> “Initial information indicates that the subcontractor violated mandatory security and privacy protocols outlined in their contract,” the statement read.

Could this lead to criminal charges? Perhaps charging the contractor under CFAA for unauthorized access?

Only if the contractor was not meant to have access to this data. I would put money on them being contracted to "securely manage" the data CBP accrued without consent.

