
A newly-released Inspector General (IG) audit sent tremors through the U.S. travel-security world on Friday, September 18. The unclassified summary, dated September 15 and first reported by Biometric Update, found that a vendor supporting TSA’s Credential Authentication Technology 2 (CAT-2) machines could – and sometimes did – extract high-resolution scans of travelers’ driver-license and passport photos while performing maintenance and software upgrades, all without TSA tracking or confirmation that the copies were later deleted. The IG stressed that routine checkpoint operations still purge data within seconds and that it uncovered no evidence of misuse. The problem arose in a little-known “service tunnel” that allows contractors to troubleshoot equipment remotely. Because TSA had no written policy limiting what contractors could copy, and no audit log capturing when extractions took place, investigators concluded the gap constituted a “significant weakness” that puts millions of traveler identities at theoretical risk. The watchdog issued three recommendations: tighten contractual language, require tamper-proof access logs, and create a verification process to confirm deletion of any images pulled for testing or repairs. Why does this matter for global mobility managers and frequent flyers? CAT-2 readers are the biometric workhorses of U.S. aviation security: more than 2,100 units are already deployed at 250+ airports, and TSA’s FY 2027 budget asks Congress for another US $41 million to accelerate nationwide rollout. Corporate mobility programs count on CAT-2 to shave minutes off security queues for time-pressed executives; any erosion of public trust could slow approvals for new lanes or prompt lawmakers to impose additional privacy hurdles. TSA has accepted the findings and says corrective action plans are under way, but two of the three recommendations remain “open and unresolved,” according to the IG. Until permanent safeguards are in place, mobility professionals should remind traveling employees that passport and ID images may be retained longer than advertised during off-hour system maintenance and should build that residual risk into company data-protection assessments. For travellers, the takeaway is simple: biometric checkpoints are still faster and generally secure, but the governance around them is catching up to the technology. Expect stricter audit trails — and possible brief outages — as TSA patches the hole over the next several months.
Source: Biometric Update