Product1 publisher3 min readPublished
A discovery packet in Montana named the Border Patrol unit that screens financial activity for stops
404 Media found Border Patrol units that review Americans' financial activity and hand the result to local police. The document behind the finding came out of one defendant's discovery, which leaves the input end of the pipeline unnamed.
The Product Desk · Product desk

What happened
- 404 Media found that Border Patrol operates secretive units that analyse Americans' financial activity and pass the resulting intelligence to local police, who then stop drivers not suspected of any specific crime.
- One of those units reviewed the financial activity of a man driving across Montana, after which local authorities stopped him on the stated pretense of an obstructed license plate and charged him with a DUI.
- Kyle Olson learned where his stop came from via a Homeland Security document produced in discovery, written by Border Patrol Agent Matthew Phelps, which Olson then shared with 404 Media.
- 404 Media named the units for the first time: Predictive Intelligence Targeting Teams, sitting inside Border Patrol sector Targeting & Intelligence Divisions.
- Border Patrol and CBP told 404 Media that routing bank records to predictive policing specialists is simply a smart way to pursue criminals.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- constraint With the targeting parameters unpublished, a fintech's usual assurance that it discloses records only on lawful request no longer tells a customer what their normal-looking spending can set in motion.
- exposure Every company holding transaction data now has a plausible path from its ledger to a highway stop that it cannot map, because the reporting identifies no institution at the collecting end of that path.
- precedent This surfaced because prosecutors had to explain a stop in discovery, which sets the expectation that the next such program becomes visible through a defendant's case file rather than any transparency report.
- contradiction Techdirt's bulk-collection framing and the agent's narrow phrase about law enforcement-sensitive systems support different risk assessments, and a product team choosing between them is choosing how much data to keep.
The line a payments team gives a customer who asks is that transaction records leave the building only on a lawful request, one account at a time. What the Montana filing describes sits at the other end of that sentence. Border Patrol Agent Matthew Phelps wrote that his job on the Spokane Sector team is to review law enforcement-sensitive databases, including Americans' financial activity, and hand the result to local police [5]. His account of this stop is that he saw "information contained within law enforcement-sensitive systems suggesting financial activity patterns commonly associated with illicit narcotics activity" [6]. That sentence is the whole documented mechanism.
Documented: one agent, one sector, one team name, one stop [15]. Not documented: the input end, meaning no bank, no processor, no broker, no contract, no record volume [12]. Techdirt reads the practice as bulk financial records shoved into a system whose output is reasons to pull people over, and calls it a fresh route into civil asset forfeiture [8]. The document quoted in that piece does not say bulk. A payments team has to hold both readings, because it cannot plan against the second without knowing the first.
Here is what teams tell themselves about pattern detection: it is a compliance obligation aimed at a small population doing something wrong, and the worst customer outcome is a frozen account and an apology. Here is what this record shows the output can be: a stop on the stated pretext of an obstructed license plate, a DUI charge [3], and then an attempt to convert the stop into drug trafficking charges [14]. Techdirt argues that competent money laundering produces financial activity that looks entirely normal [10]. The corollary for anyone tuning a model on transaction data is that a system rewarded for finding abnormality will mostly find customers whose cash flow is lumpy for dull reasons.
Government access to financial records held by third parties was already broad under the third-party doctrine, as Techdirt notes [9]. What changed in this record is who consumes that access and what they produce with it, which is a stop of someone not suspected of a specific crime [1]. The parameters the targeting teams use are not published [11], so no internal risk review can test whether a given customer profile scores.
The sort worth doing has two axes. First, whether you can name every downstream system that receives or mirrors your transaction records. Second, whether a user behaving normally can generate the pattern you would flag. Yes and no puts you in decent shape. No and yes puts you in the quadrant where Friday's honest answer to a customer is that you do not know and cannot find out. Inside that quadrant the only lever is what you retain and how coarse you keep it, because the flag is not something you get to see.
What to watch
- Whether Olson's court orders the PITT scoring parameters disclosed, or the government drops charges rather than produce them.
- Whether any bank, processor or data broker is identified as a source of the financial activity these teams review.
- Whether Targeting & Intelligence Division units with PITTs are documented in Border Patrol sectors beyond Spokane.