US charges American with reportedly erasing his phone with a 'duress' password amid border inspection

US charges American with reportedly erasing his phone with a ‘duress’ password amid border inspection

The U.S. Justice Department is taking legal action against an American accused of giving U.S. border officials a passcode that erased the data on his phone, as stated in an indictment and media coverage. 

This case is believed to be the first instance in the U.S. in which federal prosecutors have charged an individual for purportedly destroying data using a “duress” password embedded in the phone’s operating system.

According to The Guardian, which reported on the matter after the initial court hearing on Monday, Atlanta resident Samuel Tunick is challenging the allegations. Tunick’s legal representatives argue that it was illegal for U.S. Customs and Border Protection to confiscate his phone when he returned to the U.S. last year and that any evidence — including the supposed erasure of his phone — should be dismissed.

The case revolves around a function found in GrapheneOS, a tailored Android operating system that replaces the software typically on most modern Google Pixel devices. Tunick’s legal team confirmed that GrapheneOS was operational on his phone.

This software feature allows the phone’s owner to configure a passcode that intentionally erases the device’s data if entered instead of the standard unlock passcode.

Tunick’s situation also brings to light ongoing debates about the constitutional rights that can be invoked at the border, which the U.S. government has historically maintained is not considered U.S. territory until an individual is granted permission to enter.

The government’s indictment, which contains a typo (“Untied States Code”), claims Tunick allegedly provided a passcode to border officials that led to the phone “erasing the digital contents” before the device was taken.

Tunick’s legal team submitted a motion to suppress the evidence, asserting that the detention and confiscation were unlawful. The motion detailed that U.S. border authorities had subjected Tunick to a secondary inspection at Atlanta’s Hartsfield-Jackson airport upon his return from abroad on January 24, 2025, but he was continuously denied access to legal counsel and was not informed of his rights.

Tunick’s lawyers alleged that the government insisted on accessing his phone under the guise of searching for child exploitation material, yet failed to provide justification for its suspicions. His motion to suppress contended that the government was actually investigating him due to his affiliation with an enduring environmental movement named Defend the Atlanta Forest, which opposes the establishment of a vast training facility for law enforcement in Atlanta known as “Cop City.”

The motion stated that the border agents claimed they did not require a warrant to probe Tunick’s phone since he had not yet entered U.S. territory. The U.S. government has consistently asserted that it can inspect and seize individuals’ devices without a warrant or court authorization until they are allowed entry into the United States.

When Tunick provided his passcode and authorities entered it, “the screen went blank, flashed several times, and the phone seemed to restart.” The authorities confiscated his phone anyway, informing him that he was free to leave and could enter the United States.

Prosecutors subsequently charged Tunick under a federal law that renders it illegal to intentionally destroy or damage property to obstruct authorities from seizing it. Tunick has pleaded not guilty.

Matthew Dodge, an assistant federal public defender on Tunick’s legal team, informed TechCrunch that it is exceptionally uncommon to see this federal law applied in an indictment.

Security professionals also indicated that they had not encountered charges filed in this manner before.

Bill Budington, a senior staff technologist at the Electronic Frontier Foundation, and Runa Sandvik, a digital security expert who aims to protect vulnerable individuals as the founder of the security consultancy firm Granitt, told TechCrunch that they had not encountered analogous cases involving the application of duress passwords.

“I have not seen this before, although I’ve discussed potential scenarios with activists and journalists throughout the years,” remarked Sandvik. “I believe this case serves as a reminder that authorities may claim you intentionally destroyed data, so it’s advisable to not carry that data when crossing certain boundaries.” 

“With some advanced planning, you can always download the necessary data once you reach your destination,” added Sandvik. 

The Electronic Frontier Foundation offers resources on how to safeguard your data and security at the U.S. border, detailing your rights.

The Atlanta federal court presiding over the matter is anticipated to rule on Tunick’s motion to suppress later this year. A spokesperson for the Justice Department declined to provide comments when contacted by TechCrunch.

Updated to correct the spelling of a surname in the fifteenth paragraph.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.