations or steal sensitive information."

CBP moved quickly once the risks were identified. The agency revoked "all identified excessive privileges" and ran a validation scan confirming no other similar misconfigurations existed. It also implemented new access-control monitoring, providing evidence to the OIG in April and July, enough to resolve one recommendation and partially satisfy another, which remains open pending documentation that the new alert systems and response protocols are functioning.

The OIG is still waiting on evidence that the more than 100 attack paths identified in the audit have been analyzed and any unnecessary accesses adjusted. CBP set an end-of-August deadline for several remaining actions, including a memorandum on security policies, new procedures for removing contractors from directories after separation, and documented IT system access procedures.

The finding fits a pattern. A 2017 OIG report flagged CBP's IT systems as not fully supporting border security objectives; a 2024 audit of the CBP One app found security vulnerabilities in both the application and its supporting infrastructure. CBP's 2023 IT strategy document identified zero-trust architecture as a top priority, this audit suggests the gap between strategy and operational reality hasn't fully closed.


Published ·Deep Fathom