U.S. Immigration and Customs Enforcement is rolling out a program designed to protect agents and their families from doxxing, but some ICE employees are raising concerns that the same technology could potentially be used to monitor personnel or identify internal critics and whistleblowers.

An internal memo obtained by The Intercept and signed by Acting ICE Director David Venturella describes a "Doxing Mitigation Initiative" involving cybersecurity company ZeroFox. Separately, federal procurement records show ICE awarded ZeroFox a roughly $13 million contract in July for software licenses supporting Homeland Security Investigations' Office of Intelligence.

The public procurement description doesn't specifically identify the contract as a doxxing program, meaning the precise relationship between the broader ZeroFox software purchase and the initiative described in the leaked memo isn't fully established publicly. The statement of work detailing the contract's capabilities hasn't been released.

ZeroFox sells technology that monitors online sources for threats and exposed personal information. The ICE memo, according to The Intercept, presents the system as a way of strengthening protections for employees and their families, but doesn't provide a detailed explanation of how the technology will operate.

That uncertainty has generated concern among some personnel.

"It sounds like inside surveillance," one ICE official told The Intercept anonymously, citing fears of retaliation. The employee questioned whether a system intended to locate exposed information about agents might also be capable of tracking agency critics.

"If things go sideways, they may just throw all your info out there, make you out to be the problem or dox you," the official said. "I don't trust it."

Those comments describe fears about possible misuse rather than evidence that ICE intends to deploy ZeroFox against whistleblowers. The available material doesn't establish that the agency is using the technology to identify employees who speak with journalists or criticize management.

A second ICE official raised concerns about providing personal information to an outside company. "I frankly don't trust the feds with that," the employee told The Intercept. "I'm not really keen on giving my PII (personally identifiable information) to a company that doesn't have a solid track record with government contracts."

ZeroFox's history with government agencies has previously attracted scrutiny. During the 2015 protests in Baltimore following Freddie Gray's death, a ZeroFox "Crisis Management Report" categorized activists DeRay McKesson and Johnetta Elzie as "high" severity "physical" threats, despite providing no specific evidence that either posed a physical threat.

ZeroFox co-founder Evan Blair later said the designation wasn't intended to suggest that McKesson or Elzie planned to cause harm and indicated that their large social-media followings likely contributed to the classification.

The company also became part of an intelligence breakdown examined after the Jan. 6, 2021, attack on the U.S. Capitol. The FBI switched from Dataminr to ZeroFox on Jan. 1, 2021, but a Senate investigation found the transition hadn't been fully completed before Jan. 6.

Internal FBI correspondence cited by the Senate investigation showed Washington Field Office personnel were still working to establish automated searches days before the attack. The FBI later told investigators that the transition "was a challenge" and "was not ideal."

Cybersecurity specialists say the technical capabilities involved could have uses beyond protecting employee information, depending on how a system is configured. Richard Forno, associate director of the Cybersecurity Institute at the University of Maryland, Baltimore County, told The Intercept: "It's plausible that this tech could be used to seek out whistleblowers."

Forno described a hypothetical "honey pot situation" in which distinctive information could be distributed internally and then traced if it appeared outside the agency. No evidence has emerged that ICE is using ZeroFox in that manner.

Sophia Cope, an attorney with the Electronic Frontier Foundation, said protecting employees from publication of sensitive personal information can serve a legitimate safety purpose, while warning that the scope of such a system matters.

"However," Cope said, "if ICE is instituting this program to shield officers and the agency itself from public accountability, especially when information is already publicly available, then that's a serious concern and flies in the face of our democratic values."

The federal contract confirms that ZeroFox software is being supplied to HSI's Office of Intelligence, while the leaked memo describes a program intended to protect ICE personnel from doxxing. What remains unclear publicly is precisely what information ZeroFox will collect from employees, how that data will be used and what restrictions ICE has placed on uses beyond personnel protection.