China-Born CBP Supervisor Accused of Stripping 46 Homeland Security Computers at U.S.-Canada Border Facilities


Sept. 13, 2026, 9:01 a.m.

Views: 1634


Chinese National Accused of Illegally Modifying Homeland Security Computers at Maine-Canada Border Station

China-Born CBP Supervisor Accused of Stripping 46 Homeland Security Computers at U.S.-Canada Border Facilities

A U.S. Customs and Border Protection supervisor who described himself as a native of Guangzhou, China, has been accused of secretly altering dozens of Homeland Security computers at sensitive border facilities in Maine, raising serious questions about insider access, hardware integrity and the security of federal systems operating along the U.S.-Canada border. According to an FBI affidavit cited in court records, Terry “Jiajia” Liu allegedly opened government computers during overnight shifts, removed processors, memory and storage components, replaced them with inferior hardware and returned modified machines to service on the CBP network. Investigators ultimately identified 46 altered computers across three border facilities.

The scale of the alleged tampering is what makes this more than an ordinary workplace theft case. Investigators say 38 computers at Calais, six at Ferry Point and two at Milltown had been modified. Thirty-nine reportedly had processors replaced, six had memory changes and eight had hard-drive changes, with some computers altered in multiple ways. Many machines originally equipped with 14th-generation Intel processors were allegedly downgraded to older processors or Intel Pentium models, while other systems ended up with less memory or storage than their original configurations. Some of those computers were then reconnected to the CBP network.

For Americans, the central concern is straightforward: federal border-security computers should never be physically modified by an employee outside authorized maintenance procedures. CBP systems operate inside an agency responsible for screening travelers, inspecting cargo, enforcing immigration and customs laws and protecting U.S. ports of entry. When an insider allegedly opens those computers, removes hardware and reconnects altered machines to the government network, the security problem extends beyond the market value of the stolen components. Every unauthorized physical change creates uncertainty about whether the machine still meets federal performance, integrity and cybersecurity requirements.

The allegations become even more troubling because Liu had reportedly been explicitly told to stop touching CBP computers. According to the FBI affidavit, Port Director Theodore Cummings emailed Liu on March 18, 2025, instructing him: “Please do not move any computers or computer parts.” The message made clear that CBP computers were supposed to be serviced through authorized information-technology channels. Yet months later, personnel discovered that approximately 23 machines had been modified without permission, a number that later grew to 46 after a broader inventory.

Investigators eventually installed surveillance cameras. During a January overnight shift, according to the affidavit, video allegedly showed Liu carrying computers into a training room, removing side panels, using tools to remove a processor, cleaning the component and installing a replacement. Investigators said he then connected monitors, keyboards and network cables to test the altered computers. Another camera later allegedly recorded him removing a memory module, placing it in his desk drawer and carrying the computer into a server room, where it was again connected to equipment and the network.

The investigation also identified what authorities believe was a financial motive. FBI records described 13 emails Liu allegedly sent from a personal account to his official CBP address containing shipping labels and trade-in summaries for processors matching models missing from government computers. Newegg records reportedly showed that Liu received credit for trading in 14th-generation Intel Core i7 processors 16 times between May 2025 and July 2026, with offers of roughly $200 to $210 per processor. Investigators also found three $200 Newegg credits in his American Express records.

The government estimates that restoring the modified equipment would cost more than $20,000, while replacing all 46 computers would cost more than $105,000 before additional configuration expenses. Those figures matter, but the larger issue is the integrity of government infrastructure. A stolen processor can be replaced. Trust in the configuration of computers connected to a border-security network is much harder to restore once employees begin bypassing official hardware controls.

Liu’s own alleged statements deepen the concern. According to FBI Special Agent Christopher J. White, Liu admitted during a September 9 interview that he replaced government components with older parts purchased from Amazon and Newegg and used CBP parts to obtain trade-in credit. Investigators said his explanation changed during questioning. Liu first claimed the modifications were intended to improve efficiency, then allegedly acknowledged that he knew the changes reduced performance and said he was frustrated with the slow pace of CBP computer repairs.

That explanation, if accurately described by investigators, demonstrates exactly why federal agencies need strict separation between employee frustration and control over sensitive systems. A government employee cannot be allowed to independently decide that official hardware is too slow, remove components, substitute inferior parts and reconnect altered computers to a federal network. Border-security systems depend on chain of custody, documented maintenance, standardized configuration and accountability. Once those protections are ignored, even conduct motivated by personal financial gain can create vulnerabilities that adversaries could theoretically exploit.

Liu’s personal background has also drawn attention. The report says he described himself as a native of Guangzhou, China, and prosecutors cited “recent and frequent international travel,” “apparent foreign connections” and substantial financial means when arguing that he presented a flight risk. His immigration status, however, was not established in the reporting, so the available record does not support treating this as a proven Chinese-government operation or an espionage case. The confirmed national-security issue is the alleged insider manipulation of Homeland Security hardware at active U.S. border facilities.

That distinction does not make the incident less serious. China is already one of America’s principal strategic competitors in cyber operations, telecommunications, critical infrastructure and intelligence collection. U.S. agencies therefore have strong reasons to scrutinize insider access carefully when sensitive systems are involved, especially when employees have extensive access to government hardware and the ability to work alone during overnight shifts. The proper lesson is that federal agencies cannot rely only on network cybersecurity. Physical hardware, employee access and maintenance procedures are equally important parts of national security.

The case also shows how easily a seemingly mundane theft can become a system-security problem. Replacing a processor or memory module may look like property theft on paper. Inside a Homeland Security environment, however, hardware determines whether systems operate according to approved specifications. Unauthorized replacements can create performance failures, compatibility problems, audit gaps and uncertainty about what else may have changed. Investigators in this case have not alleged that Liu installed malware or transmitted government information outside the agency, but the fact that modified computers were reconnected to the CBP network shows why physical access must be controlled as tightly as administrative passwords.

Americans should also pay attention to the working conditions described in the affidavit. During midnight shifts, one supervisor could be responsible for open ports across the area, leaving periods in which Liu allegedly worked away from other officers. That kind of operational structure can create an insider-risk blind spot. Sensitive federal facilities should assume that trusted employees may still misuse access, and monitoring should be designed around that reality rather than around the assumption that internal staff are automatically safe.

The broader security lesson extends well beyond Maine. Federal agencies throughout the country rely on thousands of desktop computers, servers, network appliances and communications systems distributed across remote offices and field locations. Many sites operate around the clock with limited staffing. A determined insider who has physical access, basic technical knowledge and unsupervised time can potentially bypass procedures that expensive cybersecurity software cannot see. America’s defenses therefore depend on inventory control, tamper detection, hardware attestation, surveillance in sensitive rooms and automated alerts when approved configurations change.

This case should push federal agencies to strengthen hardware accountability across all sensitive facilities. Every processor, storage device and memory module in a government system should be traceable. Unauthorized opening of equipment should trigger review. Machines that undergo unexpected component changes should be automatically quarantined before being permitted back onto protected networks. Employees with limited IT responsibilities should never be able to substitute hardware outside a documented maintenance process without immediate detection.

The China connection in this case should be handled precisely. Liu reportedly described himself as coming from Guangzhou, China, but the available court reporting does not establish a Chinese intelligence role or state direction. That does not erase the national-security implications. America is in an era of intense competition with China in cyber capabilities, intelligence, technology and infrastructure, making insider-control failures inside agencies such as CBP particularly dangerous. The United States cannot afford weak internal safeguards around systems that protect its own borders.

Even the retail trail requires accuracy. Investigators say government processors may have been traded through Newegg’s trade-in system, but Newegg itself should not be treated as part of any China-linked activity. The company was founded by Taiwan-born entrepreneur Fred Chang, and the retailer appears in the case simply because investigators traced hardware trade-ins through its program. The relevant conduct is the alleged removal of government property and unauthorized modification of federal systems.

The final danger exposed by this case is complacency. Americans tend to imagine threats to federal computer systems as sophisticated remote hacking campaigns launched by foreign intelligence services. Yet some of the most damaging vulnerabilities can begin with something far simpler: a trusted employee, a screwdriver, an unattended computer and enough time to open the case. When dozens of Homeland Security machines can allegedly be altered before the full scope is discovered, the problem is not only one employee’s conduct. It is a warning that physical access to federal technology must be treated as a national-security privilege.

For the United States, that lesson is immediate. Border-security computers should be protected from insider manipulation with the same seriousness applied to cyberattacks from abroad. Whether the motive is financial theft, frustration, sabotage or something more serious, unauthorized hardware changes inside Homeland Security systems create unacceptable risk. The alleged modification of 46 CBP computers at facilities along the Maine-Canada border shows how vulnerable government infrastructure can become when trust is not continuously verified.


Return to blog