During the summer 2020 protests in Portland, the Federal Protective Service, a Department of Homeland Security component, said that about 38 of its officers had been doxxed, with names, photos, and personal information posted online. The wave overlapped with the BlueLeaks dump, which exposed roughly 269 GB of internal police files dating back to 1996, and CBP authorized officers to cover their name tags because of the doxxing risk.
What happened
Beginning in June 2020, federal officers deployed to Portland during the protests after the murder of George Floyd were targeted in a sustained doxxing campaign. On July 21, 2020, Federal Protective Service Deputy Director of Operations Richard Cline said at a press conference that about 38 of the agency's officers had been doxxed, with names, photos, and in some cases home addresses or family details posted online. Acting CBP Commissioner Mark Morgan said separately that he had authorized officers to remove their names from their uniforms because of the doxxing risk, with each officer instead carrying a traceable identifier. The wave overlapped with BlueLeaks, a release of roughly 269 GB of internal law-enforcement files from more than 200 US agencies, published on June 19, 2020 by Distributed Denial of Secrets after a breach of the web developer Netsential, attributed to Anonymous. The BlueLeaks files spanned August 1996 through June 2020 and included internal bulletins, emails, reports, and in some files officers' personal details. Federal officials said they would pursue the people behind the Portland officer doxxing, but as of this writing no federal prosecutions of the 2020 campaign have been publicly reported.
How the officers were identified
The Portland doxxing drew on more than one channel.
The main channel for naming officers was face-to-name matching. Activists took photos of officers in tactical gear during protests, ran reverse-image and social-media searches, and identified officers by name even when they wore no visible name tags. Several officers were named publicly this way.
The channel that turned a name into a home address was the ordinary people-search broker page. Once an officer's name was known, a free or paid query against broker sites that aggregate property records, voter records, and adjacent public sources returned an address. That step runs quietly and does not depend on any leak.
The same weeks also saw BlueLeaks, a release of roughly 269 GB of internal documents from more than 200 US law-enforcement agencies, published on June 19, 2020 by Distributed Denial of Secrets after a breach of a web developer that served police fusion centers. BlueLeaks exposed police data broadly, though reporting has not established it as the source of the 38 officers' information.
Why this case matters
Portland 2020 is a reference case for how doxxing runs against federal law enforcement. The same pattern recurred in July 2025, when DHS said Antifa-affiliated groups in Portland had posted the names, photos, and home addresses of ICE officers, in some cases with details about their spouses and children. As of late 2025, no doxxing charges had been filed in that later wave either.
Attacks on federal judges' families drove judicial-security legislation. The Portland officer doxxing did not produce comparable federal protection for federal law enforcement. The federal Lieu Act lets covered federal judges demand removal of their personal information from data brokers, but it does not cover federal officers, agents, or federal prosecutors, and most state analogs of Daniel's Law do not name them either.
What this means for your own exposure
If you are a federal officer, agent, or federal prosecutor, the Portland pattern is the working model for how the chain runs against you. You get identified by face, your name gets published, and a broker query converts that name into your home address and the people who live there. The first steps depend on a protest cycle. The broker step is available on any day.
The Lieu Act helps if you are a judge. It does not help most federal law enforcement. What you can control is broker removal: find the broker pages that carry your name and address, demand removal, and refile when a listing comes back. State analogs to Daniel's Law sometimes cover federal officers and sometimes do not, so check the statute in your state. Frontline Privacy scans the broker pages that carry your information, files removals, and keeps checking as listings reappear.
For more on the doxxing threat shape and what to do if you have been doxxed, see /doxxing and /doxxing/recovery.
What reduces this risk
The Portland officers were identified mainly through activists circulating names, photos, and duty assignments on social media, including reverse-image searches that matched faces to names. Converting a known name into a home address then ran through ordinary people-search broker pages, which resell addresses tied to property and voter records. Large leaks and reverse-image matching depend on a protest cycle. Broker pages that resell home addresses by name are available every day, on any officer, whether or not a hack is in the news. The federal [Lieu Act](/laws/lieu-act) covers federal judges, not federal law enforcement, and state analogs to [Daniel's Law](/laws/daniels-law) differ on whether federal officers are covered at all. For most federal officers today, the protection they actually control is the broker removal they run or pay for, kept up after the protest cycle ends.
Public sources
- 38 Police Officers Have Been Doxxed During Protests in Portland, DHS Says — Newsweek, 2020-07-21
- Police officers' personal information leaked online, U.S. says — Portland Press Herald (AP), 2020-06-10
- Dozens of federal law enforcement officers in Portland doxed amid riots, officials say — Fox News, 2020-07-21
- CBP Chief Says Feds Don't Wear Name Badges Due to Fears of Being 'Doxxed' — Newsweek, 2020-07-22
- 'BlueLeaks' Exposes Files from Hundreds of Police Departments — Krebs on Security, 2020-06-22
- BlueLeaks — Wikipedia, 2026-04-01