In July 2026, Immigration and Customs Enforcement awarded Baltimore-based cybersecurity company ZeroFox a contract worth up to $14.57 million. The public procurement record says the award supplies software licenses to the Office of Intelligence within ICE’s Homeland Security Investigations division for ongoing law-enforcement operations and investigations.
On September 2, 2026, The Intercept reported that ICE had introduced the software to employees as part of a “Doxing Mitigation Initiative” intended to protect personnel and their families. Two ICE officials who spoke anonymously to the publication raised concerns about how the technology might be used internally. One said the program sounded like “inside surveillance.”
That concern is the story.
The public frame is worker safety. The internal concern is whether technology capable of mapping identities and digital exposure could also be used to identify employees who speak to journalists or disclose information about agency conduct.
The public award record establishes the value, recipient, government office, broad purpose, and duration of the contract. It does not publicly disclose what data ICE will provide to ZeroFox, who will be allowed to search the system, or whether particular categories of people are excluded from monitoring.
ZeroFox says its platform continuously maps digital assets and scans sources across the surface, deep, and dark web. The company also advertises computer-vision tools for facial matching and software that correlates social accounts, exposed credentials, profiles, and other digital signals.
Those are legitimate cybersecurity capabilities with defensive uses, including finding exposed personal information and detecting threats. They are also broad capabilities whose impact depends on what information is supplied, how searches are configured, and what oversight governs the resulting alerts.

The company’s history sharpens the present concern. In 2015, during protests in Baltimore following the death of Freddie Gray after an injury sustained in police custody, ZeroFox provided city officials with a free crisis-management report identifying “Threat Actors”.
The report included peaceful Black Lives Matter organizers DeRay McKesson and Johnetta Elzie, along with Baltimore Bloc. It labelled all three “Threat Type: Physical” and recommended monitoring, despite listing no specific malicious activity for the organizers. ZeroFox’s founders later told Technical.ly that “physical” meant the individuals were active in the real world and that their prominence and social-media reach caused the system to flag them.
That explanation matters, but so does the outcome. People engaged in peaceful political activity appeared in a threat report delivered to government officials, demonstrating how a monitoring system’s categories can pull protected activity into a security workflow.
The FBI’s later use of ZeroFox requires more careful description than the original draft provided. A 2023 Senate Homeland Security Committee report found that the FBI switched from Dataminr to ZeroFox effective January 1, 2021, only days before the January 6 attack on the Capitol.
The report said FBI officials had not adequately planned the transition and that the change temporarily degraded the bureau’s open-source monitoring capabilities. It did not establish that ZeroFox’s software itself failed to identify extremist activity. The documented failure was the FBI’s contract migration and its broader handling, assessment, and distribution of intelligence.
That distinction does not erase the concern surrounding the current ICE arrangement. It clarifies it. One documented episode involved peaceful organizers being placed in a threat report, while another showed how operational decisions surrounding a monitoring contract could weaken intelligence work during a critical period.
Richard Forno, associate director of the UMBC Cybersecurity Institute, told The Intercept that the technology could plausibly be used to seek out whistleblowers. He compared the possibility to creating a honey pot that could help officials determine who was leaking information.
The mechanics make the concern understandable, but the public record leaves important details unanswered. A doxing-protection service generally needs identifying information about the people it protects and the online material exposing them. ZeroFox also advertises tools that connect accounts, images, credentials, and other digital signals. What has not been publicly disclosed is exactly which of those capabilities ICE purchased or how access to them will be restricted.
Sophia Cope, a senior staff attorney on the Electronic Frontier Foundation’s civil-liberties team, told The Intercept that protecting officers from genuine threats is legitimate. She also warned that using such a program to shield ICE from public accountability, particularly when information is already public, would conflict with democratic values.
The distinction is important. Protecting a home address from a harassment campaign is one thing. Preventing the public from identifying federal officers acting in an official capacity is another. The public contract summary does not provide enough operational detail to determine exactly where ICE intends to draw that line.

The ownership layer adds context. ZeroFox is owned by Haveli Investments, an Austin-based private equity firm focused on technology companies. An SEC-filed announcement shows that Haveli agreed to acquire ZeroFox in 2024 in an all-cash transaction with an enterprise value of approximately $350 million.
The previous draft also described former ZeroFox chief development officer Bryan Ware as a current employee. Current public profiles instead identify Ware as the founder and CEO of GraySpace Technology, so the outdated employment claim has been removed.
For potential whistleblowers, the practical risk is timing. An employee may need to reach an inspector general, congressional committee, lawyer, or journalist before managers determine who disclosed the information. Digital monitoring that connects identities, accounts, images, and relationships could make that period of anonymity shorter if it were directed toward internal leak investigations.
That is a potential use, not a disclosed feature of the ICE program. Neither the public award summary nor the available reporting establishes that ICE has used ZeroFox to identify a whistleblower. The concern comes from the platform’s wider capabilities and from the reactions of officials inside the agency.
Two facts can therefore be true at once. ICE officers and their families can face real harassment and doxing threats that an agency has reason to address. At the same time, the selected contractor offers broad monitoring technology and previously placed peaceful activists in a government-facing threat report.
Neither fact cancels the other.
The public award record lists a one-year performance period ending July 12, 2027, so it is inaccurate to say the contract has no end date. What the public summary does not disclose is whether the program includes use limitations, an independent auditor, restrictions covering journalists and employees, or a process for challenging an incorrect identification.
The honest reading of the program must separate what is known from what remains unresolved. The contract is real, its potential value is $14.57 million, and it provides software licenses to an ICE intelligence office. ZeroFox publicly advertises technology for monitoring digital exposure, correlating identities, comparing faces, and prioritizing perceived threats.
What remains unknown is how ICE will configure those capabilities and who will be allowed to use them. When officials inside the agency describe the system as possible “inside surveillance,” that concern deserves scrutiny. It is not proof of misuse, but it is evidence that the program’s safeguards need to be made public before a defensive tool quietly becomes something broader.