First 'Duress Password' Phone-Wipe Case Hits US Border Law
24 Jul 2026
A first-of-its-kind case at the border
The U.S. Justice Department is prosecuting Samuel Tunick, an Atlanta resident, for allegedly giving Customs and Border Protection (CBP) agents a passcode that wiped the contents of his phone during a border search. This is believed to be the first known U.S. case in which federal prosecutors have charged someone for allegedly destroying data via a so-called "duress password" — a passcode designed to erase or lock down a device instead of unlocking it.
Tunick was taken into secondary inspection at Atlanta's Hartsfield-Jackson airport on January 24, 2025, upon returning from overseas. He has pleaded not guilty. His attorneys argue it was unlawful for CBP to seize his phone in the first place. A first hearing was held on a Monday, according to The Guardian, though the exact date wasn't specified in that report. An Atlanta federal court is expected to rule later this year on Tunick's motion to suppress evidence.
Legal experts say this is uncharted territory
Matthew Dodge, an assistant federal public defender on Tunick's legal team, said it's "incredibly rare" to see the federal statute in question used in an indictment. Digital rights advocates echoed that sentiment: Bill Buddington of the Electronic Frontier Foundation and independent digital security expert Runa Sandvik both said they had not seen a similar case involving duress passwords before. Sandvik noted she has discussed this exact scenario with activists and journalists for years — as a theoretical risk — but had never seen it actually prosecuted.
Several details remain unclear from public reporting so far: the specific charges and statute Tunick faces, what data or evidence CBP believed was on the phone or why it was seized, the current status of the suppression motion, and how CBP determined the passcode was a deliberate duress mechanism rather than a forgotten or mistyped code.
Why founders should care
This case sits at the intersection of digital privacy, border enforcement, and product design — and its outcome could ripple through the security tech space in a few plausible ways:
- Legal precedent risk. If the court rules against Tunick, it could set a precedent treating duress passwords — a feature already built into some security-focused apps and devices — as potentially criminal rather than a legitimate privacy safeguard. Founders building or planning such features should treat this as a live legal question, not settled law.
- Increased scrutiny at borders. Travelers, including founders and employees crossing borders with company devices, may face a higher likelihood of phone seizures or more invasive scrutiny as this case draws attention to device-wipe capabilities.
- Possible demand shift. Public debate around this case could increase interest in privacy and security tools designed for border-crossing scenarios — a potential opportunity for startups in this space, though the regulatory environment around such features is likely to stay uncertain until the case resolves.
- Compliance uncertainty. Until the Atlanta federal court rules on the motion to suppress, companies and individuals face genuine ambiguity about whether standard security features like duress passcodes could carry legal risk in similar circumstances.
Given how novel this case is — described by multiple experts as something they'd never seen prosecuted before — founders in privacy, security, or mobile device management should monitor the ruling closely, as it may shape both product design choices and messaging around security features for years to come.