Standing on a public sidewalk in Portland, Maine, Polyxenia Pantos photographed an immigration arrest. Days later, according to court filings, her spouse’s home address, phone number, and list of cohabitants were inside a federal investigative database. This kind of surveillance app-style targeting of civilians has appeared in other government operations as well.
Partially unsealed filings in an active federal class action reveal the alleged mechanics: a system built for serious criminal investigations, reportedly used to catalog people who were simply watching.
What the Filing Says Happened
Court documents describe a pattern of data collection targeting observers, not suspects.
The case stems from Operation Catch of the Day, an immigration-enforcement surge in Maine during January 2026. An agent identified in filings as “J.C.” allegedly created Investigative Case Management (ICM) records for at least six observers; government filings put the number at eight.
According to court documents, the information allegedly collected included:
- Photographs of observers
- License plate numbers
- Home addresses and telephone numbers
- Names of household members
- Labels such as “Threat to Law Enforcement, Professional Protestor”
The filing alleges that after Pantos photographed an arrest near a vehicle registered to her spouse, Carlyn Williams, J.C. ran the license plate through Accurint, a LexisNexis law-enforcement database, and pulled a report containing Williams’s address, phone numbers, and cohabitants. He then allegedly circulated Williams’s photograph to colleagues before entering both individuals into ICM.
Williams says J.C. later called her and warned that continued observation could result in a domestic-terrorism watchlist entry. J.C. denied using that specific language in deposition but, according to the filing, said Williams could be arrested if she continued. No plaintiff was nominated to the terrorist watchlist, the government says.
Protect Democracy attorney JoAnna Suriani said the plaintiffs believe the government treated people exercising First Amendment rights as criminal suspects, as reported by WIRED.
The Architecture That Made This Easy
The system’s design, not just one agent’s conduct, raises the harder questions.
ICM is Homeland Security Investigations’ case-management system, built on Palantir’s Gotham software. ICE awarded Palantir the original contract in 2014; a later support contract added roughly $96 million; a 2025 award added nearly $30 million for a product called “ImmigrationOS.” Palantir did not respond to requests for comment.
Here is where the design becomes consequential. According to a 2016 DHS privacy assessment, ICM automatically shares subject records with TECS, CBP’s traveler-screening system, where they can function as lookout records at the border.
Think of it like a Google Drive folder where “view access” quietly became “edit and share” because someone built the sharing into the foundation. No one announces the scope change; the infrastructure just accommodates it.
A CBP officer allegedly used an application called Mobile Query to run facial-recognition searches on photographs J.C. supplied. That is three systems, two agencies, and one sidewalk bystander, according to the filing. Parallel patterns of secretly tracking users have surfaced in other government-adjacent technology deployments.
The Government’s Position
DHS disputes the lawsuit’s characterization and says the alleged conduct violated its own policy.
DHS calls the case meritless and denies operating a domestic-terrorism database targeting protesters. Its motion to dismiss characterizes the alleged conduct as isolated and contrary to DHS policy, arguing J.C. created records for people he believed posed a safety threat and did not nominate anyone for the terrorist watchlist.
Former acting ICE Director Todd Lyons told Rep. Maxwell Frost that ICE does not maintain a database of U.S. citizens protesting ICE activity. His letter also acknowledged that ICE may still collect information about people believed to be involved in potential federal-law violations or posing officer-safety concerns. That information becomes an official government record when collected, the letter said.
What Needs to Change
The constructive fix is purpose limitation, enforced by design rather than by policy alone.
The issue is not Palantir’s existence. It is purpose limitation: investigative systems intended for criminal cases need technical guardrails that prevent their use against people engaged in constitutionally protected observation.
Audit logs, role-based access controls, and mandatory supervisor review before an observer enters a case file are not radical demands. They are the kind of governance controls that distinguish an investigative tool from a surveillance dragnet.
The ICM-to-TECS automatic sharing pathway deserves particular scrutiny. According to the 2016 DHS privacy assessment, a record created by one agent in one state can function as a border lookout record, a documented system capability that the Maine allegations make newly relevant. That is not a theoretical risk; it is how the system was designed to work.
Plaintiffs are asking the court to archive Williams’s records, bar DHS from using collected information against them, and prohibit Maine agents from threatening observers with watchlists or following them home. The litigation may ultimately determine whether the collection violated constitutional protections. It may also settle whether the automatic data-sharing pipeline between investigative and border-screening systems requires a policy correction. No resolution has been reached; the case remains pending.




























