Online Security & Privacy

Federal Prosecution of GrapheneOS User Marks First Case of Data Wiping Charges at US Border

In a legal move that has sent ripples through the digital privacy and civil liberties communities, the United States Department of Justice has initiated a landmark prosecution against an American citizen for allegedly utilizing a "duress" passcode to wipe his smartphone during a border inspection. This case, documented in recent federal indictments and court filings, represents what legal experts believe to be the first instance in United States history where an individual has been criminally charged for the destruction of digital data via specialized software features during a Customs and Border Protection (CBP) search. The defendant, Samuel Tunick, a resident of Atlanta, finds himself at the center of a high-stakes legal battle that pits the government’s broad authority at ports of entry against the individual’s right to digital privacy and the protection of sensitive data.

The prosecution stems from an incident that occurred in early 2025 at Hartsfield-Jackson Atlanta International Airport. According to court records, Tunick was returning to the United States from an overseas trip when he was flagged by CBP officers for secondary inspection. During this encounter, authorities demanded access to his mobile device. The government alleges that Tunick provided a passcode which, rather than unlocking the device for inspection, triggered a "wipe" command that erased the phone’s contents. This action has led to charges under a federal statute traditionally reserved for the physical destruction of evidence, marking a significant expansion of how such laws are applied to the digital realm.

The Chronology of the January 2025 Incident

The events leading to the indictment began on January 24, 2025, as Samuel Tunick arrived at Atlanta’s Hartsfield-Jackson airport, one of the world’s busiest international gateways. Upon his arrival, Tunick was diverted from the standard customs line into a secondary inspection area. This process is a routine but often intensive procedure where CBP officers exercise their "border search authority"—a legal doctrine that allows for searches of persons and property without a warrant or probable cause.

Tunick’s legal team, led by assistant federal public defender Matthew Dodge, asserts that the detention lasted for a significant duration, during which Tunick was repeatedly denied access to legal counsel. The defense claims that border agents pressured Tunick to provide the passcode to his device under the guise of an investigation into child exploitation material. However, the defense argues that this was a pretext, and that the government’s true interest lay in Tunick’s political affiliations.

According to the government’s indictment, when Tunick eventually provided a passcode, the officers entered it into the device. Immediately following the entry, the screen reportedly went blank, flashed several times, and the phone initiated a restart process. It was later determined that the digital contents of the device had been deleted. Despite the loss of data, authorities seized the physical device before eventually allowing Tunick to enter the country. The subsequent indictment, which notably contained a typographical error referring to the "Untied States Code," officially charged Tunick with the destruction of property to prevent its seizure.

Technical Context: GrapheneOS and the Duress Feature

The device in question was running GrapheneOS, a privacy- and security-focused mobile operating system. GrapheneOS is a hardened version of the Android Open Source Project (AOSP) and is frequently installed on Google Pixel hardware by users seeking enhanced protection against surveillance and data theft. It is favored by journalists, activists, and security professionals for its robust encryption and sandboxing capabilities.

One of the specific features of GrapheneOS is the "duress passcode." This feature allows a user to configure a secondary PIN or password that, when entered at the lock screen, triggers a specific action rather than granting access. In most configurations, this action is a "factory reset" or a secure wipe of the device’s encryption keys, rendering the data on the phone permanently inaccessible. The developer documentation for GrapheneOS explicitly lists this as a feature designed to protect sensitive information in situations where a user is being coerced into providing access to their device.

The use of this feature is at the heart of the DOJ’s case. Prosecutors argue that by setting and then providing this specific passcode, Tunick "knowingly" destroyed property—the digital data—to prevent it from being searched and seized by federal authorities. This marks a pivotal shift in the government’s approach to "anti-forensic" tools, moving from simply attempting to bypass them to prosecuting the act of using them as a criminal offense.

Legal Framework: 18 U.S.C. § 2232 and the Border Exception

The statute under which Tunick is being prosecuted is 18 U.S.C. § 2232, which deals with the "Destruction or removal of property to prevent seizure." Historically, this law has been applied to physical scenarios, such as a suspect throwing a bag of illicit substances out of a car window during a police chase or flushing evidence down a toilet. The application of this statute to the deletion of digital files on a personal device is a novel interpretation that has alarmed privacy advocates.

The case also highlights the ongoing controversy surrounding the "border search exception" to the Fourth Amendment. Under normal circumstances within the interior of the U.S., the Supreme Court ruled in the 2014 case Riley v. California that police generally must obtain a warrant to search the digital contents of a cell phone seized during an arrest, citing the immense amount of private data stored on modern devices. However, the U.S. government maintains that these protections are significantly diminished at the border.

The government’s long-standing position is that the border—and its functional equivalents, like international airports—constitutes a unique zone where the sovereign’s interest in protecting the nation outweighs individual privacy rights. Consequently, CBP claims the authority to perform "basic" searches (manually scrolling through a phone) and even "forensic" searches (using specialized software to extract data) without a warrant. While some lower courts have begun to require "reasonable suspicion" for forensic searches, the overall legal landscape remains heavily tilted in favor of the government at ports of entry.

The "Cop City" Connection and Political Implications

The defense has introduced a significant political dimension to the case, arguing that the search of Tunick’s phone was not a random customs check but a targeted attempt to gather intelligence on a specific political movement. Tunick is associated with "Defend the Atlanta Forest," a decentralized environmental and social justice movement that opposes the construction of the Atlanta Public Safety Training Center, colloquially known as "Cop City."

The $90 million training facility has been the subject of intense local and national protest for several years. The movement gained international attention following the fatal police shooting of activist Manuel "Tortuguita" Terán in 2023 and the subsequent racketeering (RICO) indictments of over 60 individuals linked to the protests. Tunick’s attorneys argue that the border agents’ claims of searching for child exploitation material were a "pretext" to gain access to communications and contacts related to the anti-Cop City movement.

This allegation of political targeting adds a layer of complexity to the case. If the defense can prove that the search was motivated by the defendant’s political beliefs or associations, it could bolster their motion to suppress the evidence, as the Fourth Amendment prohibits searches that are "unreasonable," and targeted harassment of political dissidents is a cornerstone of unreasonable search and seizure arguments.

Expert Reactions and Digital Rights Analysis

Security and legal experts have expressed concern over the precedent this case could set. Bill Budington, a senior staff technologist at the Electronic Frontier Foundation (EFF), noted that while the use of encryption is a standard security practice, the active destruction of data in the presence of law enforcement is a "legal minefield."

Runa Sandvik, a digital security expert and founder of Granitt, emphasized that this case serves as a stark warning to travelers. "I think this case serves as a reminder that authorities may argue you knowingly destroyed data," Sandvik said. She suggested that for high-risk individuals, such as journalists or activists, the safest course of action is to "not have that data on you when you cross certain borders." This "travel light" approach involves backing up data to secure cloud servers and wiping devices before travel, then restoring the data once the border has been crossed.

The EFF has long advocated for stricter limits on border device searches, arguing that the "border exception" should not extend to the vast digital archives contained in modern smartphones. They argue that a phone is not a "container" in the traditional sense, like a suitcase, but a portal to a person’s entire life, including private medical records, financial data, and privileged communications.

Broader Impact and Future Outlook

The outcome of the Tunick case will likely have significant implications for the future of digital privacy at U.S. borders. If the government is successful in its prosecution, it could pave the way for more frequent charges against individuals who use privacy-enhancing technologies. It might also discourage the development and use of "duress" features, as users fear that the very tools meant to protect them from coercion could lead to federal prison sentences.

Conversely, if Tunick’s motion to suppress is successful, it could signal a judicial tightening of the border search exception. A ruling that the seizure of the phone was unlawful because it was based on political targeting or lacked sufficient suspicion would be a major victory for civil liberties advocates.

The Atlanta federal court is expected to rule on the motion to suppress later this year. As the proceedings continue, the case remains a critical touchstone for the debate over how 18th-century constitutional protections apply to 21st-century technology. For now, the message from the Justice Department is clear: digital actions taken at the border have real-world legal consequences, and the use of software to thwart government searches will be met with the full force of federal law.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button