A U.S. citizen returning through Atlanta allegedly gave customs officers a “duress passcode” that wiped his Android phone instead of unlocking it. Federal prosecutors now say that act amounted to obstruction of justice, raising a fascinating and consequential question for international travelers: how far can you go to protect your digital privacy at the border?
Traveler Faces Federal Charge After “Duress Passcode” Wipes Phone At Atlanta Airport
This sounds like a gadget Q would hand James Bond.
A traveler is stopped at the border and pressured to unlock his phone. Instead of providing the real passcode, he supplies a secondary code that quietly erases everything on the device.
But this is not fiction.
Federal prosecutors in Atlanta have charged Samuel Tunick, a U.S. citizen and Atlanta resident, with obstruction after he allegedly gave customs officers a duress passcode that triggered a complete wipe of his Android phone.
Tunick was stopped for questioning at Hartsfield-Jackson Atlanta International Airport on January 24, 2025, while returning from the Dominican Republic. Customs officers seized his phone, and prosecutors allege that the code he provided caused the device’s contents to be erased.
The phone reportedly ran GrapheneOS, an open-source, privacy-focused operating system available for certain Android devices.
How A Duress Passcode Works
A duress passcode is a secondary code configured in advance.
The normal passcode unlocks the phone. The duress code may appear to do the same thing, but instead initiates a factory reset or destroys encryption keys, rendering the data inaccessible.
The hardware remains intact. The information stored on it does not.
That distinction is central to the prosecution. The government’s theory is that the physical phone was merely the container. Officers had asserted authority to seize the data inside it, and entering the duress code was an intentional act designed to destroy that evidence.
The federal statute being used carries a maximum penalty of five years in prison, along with a potential fine.
Prosecutors do not necessarily have to prove that the erased data itself reflected a crime. The obstruction allegation rests on whether Tunick intentionally destroyed information to prevent the government from lawfully obtaining it.
The Border Search Question
The most important issue may be whether the phone search was lawful in the first place.
Border agents exercise unusually broad search powers at airports and other ports of entry. They often search luggage and electronic devices without the warrant that would ordinarily be required elsewhere.
That does not mean citizens have no constitutional protections at an airport, but the government traditionally receives far more latitude at the border, an issue we’ve discussed here before.
Tunick’s lawyers argue that he was targeted because of his opposition to Atlanta’s controversial police and fire training facility, commonly called “Cop City.” They also contend that he was unlawfully detained, was not advised of his rights, and was denied access to counsel.
The government has apparently revealed little about what it was originally investigating, a notable omission. It allows prosecutors to focus on the alleged destruction of data without publicly explaining why Tunick was stopped or what agents expected to find on his phone.
Deleting Your Phone Before Travel Is Different
Timing always matters.
A traveler who wipes a phone before leaving home may plausibly argue that he simply did not want to carry sensitive personal data across an international border.
That is very different from handing officers a code during an active search while knowing it will destroy the information they are attempting to access.
The first act may be characterized as preventative privacy protection. The second may be viewed as intentionally frustrating an imminent government seizure.
That does not resolve whether the underlying search was constitutional, but it explains why prosecutors believe this particular case crossed the line.
A Warning For International Travelers
I find warrantless searches of personal electronic devices deeply troubling.
A modern smartphone may contain years of private messages, photographs, financial records, medical information, travel history, passwords, and confidential work material. Searching a suitcase is intrusive. Searching a phone can expose nearly an entire life.
But travelers should also understand the risk of using a destructive duress feature once border agents have seized a device and demanded access.
Refusing to provide a passcode raises its own legal questions. Providing a code that actively deletes the contents is potentially far more dangerous.
The safest privacy strategy may be the least cinematic one: travel with as little sensitive data as possible, log out of accounts, and keep important material stored securely elsewhere rather than relying upon a self-destruct mechanism at the inspection desk.
CONCLUSION
Federal prosecutors have charged a U.S. citizen after he allegedly supplied customs officers with a duress passcode that wiped his phone during a border search at Atlanta Airport.
The case may become an important early test of how traditional obstruction laws apply to privacy tools designed to destroy data under pressure.
I remain uneasy about the government’s power to search phones without a warrant at the border. But intentionally triggering a data wipe after officers have already seized the device is a very different act from simply declining to cooperate.
James Bond might get away with it. But an ordinary traveler like Tunick may face five years in federal prison…
image: DHS



Had child porn on it, no other legitimate explanation.
He’s lucky he’s only facing 5 years.
Luck this cheap up for life!
You ‘projecting’ again?
Spoken like someone who has never valued their own privacy… (and, given your ‘work’…) So, basically, you’re just repeating the lame ole trope of: “if you have nothing to hide…”
There are legitimate reasons people protect their data—proprietary business information, medical records, legal communications, financial data, or a fundamental belief in privacy against arbitrary government searches.
In most contexts, if the government wants to search someone’s private property, they can get a warrant like the Constitution requires, rather than relying on a presumption of guilt.
Conflating the desire for basic digital privacy with criminality is how you sleepwalk into a police state.
This is incorrect. There are many other explanations.
Huh, interesting, because when the Secret Service deleted all its January 6, 2021, data that was totally fine. So, state-level data destruction is excused as administrative mishap or system migration, while individual-level data protection is prosecuted as a criminal felony. Nice double-standard we got there… /s
It’s pretty simple. It’s clear they were targeting him without cause and aware of his arrival (or someone recognized his name as to the opposition to Cop City. Release the information as to why. If they don’t it’s because they had no cause and were just harassing him. If there was legitimate suspicion of illegal activity they would have already presented that. Seems pretty clear that there wasn’t. Sorry, the border is not a no mans land of proper conduct when dealing with citizens (or even visitors). Good for him in defending his privacy.
I predict that Tunick, like the vindictive prosecution of David Hearn, the ex-Olympian at the Reflecting Pool, and many other cases like these, are going to end with the government failing, and a settlement in-favor of those they wrongly prosecuted. At least that’s my hope. If this administration pardoned all the J6ers, even the violent offenders, why should these absurd cases even proceed? It’s a PR-stunt; a deflection; and a waste of our taxpayer funds.
Meant to say lock this creep up for life!
Lock up the CBP officers? Ok, you’re the boss!