The U.S. Justice Department has brought federal charges against Atlanta resident Samuel Tunick after border agents say he provided a passcode that triggered his phone to erase its contents when he returned to the United States. Media reports and the indictment indicate this may be the first known U.S. prosecution linked to a built‑in “duress” password that intentionally deletes device data.
What happened and when
According to a motion filed by Tunick’s lawyers, Tunick was taken to secondary inspection at Hartsfield–Jackson Atlanta International Airport on January 24, 2025, as he arrived from overseas. The government’s indictment alleges Tunick provided a passcode that caused the device to "delete the digital contents" before agents seized the phone. The document contains a typographical error referencing the “Untied States Code.”
The technology involved
Tunick’s attorneys confirmed the phone was running GrapheneOS, a custom Android operating system commonly used on Google Pixel devices. GrapheneOS includes an option that lets an owner configure a separate passcode which, if entered instead of the unlock code, deliberately wipes the device’s stored data.
Legal challenges from the defense
Tunick has pleaded not guilty and his lawyers moved to suppress the evidence, arguing the detention and seizure were unlawful. Their motion contends Tunick was repeatedly denied access to an attorney and was not informed of his legal rights during the secondary inspection. The defense further alleges that agents invoked the need to search for child exploitation imagery without presenting evidence to justify that suspicion.
The motion also claims the government’s actual interest was Tunick’s association with Defend the Atlanta Forest, an environmental movement opposing the construction of a large law enforcement training campus in Atlanta known as “Cop City.”
Criminal charge
Prosecutors charged Tunick under a federal statute that prohibits knowingly destroying or damaging property to prevent authorities from seizing it. Tunick has pleaded not guilty. Matthew Dodge, an assistant federal public defender representing Tunick, told TechCrunch that it is very unusual to see that federal statute used in an indictment.
Security technologists interviewed by TechCrunch—Bill Budington of the Electronic Frontier Foundation and Runa Sandvik, founder of security consultancy Granitt—said they had not seen prior cases brought using a duress password in this manner.
Broader implications: rights at the border
The case reignites questions about constitutional protections at the U.S. border, where the government has long maintained it can search and seize electronic devices without a warrant or court order until a traveler is admitted. The defense’s motion to suppress argues that Tunick’s treatment during the inspection violated his rights.
Experts note that while prosecutions like this appear rare, authorities could argue a person knowingly destroyed data. Runa Sandvik advised that travelers consider removing sensitive data before crossing certain borders and redownloading it after arrival. The Electronic Frontier Foundation offers guides on protecting data and understanding rights when crossing U.S. borders.
Next steps
The federal court in Atlanta is expected to rule on Tunick’s motion to suppress later this year. A Justice Department spokesperson did not respond to request for comment.
Summary
The Tunick case sits at the intersection of privacy technology and border search law: prosecutors allege he provided a passcode that wiped his phone, while his defense contends the seizure and questioning were unlawful. The outcome may shape how courts treat the use of built‑in data‑wiping passcodes and legal protections for devices at international borders.



