Cartel Hackers Exploit Commercial Data to Target US Law Enforcement
A Justice Department report highlights how the Sinaloa cartel used publicly available data to track and intimidate an FBI official, exposing a significant vulnerability for federal agents.
Hackers working for the Sinaloa cartel successfully exploited commercially available data to identify an FBI assistant legal attaché in Mexico City, according to a June 2025 Justice Department Inspector General report. The hackers used the official's phone number to obtain call records and location data, and then utilized Mexico City's camera network to track the official's movements and identify their contacts. This information was subsequently used to intimidate potential sources and cooperating witnesses, and in some instances, led to their deaths.
The incident underscores a growing threat known as ubiquitous technical surveillance (UTS), where adversaries can gather intelligence without direct physical surveillance. An updated audit by the DOJ Inspector General, released in late 2025, stated that deficiencies identified in the audit place the Department and its employees, investigations, operations, sources, and witnesses at increased risk to UTS threats. The audit also noted a lack of common definition for UTS within the Department and insufficient action to mitigate the threat.
Concerns about data exploitation extend to the U.S. border, where drug cartels have reportedly placed bounties on Immigration and Customs Enforcement (ICE) and Customs and Border Protection (CBP) officers. In October 2025, the Department of Homeland Security (DHS) reported bounties of $2,000 for doxxing or gathering intelligence on agents and up to $50,000 for killing high-ranking officials in Chicago. This risk can follow officers home, creating vulnerabilities for their families and communities.
Researchers have demonstrated how easily sensitive personal information can be acquired. For instance, Duke University researchers purchased records on U.S. military personnel, including names and home addresses, for as little as 12 cents each. A separate investigation using commercial location data successfully traced devices associated with U.S. military sites in Germany to the homes and schools of military children.
To combat this threat, the author suggests implementing a program to assess what adversaries can already access about agents. This would involve helping agents and their families remove personal information from data broker sites, secure their accounts, and establish clear channels for reporting threats. Congress is urged to provide sustained funding and clear authority for such protective measures.
The administration has designated six Mexican cartels as foreign terrorist organizations, and DHS leadership has publicly acknowledged threats to its officers. Proactive measures to protect the workforce from cartel surveillance are necessary and can be implemented immediately, prioritizing those at greatest risk, such as task forces working cartel cases, overseas attachés, and individuals protecting leaders. The goal is to reduce exposure and train agents to operate with the assumption that they are visible.