NewsMacroSEC Purchased Access to Over One Billion Airline Records to Track Travelers Without a Warrant

SEC Purchased Access to Over One Billion Airline Records to Track Travelers Without a Warrant

Author: Decrypt·

Key Takeaways

  • The SEC obtained access to over one billion airline ticketing records from Airlines Reporting Corporation without a court order or warrant, including passenger names, credit card numbers, and flight itineraries.
  • ARC's Travel Intelligence Program had previously provided similar data access to the FBI, IRS, and Department of Homeland Security before being shut down in 2025 under lawmaker pressure.
  • The SEC's subscription included a real-time alert system that flagged travel by specifically monitored individuals, with the agency requesting up to 25 alerts per day.
  • Privacy advocates characterize the practice as a data broker loophole allowing agencies to commercially purchase records they would need legal authority to compel through a subpoena or warrant.
  • Despite TIP's closure, other commercial data brokers continue selling similar travel-data products to federal buyers in a legally unresolved gray area following the Supreme Court's 2018 Carpenter ruling.
SEC Purchased Access to Over One Billion Airline Records to Track Travelers Without a Warrant

The U.S. Securities and Exchange Commission purchased access to a global airline ticketing database containing more than one billion records, according to SEC documents obtained by 404 Media through a Freedom of Information Act request.

The data was supplied by Airlines Reporting Corporation (ARC), a clearinghouse co-owned by American Airlines, Delta Air Lines, and United Airlines. ARC operates between carriers and travel agencies, processing and reselling bookings made through platforms such as Expedia and Kayak.

The records available to the SEC included passengers' full names, credit card numbers used to purchase tickets, departure and arrival cities, and flight numbers. The SEC's subscription also included a real-time alert system that checked new bookings against a list of individuals the agency was monitoring. The system flagged travel from the prior 24 hours, and the SEC requested between one and 25 such alerts per day. No court order was required; the government simply purchased the data, likely without a warrant.

ARC's Travel Intelligence Program (TIP) had previously sold access to the same post-9/11 surveillance infrastructure to the FBI, the IRS, and the Department of Homeland Security. The SEC's participation illustrates how the practice expanded beyond national security and border agencies to civil financial regulators. The newly released documents reveal that the program's reach was broader than previously known—foreign-to-foreign journeys were captured in the system alongside domestic flights. Lawmaker pressure ultimately forced TIP's shutdown in 2025.

ARC defended the program in a statement to 404 Media, saying TIP "was established after the September 11, 2001, terrorist attacks" and "has likely contributed to the prevention and apprehension of criminals involved in... money laundering" and terrorism.

The SEC is a financial regulator tasked with protecting American consumers from insider trading, fraud, and market manipulation—not an intelligence agency. However, the travel and payment data it purchased overlaps directly with the financial trails left by cryptocurrency users: a credit card linked to an exchange account, a flight to a crypto conference, a border crossing.

During the second Trump administration, the SEC has scaled back major crypto enforcement actions (Decrypt), even as the data-broker workaround allows federal agencies to bypass the warrant process they would need to follow if they demanded the records directly. The IRS has similarly been expanding its surveillance of crypto investors using comparable methods. The SEC's Coinbase probe the prior year demonstrated the same appetite for user data.

Privacy advocates and civil liberties groups refer to this practice as the "data broker loophole"—agencies buying commercially available data that they would otherwise need legal authority to obtain through a subpoena or warrant. The approach exists in an unresolved legal gray area: the Supreme Court's 2018 ruling in Carpenter v. United States held that accessing certain third-party digital records constitutes a Fourth Amendment search requiring a warrant, yet agencies contend that data purchased on the open market falls outside that framework. While TIP itself has shut down, the commercial travel-data market it relied on remains active, and other brokers continue to offer similar products to federal buyers. Money laundering, the charge most frequently associated with crypto-related enforcement, was among the criminal activity ARC cited in defending the program.