№207|10:51 PM ET
Independent reporting on technology, markets & policy
TechEchelon
№01 / Anchor·CYBERSECURITY

U.S. Charges Citizen for Using Duress Password to Wipe Phone at Atlanta Airport

Federal prosecutors have charged American citizen Sam Tunick for allegedly using a GrapheneOS "duress password" to wipe his phone during a border detention at Atlanta's Hartsfield-Jackson airport in January 2025, testing a rarely invoked statute on destruction of property.

JG
Jay Goldberg
JUL 26, 2026 · 09:02 PM ET · 2 MIN READ
via Wikipedia (GrapheneOS)

Federal prosecutors are pursuing criminal charges against American citizen Sam Tunick for allegedly wiping his smartphone during a border detention at Atlanta's Hartsfield-Jackson International Airport on January 24th, 2025.

According to court documents, Tunick provided federal agents with a "duress password" — a feature of the privacy-focused mobile operating system GrapheneOS — that erased his device rather than unlocking it when entered. The government contends this constitutes a violation of a little-known and rarely invoked statute that prohibits the destruction or damage of property to prevent authorities from seizing it.

Agents detained Tunick at the airport while allegedly questioning him about child exploitation images. His attorneys, however, argue in a filed motion that this was "a pretext for a fishing expedition into Mr Tunick's connections" to the Stop Cop City movement in Atlanta.

The defense has challenged the legality of the detention and seizure on multiple grounds, arguing that all evidence gathered should be suppressed. According to Tunick's legal team, agents refused him access to an attorney, did not present a warrant, and did not inform him of his legal rights. The defense also alleges that access to his phone was sought under false pretenses.

The government has countered that it was not required to produce a warrant because Tunick had not yet been formally granted permission to enter the United States, a legal threshold that has become a key point of contention in the case.

Marlon Kautz, a member of the Atlanta Solidarity Fund, told a British newspaper earlier this week that "we all have a right to secure our private data against unconstitutional searches. And we should — especially in a time of rising authoritarianism."

The case turns on a narrow but significant legal question: whether activating a manufacturer-designed security feature that erases a device constitutes the criminal destruction of property. The statute the government is relying on is described by legal observers as seldom used in this context.

GrapheneOS is an Android-based operating system marketed around privacy and security features, including the ability to set alternate passwords that trigger a full device wipe. The duress password capability is designed to allow users to protect sensitive data in high-pressure situations — precisely the use Tunick's attorneys say he made of it.

The case arrives against a backdrop of intensified scrutiny of border device searches under the current administration. Entry into the United States has become a more complicated process for travelers, including citizens, who have reported hours-long detentions and examination of social media accounts.

How courts rule on the government's theory of criminal liability — that triggering a built-in software security feature equals destruction of property — could shape the legal landscape around digital privacy rights at the border for years to come.

JG
━ ABOUT THE REPORTER
Jay Goldberg

Jay Goldberg is a staff writer at TechEchelon covering technology, markets, and policy. He files the breaking news and deal coverage that move the publication's core desks.

More from Jay
● THE BRIEF · DAILY NEWSLETTER

Five stories every morning. Before the opening bell.

Written for readers who already know the basics — markets, AI, and the policy decisions that shape both.

Mon — Fri · 06:30 ET · Free

No spam · Unsubscribe anytime