Why the OIG Did This Audit
TSA uses watchlist data to vet airline passengers and employees to prevent known or suspected terrorists or other dangerous persons from boarding aircraft.
According to media reporting, in January 2023, a hacker allegedly accessed a version of watchlist data that had been shared with an external partner. We conducted this audit to determine the extent to which TSA has implemented controls to safeguard watchlist data shared with external partners and stakeholders.
What the OIG Found
The Transportation Security Administration (TSA) has adjusted how it conducts watchlist data matching, thereby reducing security and privacy risks related to the previous practice of sharing watchlist information with aircraft and airport operators. TSA addressed concerns associated with an alleged January 2023 breach of watchlist data by fully implementing planned procedural changes and assuming full responsibility for vetting employee and passenger populations.
- As part of its initial response to this alleged breach, TSA issued a security directive for all aircraft operators to destroy documents and files containing copies of watchlist data no longer needed for security measures, limited access to watchlist data, and implemented procedures to prevent unauthorized access.
- Shortly thereafter, TSA fully internalized watchlist data matching functions, and finalized and implemented internal programs and systems to remove all aircraft operators’ access to watchlist data. As of July 2024, aircraft operators could no longer access watchlist data because TSA performed all watchlist data-related vetting.
Given TSA’s actions on this matter, the OIG made no recommendations.
Read the full OIG report here.


