LIVE · cybersecurity feed
Live wire
Australia Warns of Active Exploitation of Critical TeamCity Server FlawCVE-2026-21962 · Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical DataUS sanctions Iranian cyber actors as UK discloses power plant attackHackers target WordPress sites in miniOrange auth bypass attacksFake GTA 6 Extended Look and demo sites deliver an infostealerCVE-2026-63520 · Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)Fake Microsoft security scans trick victims into uninstalling their antivirusCVE-2026-19478 · ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and MoreThe Vulnerability Gap: Why Discovery Is Outrunning RepairCISA’s logging guidance works beyond government
security

The County Prosecutors Who Became ICE Informants

Illinois prosecutors shared defendants’ personal data with federal immigration agents without criminal warrants, public disclosure, or legislative oversight.

zeroday.news ·

Prosecutors in at least 17 Illinois counties have been found to have shared sensitive personal data of criminal defendants with federal immigration agents without obtaining criminal warrants, public disclosure, or legislative oversight. This collaboration, which occurred during the first 15 months of President Donald Trump's second term, involved state's attorneys' offices acting as informants for US Immigration and Customs Enforcement (ICE) and Homeland Security Investigations (HSI).

The practice was uncovered through an investigation that reviewed over 5,000 pages of internal emails and case files obtained via Freedom of Information Act (FOIA) requests from all 102 Illinois state's attorney's offices. These documents revealed that prosecutors shared details such as defendants' dates of birth, home addresses, upcoming court dates, and even police reports and photographs. In some instances, prosecutors proactively offered information, while in others, they responded to direct inquiries from federal agents.

One documented case involved Rolando Perez Samayoa, who was arrested for a DUI in Marion County in October 2024. In January 2025, Assistant State’s Attorney John Christeson emailed HSI agent Sergio Fulgencio, providing Samayoa's date of birth, address in Centralia, Illinois, and an upcoming court date. Fulgencio subsequently requested and received Samayoa's police report and related tickets. Three weeks later, federal agents apprehended Samayoa outside his home, also taking his 17-year-old son.

The collaboration raises questions about the effectiveness of Illinois' 2017 TRUST Act, a "sanctuary" law intended to prevent local law enforcement from assisting federal deportation efforts. While the act bars police and other agencies from aiding federal agents without a federal criminal warrant, it does not explicitly define whether prosecutors and their staff are subject to the same restrictions.

The investigation found that the sharing of information often occurred without the knowledge of defendants or their attorneys. The consequences of this collaboration were significant, with individuals flagged to ICE being detained and deported, leading to family separations.

In another instance, just 20 minutes after flagging Samayoa, Christeson contacted Fulgencio again about another individual with a local warrant. Fulgencio confirmed that agents were already tracking this person on a civil removal order. Christeson indicated that the county warrant would not take priority over removal, and within 34 minutes, Fulgencio reported that the individual was in ICE custody awaiting removal.

The records indicate that DuPage County, where one in five residents are foreign-born, had the most frequent contact with federal immigration agents among Illinois prosecutor's offices. Staff there both responded to ICE requests and proactively offered cases for federal agents to pursue. For example, in April 2025, a Customs and Border Protection officer at O'Hare International Airport requested records related to a voter fraud investigation from an assistant prosecutor, using an administrative subpoena rather than a judge-issued warrant.

Legal experts suggest that local officials might be tempted to use deportation as an easier path than criminal prosecution to "clear their docket," potentially undermining defendants' rights in criminal proceedings. Unlike criminal cases, which require proof beyond a reasonable doubt and appointed attorneys for indigent defendants, immigration removal proceedings are civil, have a lower legal standard of "clear and convincing evidence," and do not guarantee the right to an appointed lawyer. Once a defendant is turned over to ICE, the protections afforded by the criminal justice system are often lost.

While some prosecutor's offices in Illinois had limited contact with ICE, others, despite facing similar federal pressure, reported no contact or actively avoided collaboration. This suggests that each instance of collaboration was a deliberate choice. The Department of Homeland Security has not commented on its agents' work with local officials in Illinois. Advocacy groups, who championed the TRUST Act, contend that the revealed collaborations demonstrate a breach of trust between immigrant communities and the criminal justice system.

ShareXLinkedInWhatsAppFacebook

More News

view all →
malware

First Malware Built Specifically for Car Head Units Fuels Botnet

Kaspersky researchers have linked the malware to the BadBox botnet, which has ensnared millions of devices. The post First Malware Built Specifically for Car Head Units Fuels Botnet appeared first on SecurityWeek.

vulnerabilitycritical

Australia Warns of Active Exploitation of Critical TeamCity Server Flaw

Australian officials are urging TeamCity customers to patch an actively exploited critical flaw, which follows a similar warning from the US government

vulnerability

CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw

Disclosed in January and honeypots buzzed soon after, CISA says it’s finally time for the USG to plug the gap

malware

Fake Minecraft Clients Deliver WeedHack Malware Despite Infrastructure Takedown

A threat actor keeps spreading the WeedHack malware to Minecraft players despite its original infrastructure taken down in July

CVE-2026-73570

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks

At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday. About CVE-2026-73570 Zimbra Collaboration Suite (ZCS) is a communication and collaboration platform popular with organizations that need to have control over their data or can’t afford a pricy alternative service like Microsoft 365 or Google Wor

security

ReliaQuest Rejects Compromise Claims After ShinyHunters Incident

ReliaQuest has detailed a social engineering attack linked to ShinyHunters, denying reports that the threat actor successfully compromised its systems