US Charges Man for Using a Duress Password During a Border Phone Search

27.07.2026 3
US Charges Man for Using a Duress Password During a Border Phone Search

A US citizen is being prosecuted for entering a duress password on his own phone during a border search, in what lawyers and privacy researchers believe is the first case of its kind. Samuel Tunick handed border agents a passcode at Atlanta's Hartsfield-Jackson airport, the screen went dark, and the device wiped itself. The federal government has now charged him under a statute written for people who destroy property to stop it being seized. He has pleaded not guilty.

What happened at Hartsfield-Jackson

On 24 January 2025 Tunick landed in Atlanta returning from a trip abroad and was pulled aside for secondary inspection. Agents from Customs and Border Protection asked for access to his phone, saying they were looking for child exploitation imagery. According to his defence, no evidence was ever offered to justify that suspicion.

Tunick gave them a passcode. In the account filed with the court, the screen went blank, flashed several times and the phone appeared to restart. It was not restarting. The code he entered was a duress password, and the device had just erased itself. Agents seized the handset anyway and let him into the country. Eighteen months later the case became a federal indictment.

How a duress password works

Tunick's phone ran GrapheneOS, a privacy-focused Android alternative that installs on Google Pixel hardware. Among its features is a second passcode that looks exactly like the normal one but triggers an immediate wipe instead of unlocking. There is no warning dialogue, no confirmation prompt and no visible difference at the lock screen.

The wipe is not a slow file deletion that forensic tools can partially recover. The system destroys the encryption keys that make the stored data readable and powers the device down. Without those keys the remaining bytes are noise. That design is deliberate: the feature exists for journalists, activists and domestic abuse survivors who may be physically compelled to unlock a device, and a wipe that could be interrupted halfway would be useless to them.

The charge: a property statute pointed at encryption keys

Prosecutors reached for 18 U.S.C. section 2232(a), which covers anyone who, before, during or after a search or seizure by an authorised official, knowingly destroys, damages, wastes, disposes of or transfers property to prevent it being seized. The maximum sentence is five years.

The statute was written with physical evidence in mind: flushing drugs, burning documents, throwing a weapon off a bridge. Applying it here requires treating the data on a personal device, or the encryption keys protecting it, as the property being destroyed. The phone itself was not damaged at all. Agents took it away in working order.

  • The act charged: typing a code into a device the defendant owned, when asked for a code by an officer.
  • The property allegedly destroyed: data, not hardware. The handset survived and was seized intact.
  • The precedent at stake: whether a documented, shipped operating system feature becomes a crime the moment it is used in front of an official.

Bill Budington of the Electronic Frontier Foundation and security researcher Runa Sandvik both said they had never seen the provision used this way before.

What the defence argues

Tunick is represented by assistant federal public defender Matthew Dodge. The defence is running two lines at once. The first is procedural: the stop was pretextual, Tunick was repeatedly denied access to a lawyer, and he was never informed of his rights. The second goes to the charge itself, arguing that entering your own passcode into your own phone is not the destruction of property, and that no lawful seizure was under way at the moment he typed it.

That second point is the one with consequences beyond this defendant. If a passcode entry counts as destruction whenever an officer is watching, then any security feature that fails closed becomes legally hazardous. An Atlanta federal court is expected to rule on the motion to suppress later this year.

Important: Nothing here is legal advice, and the practical lesson from this case is not about which passcode to enter under pressure. It is that the decision is made much earlier, when you choose what data is on the device before you travel.

The border is a low-rights zone by design

This case only exists because of how thin constitutional protection is at a port of entry. CBP asserts authority to conduct basic searches of electronic devices without a warrant and without any particular suspicion, and courts have largely allowed the border exception to stand while circuits continue to disagree about advanced forensic searches.

The volume is rising. In fiscal year 2025 CBP searched 55,318 electronic devices, up 17.6 percent on the year before and up from 41,767 in 2023. Basic searches accounted for 50,922 of those, with 4,396 advanced searches involving analysis or copying of contents. Of the total, 13,590 involved US citizens. Set against roughly 419 million travellers, the odds for any individual remain under 0.01 percent, but the trend line has pointed one way for three years.

This is the category of exposure a VPN does not address, and it is worth being precise about why. Encrypting traffic protects data while it moves across a network; a border search takes the endpoint itself, where the data sits decrypted behind a lock screen. The same distinction we covered when looking at device-level identifiers that survive any tunnel applies here in physical form. Network privacy and device privacy are separate problems, and travellers who conflate them tend to protect the wrong one. For anyone tracking how far US entry screening may go, we also looked at the proposal to require ten years of social media, email and phone history for entry.

Conclusion

Conclusion: The duress password prosecution turns a shipped privacy feature into the alleged criminal act, and it does so on the terrain where rights are weakest. If the court accepts that entering a code on your own phone destroys property, the ruling reaches well past one traveller in Atlanta: it would put a legal shadow over every security design that wipes rather than yields. The motion to suppress, expected later this year, is the first real test.
Tags: usa privacy surveillance digital rights cybersecurity security vpn

Read also