Officials of the U.S. Customs and Border Protection (CBP) said that one its subcontractors had been breached in a “malicious cyberattack,” exposing images of travelers coming in and out of the country.
As a result, about 100,000 people had their information compromised by the attack.
The database, which comprised of photos of people’s faces and license plates, had been transferred to the subcontractor’s network without the federal agency’s authorization or knowledge, said a CBP spokesperson to The Register.
Fortunately, the stolen information doesn't include any identifying information.
No passport, images from airports or other travel document photos were compromised, but rather of drivers in their cars and license plates of vehicles crossing through one port of entry over a six-week period, the officials said.
The CBP first discovered about the breach back in May 31st, when it realized a federal subcontractor had transferred copies of the images to the subcontractor’s network, which the agency said was done without its knowledge and in violation of the contract.
The hackers here, managed to hack the subcontractor’s network to steal the information.

“As of today, none of the image data has been identified on the dark web or internet,” the CBP agency said in a statement
The news comes after The Verge reported that the CBP carried out large-scale tests in 2016 of new facial recognition technology at various point-of-entries that scanned drivers’ faces without their consent.
With more and more personal information collected, including biometric data, critics have been raising the alarm, arguing that individual privacy and security are not being safeguarded.
This incident also prompts questions about how the federal government secures and shares personal data.
News of the breach comes as facial recognition technology has been the subject of a growing debate among civil liberty groups and lawmakers, who have raised concerns related to false matches and arrests while balancing the need for public safety.
With databases containing personal identifying information becoming an alluring target for hackers and cybercriminals, the incident further underscores the need for careful evaluation of data collection practices by government agencies.




















































































































































































































































































































































































