On June 19, 2018, Sam Lavigne, an artist and programmer who taught at NYU's Tisch School of the Arts, published a database on GitHub containing names, profile photos, job titles, and city-level locations of 1,595 individuals who listed Immigration and Customs Enforcement as their employer on LinkedIn. GitHub and Medium removed the data within 24 hours under their anti-harassment policies. WikiLeaks republished it the same week as 'ICEPatrol.'
What happened
On June 19, 2018, during a national news cycle dominated by family-separation enforcement at the U.S.-Mexico border, Sam Lavigne published a database he had built by scraping LinkedIn for users who listed Immigration and Customs Enforcement as their employer. The dataset contained 1,595 entries: names, profile photos, job titles, and city-level locations. Lavigne posted the data on GitHub, with a companion essay on Medium. Both platforms removed the material within 24 hours under their anti-harassment and doxxing policies. Twitter suspended accounts that linked to the dataset. The Verge, TechCrunch, BuzzFeed News, and New York Magazine covered the takedowns that week. Days later, WikiLeaks republished the data as 'ICEPatrol' and framed the takedowns as censorship; Newsweek covered the republication on June 22. The episode set an early test of whether aggregating public LinkedIn data counted as doxxing under platform policies, since the underlying records were profile data anyone could find one entry at a time.
What the dataset did not contain
This is what made the takedowns controversial. The dataset included no home addresses and no phone numbers. As TechCrunch reported, it was LinkedIn profile data that anyone could find by searching one name at a time.
The platforms did not need home addresses to call it doxxing. They applied their policies to the aggregation itself, not to any single field. That was a new interpretation in 2018. In the years since, major platforms have increasingly treated aggregation itself as doxxing.
WikiLeaks republishes
Days later, WikiLeaks republished the dataset as "ICEPatrol" and framed the takedowns as censorship. Newsweek covered the republication on June 22.
The same sequence has repeated since. A U.S. platform hosts the data, the platform removes it under its policies, and a site outside U.S. jurisdiction republishes it. The 2025-2026 ICE List incident followed that pattern at a far larger scale and was hosted offshore from the start.
Why this case matters
The Lavigne case set an early baseline for what platform policies treat as doxxing. Data anyone could find one record at a time can still count as doxxing in aggregate. Department rosters, conference attendee lists, association directories, and LinkedIn profiles are all input to that kind of collection. An officer or federal agent who assumes a LinkedIn profile is harmless because it lists no address is missing how aggregation works.
The takedowns also did not stop the data from spreading. GitHub and Medium removed it within a day, and WikiLeaks republished it offshore. The platform-policy layer is real but partial. Once data is published, removing the original does not pull it back from mirrors.
What this means for you
LinkedIn and any public professional bio are part of your threat model. Department directories and rosters are the local version, and the same aggregation logic applies to both.
The step from a name to a home address runs through commercial broker sites. The Lavigne dataset held no addresses, but anyone could run the names through people-search and reverse-lookup pages and pull addresses anyway. That is the step a stalker would use against any sworn officer, and it points strangers toward a home and the people in it.
The defensive layer that does not depend on a takedown is continuous removal of those address records: filing opt-out requests across the commercial people-search sites, then refiling when a listing comes back.
For more on the doxxing chain, see /doxxing. For the federal-scale version of this threat, see the ICE List page.
What reduces this risk
The Lavigne dataset held LinkedIn profile data, not home addresses or phone numbers, so removing broker listings would not have stopped the scrape itself. The exposure that removal does reduce is downstream. Once a name is public, anyone can run it through commercial people-search and broker sites to find the home address attached to it, the same lookup a stalker would use against any sworn officer. LinkedIn profiles, department rosters, association directories, and conference programs are all input to that step. Platform takedowns are real but partial, and they do not pull data back from mirrors hosted outside U.S. jurisdiction. The layer that does not depend on a takedown is continuous removal of the address records that link a name to a residence. Frontline Privacy files opt-out requests across the commercial people-search sites we cover, then keeps checking so we can refile when a listing comes back.
Public sources
- A huge spreadsheet naming ICE employees gets yanked from GitHub and Medium — TechCrunch, 2018-06-21
- GitHub, Medium, and Twitter take down database of ICE employees — The Verge, 2018-06-19
- Medium Just Took Down A Post It Says Doxed ICE Employees — BuzzFeed News, 2018-06-19
- LinkedIn List of ICE Employees Removed by Medium and GitHub — New York Magazine / Intelligencer, 2018-06-20
- ICEPatrol: WikiLeaks Publishes Database of ICE Employees — Newsweek, 2018-06-22