U.S. Prosecutes Atlanta Man for Using Duress Password to Wipe Phone During Border Search

The U.S. Justice Department is prosecuting Samuel Tunick, an Atlanta resident, for allegedly providing Customs and Border Protection agents with a passcode that wiped the contents of his phone during a secondary inspection at Hartsfield-Jackson airport. The case, reported by TechCrunch on July 24, 2026, is thought to be the first in the United States where federal prosecutors have charged someone for alleged destruction of data using a duress password built into a phone's operating system.
Tunick was returning from overseas on January 24, 2025, when CBP pulled him into secondary inspection. His phone was running GrapheneOS, a custom Android distribution designed for privacy and security hardening. GrapheneOS includes a duress password feature: entering it instead of the normal unlock passcode wipes the device's storage. When border agents entered the passcode Tunick provided, the screen went blank, flashed several times, and the phone appeared to restart.
The indictment, which contains a typo reading "Untied States Code" instead of "United States Code," charges Tunick under 18 U.S.C. § 2232, a statute that makes it unlawful to knowingly destroy or damage property to prevent authorities from seizing it. The indictment accuses Tunick of providing a passcode that caused the phone to "delete the digital contents" prior to the device being seized. Tunick has pleaded not guilty.
Border agents claimed they did not need a warrant to search the phone because Tunick had not yet crossed the U.S. border, invoking the broad search authority CBP exercises at ports of entry. This is the legal foundation that distinguishes border searches from domestic searches under the Fourth Amendment's border search exception, and it places the Tunick case squarely within a long-running tension between border search authority and digital privacy.
Tunick's defense attorney, Matthew Dodge, an assistant federal public defender, has filed a motion to suppress the evidence, arguing the detention and seizure were unlawful. The motion alleges that Tunick was repeatedly denied access to an attorney and was not informed of his legal rights during secondary inspection. It further accuses the government of demanding access to his phone under the pretext of searching for child exploitation imagery without evidence to justify its suspicion. The motion argues the government was instead investigating Tunick over his association with the Defend the Atlanta Forest movement, which opposes the "Cop City" law enforcement training campus.
The first court hearing in the case was held on Monday, July 20, 2026. The Guardian had covered the case earlier in the same week, and the Associated Press also published a wire story on July 24.
GrapheneOS's duress feature is not unique in concept. Several privacy-focused mobile platforms and applications have offered similar functionality, though implementation details vary. The feature is designed for scenarios where a user is compelled under threat to surrender a passcode; entering the duress PIN or password triggers irreversible data deletion rather than unlocking the device. The technology sits at the intersection of legitimate privacy protection and legal obligations to comply with law enforcement, and the Tunick case is the first known U.S. prosecution to test that intersection in federal court.
Worth flagging: the statute invoked here, 18 U.S.C. § 2232, was written to address physical destruction of property, not the automated, software-triggered erasure of data on a device the user owns. Whether courts will treat a duress-password wipe as equivalent to, say, burning documents to prevent their seizure is an open legal question, and the outcome will shape how both privacy software developers and law enforcement approach device searches at the border going forward.
The motion to suppress raises a separate set of concerns that go beyond the duress-password charge. If the court finds that CBP denied Tunick counsel and conducted a pretextual search, the suppression of evidence could follow regardless of the wipe. The government's justification for the search, and whether it can establish individualized suspicion, will likely be contested.
For the privacy and security community, the case lands at a moment of heightened attention to both mobile device security and government surveillance practices. GrapheneOS has gained visibility as a hardened Android alternative, and a prosecution targeting its duress feature will draw scrutiny from developers, civil liberties groups, and anyone who configures devices for high-risk users. The legal precedent set here, if the case proceeds to trial, could influence how duress features are designed, documented, and deployed.
In this author's view, the core tension is not going away. Devices will continue to offer stronger self-protective capabilities, and border authorities will continue to assert broad search powers. What the Tunick case determines is whether using a built-in security feature to protect data from seizure constitutes a federal crime. That is a consequential question, and one worth watching closely.


