Analysis

CBP’s Predictive Policing Units Have Financial Data, Won’t Say How They Got It

October 8, 2026 | Maya Al-Ahmad, EPIC Clerk

A recent story by 404 Media revealed that Customs & Border Patrol’s (CBP) predictive policing units, or Predictive Intelligence Targeting Teams (PITT) have been using financial data to target individuals for anomalous financial activities and hiding their involvement behind local law enforcement. CBP has refused to say how it acquired the financial records it is using, raising significant concerns that it is violating the privacy and statutory rights of unknown amounts of individuals. Lawmakers should take action to rein in federal agencies’ use of predictive policing and abuse of financial and travel information.

This past May, Kyle William Olson was pulled over by a Montana Highway Patrolman. Although he was told he was pulled over because of a partially obscured license plate (Mr. Olson had also previously been identified for investigation by CBP). The obscured license plate was merely the pretext used to stop him. In documents obtained by 404 Media, a member of CBP’s Spokane PITT unit stated that Mr. Olson’s stop was partially motivated by “information contained within law enforcement-sensitive systems suggesting financial activity patterns commonly associated with illicit narcotics activity.” The source of this information remains unclear, and CBP has not answered questions as to whether it obtained a warrant to access this financial activity.

This story is all too familiar. In 2022, CBP used automatic license plate readers (ALPRs) and predictive algorithms to track and analyze the travel path of Alek Schott, a driver traveling to and from Houston. Apparently CBP identified the travel path Mr. Schott had taken as suspicious and tipped off local law enforcement. Mr. Schott was forced to wait on the side of the road for over an hour while officers searched through his car; they found nothing. Despite this harassment, Mr. Schott was relatively lucky to have lost just an hour. Another driver, Lorenzo Gutierrez Lugo, was not so lucky. Mr. Gutierrez was arrested while working for the trucking company Paquetería El Guero, again due to CBP’s surveillance of his travel path. It took an estimated $20,000 in legal fees to clear Mr. Gutierrez Lugo’s name, and to get his work vehicle out of impound.

The use of predictive analytics on financial and travel data to identify abnormalities and investigation targets by CPB is one example of a dangerous practice known as “predictive policing.” The use of predictive policing practices has been subject to widespread criticism because it is necessarily based on probabalistic and potentially discriminatory assumptions about future action, rather than evidence of past crimes or of specific criminal intent In the cases described above, CBP collects information on the travel patterns of drivers on major roads throughout the country and sends information about targets identified as leads to local law enforcement. It is unclear what makes a pattern “abnormal” and, as the cases of Mr. Olson, Mr. Schott, and Mr. Guttierrez Lugo show, these referrals don’t necessarily lead to the identification or prevention of a crime.

This is not the only time that the Department of Homeland Security (DHS) and its subagencies have been mining through people’s financial records. For example, ICE abused its administrative subpoena power to obtain financial records from two financial institutions, Western Union and Maxitransfers Corporation, between 2019 and 2021. ICE collected 6.2 million financial records from those institutions, which also included identifiable information such as names and addresses. This was an untargeted, bulk data collection program, seeking the records of all money transfers over $500 in four border states and Mexico, and was allegedly shut down after receiving public criticism from Senator Ron Wyden (D-OR).

Surveillance and Predictive Policing Create Unsafe Conditions Which Exacerbate Existing Racist Patterns

CBP’s attempts to find patterns in data are a form of predictive policing, a tactic that raises many issues. Surveillance through the collection of financial data, license plates readers, drone footage, or any of the other forms of surveillance used for predictive policing provides law enforcement with continuous information about large groups of individuals, whether or not they are suspected of a crime. This opens the door for any person to become the subject of government harassment for any reason – their spending habits, their travel paths, their associations, and other information that the average person would not imagine would be the basis of an investigation. Because predictive policing is a data-based practice, it is based on the fundamentally flawed presumption that an ever-expanding surveillance network is necessary and beneficial. Further, the data that predictive policing relies upon are inherently unreliable and bias-ridden, undermining any efficacy the systems could have. Ultimately, predictive policing serves to force individuals into often dangerous interactions with law enforcement without evidence of any wrongdoing.  

One of the officers who searched Alek Schott’s car, after the search proved to be a waste of time said, “nine times out of 10, this is what happens.” This stop was based off nothing more than Mr. Schott’s “abnormal” travel path. Because this alleged abnormality alone would not be enough to give probable cause for a stop, local law enforcement had to fabricate reasons to stop Mr. Schott. In his case, that his car was drifting out of the lane. Without predictive policing tools that enable fishing expeditions, law enforcement might have had no basis to stop and search Mr. Schott. If, “nine times out of 10” these baseless stops result in nothing more than an unnecessary interaction with law enforcement, all this practice does is create increased risk of a bad encounter with law enforcement. For many Americans, being one of those nine increases their risk of a harmful or dangerous situation occurring.

Financial data is a particularly sensitive form of data as it can provide insights into a person’s life and habits through their purchases, debts, income, and more. This data provides a way to glean information about what a person believes, who they associate with, and how they spend their time. When law enforcement uses this information, it potentially opens the door to investigations and harassment based on a person’s associations or beliefs.

Like all forms of predictive policing, CBP’s use of financial and travel information is bogged down in flawed data. Travel paths and financial records (as well as other sources of data) are not reliable indicators of crime and the use of this data exacerbates existing patterns of racially biased policing. Using advanced technology to root around in large datasets for abnormalities to “predict crime” lends a veneer of legitimacy to inaccurate and biased claims. There is a flawed understanding of algorithm-based predictions as being more objective, despite inequalities being baked into datasets, and in many cases despite the requirement of human review, law enforcement agents will rely on algorithmic recommendations without verifying or doing their own investigative work. CBP has not provided information about the source or types of financial information they are observing or what factors may deem someone suspicious. Without this information, it’s impossible to know how many people are caught up in the PITT’s surveillance or to hold CBP accountable for biased or illegal policing.

There are Many Ways CBP Can Access the Financial Data Used to Target Mr. Olson

Mr. Olson’s case raises more questions than answers. One major question is how CBP obtained the financial information it relied on in the first place. Although the answer remains unclear, these are some of the ways CBP is able to acquire financial records.

Law enforcement agencies regularly evade legal protections such as the 4th amendment and privacy regulations, by purchasing information directly from data brokers. Financial data brokers could be providing CBP with intimate information about various individual’s purchases, debt, income, bank accounts, and much more. This information provides an intimate look into a person’s life, their interests, beliefs, and relationships. While it’s easy to imagine any number of ways such information may be misused by the government, this information can be legally obtained as there is no comprehensive federal regulation stopping data brokers from collecting and selling this information, nor stopping agencies from purchasing it.

Another way CBP can access this data is via administrative subpoenas; these are subpoenas issued by a federal agency that do not require prior judicial approval. DHS and its subagencies frequently rely on administrative subpoenas. For example, ICE used this tool to obtain 6.2 million financial records from Western Union and Maxitransfers Corporation. More recently, DHS has been weaponizing administrative subpoenas to target the online data of individuals who have spoken critically of ICE’s violent anti-immigration campaigns. Agencies outside of DHS, namely the Drug Enforcement Administration (DEA), have also been known to use administrative subpoenas to access information in bulk. Specifically, the DEA has previously subpoenaed “any records . . . which the Attorney General finds relevant or material” to a drug investigation which has included money-counting machine purchase records. Individuals whose information has been shared with the government via an administrative subpoena often receive no notice of this disclosure.

CBP also has access to financial information via one of a few exceptions to the Right to Financial Privacy Act (RFPA). The RFPA applies privacy protections to bank records and requires agencies to provide individuals with a notice and an opportunity to object before a financial institution can disclose their personal financial information to the government. There are several exceptions within the RFPA which allow for disclosures of financial information, including disclosures which may be relevant to possible violations of the law, or for the purposes of protecting national security. The RFPA also requires financial institutions to proactively disclose information to the Financial Crimes Enforcement Network (FinCEN), which is a part of the Department of Treasury, under some conditions. For example, the financial institution must disclose normally protected information if the financial institution knows or suspects a customer is conducting illegal activities and a sufficiently large sum of money is being transferred ($5,000 is the floor for most transactions). CBP could have accessed information from FinCEN or requested disclosures from financial institutions under one of the exceptions to the RFPA.

This Practice by CBP Appears to Exploit Legal Loopholes

Congress passed the RFPA after several Supreme Court cases held that financial records could be obtained by law enforcement from banks and other institutions without a warrant (e.g. that those records were not protected under the Fourth Amendment when held by a third party). The purpose of the RFPA was to establish via statute the protections that the Constitution was lacking—a requirement that the government give a person notice when it wishes to obtain that person’s financial records as well as time to challenge the disclosure. In theory, CBP’s acquisition of Kyle Olson’s financial information should have been regulated by the RFPA and Mr. Olson should have been notified that his records were obtained. But, as discussed above, the numerous exceptions and required disclosures weaken the Act’s protections. In addition, the RFPA only applies to the federal government. As such, private businesses, such as data brokers, and state and local government entities, such as local law enforcement, are not subject to these regulations.

CBP’s lack of transparency concerning PITTs makes it nearly impossible to know how individual rights and the law are being violated. Mr. Olson’s case demonstrates a clear example of the practice of “parallel construction,” a law enforcement tactic used to cover up how investigations began. This can obscure violations of the law and make investigations appear entirely legitimate when in fact the source might be problematic. In Mr. Olson’s case, local law enforcement knew to look for his vehicle and pull him over based on the tip from CBP, but he was told he was pulled over for an obstructed license plate. The stated reason for stopping Mr. Schott – who, like Mr. Olson, was stopped by local law enforcement after a tip from CBP – was that his car was drifting out of the lane. This practice prevents people like Mr. Olson and Mr. Schott from realizing they have been surveilled and obstructs public oversight and accountability.

It is impossible to know the extent of the violations that CBP may be committing given the opacity of these behaviors. Without knowing the sources of information used to investigate people like Mr. Olson or how that data is being used, the public cannot know if their rights are being preserved or are under threat. For example, if CBP acquired Mr. Olson’s financial records from FinCEN, this might violate the Privacy Act, which restricts how government agencies can share people’s data with other agencies. If some of this data came from the IRS, that would potentially be a violation of both the Internal Revenue Code’s protections for tax data and the Privacy Act.

Lawmakers Should Restrict Predictive Policing and Hold Agencies Accountable for Past Abuses of Financial Privacy and Location Tracking

Existing protections are not keeping up with the perils of predictive policing and secretive mass surveillance. We must do more to protect the rights of everyday people simply driving or spending their money and not expecting that a government agency might seize on a perceived abnormality as a reason to harass and investigate them. For example, the Privacy Act needs to be amended to better fit the needs of the modern age, and there should be direct restrictions on the use of predictive policing tools at the federal and state level.

The RFPA needs repair, as well. The RFPA has been weakened due to both the Patriot Act and the war on drugs, allowing a postponement of notice in cases of suspected drug trafficking, espionage, and terrorism. In addition, the RFPA was already full of broad exceptions that waived the notice requirement in many circumstances. Weakening the RFPA has opened the door to abuses by federal law enforcement. The RFPA must be amended to better protect the privacy and confidentiality of financial records by reinstating notice requirements and closing overbroad loopholes.

Policymakers must also act to close off private-public avenues that allow agencies to circumvent the rights and expectations of ordinary people. First, Congress must close the data broker loophole that allows agencies like CBP to purchase information they could not otherwise obtain with by passing the Fourth Amendment is Not for Sale Act, which would ban agencies from bypassing their own regulations by purchasing commercial datasets. In addition, Congress must rein in agency use of ALPR networks like Flock, Motorola, and others that feed the mass surveillance and analysis of individuals’ travel paths. States should also enact and enforce bans on sharing existing ALPR data with DHS.

Congress must also create real accountability for CBP and other agencies that deploy unaccountable predictive policing. It can start with an investigation into the PITT teams and the data those teams rely on. Congress may also amend the Federal Agency Data Mining Reporting Act to shed light on agency practices and create real penalties when agencies fail to comply. The stories of CBP’s predictive policing must be motivation to call for more transparency from the agency, and for the investigation of these practices.


The author would like to thank Abigail Kunkler, Kabbas Azhar, and Alan Butler for their feedback and editing of this post.

Support Our Work

EPIC's work is funded by the support of individuals like you, who allow us to continue to protect privacy, open government, and democratic values in the information age.

Donate