U.S. prosecutors have charged Atlanta resident Samuel Tunick with allegedly providing Customs and Border Protection officers a passcode that triggered the wiping of his GrapheneOS phone during a border search at Hartsfield-Jackson airport. The case is being described as a likely first-of-its-kind federal prosecution involving a phone's built-in duress password feature, which can erase device data when a designated code is entered instead of unlocking the handset.
Tunick has pleaded not guilty and is seeking to suppress the evidence, arguing that his detention, denial of counsel, and the seizure of his phone were unlawful. Defense attorneys also contend the investigation was tied to his association with the Cop City environmental movement rather than the child-exploitation-related basis initially cited by authorities, setting up a broader court fight over border device searches, privacy rights, and the legal consequences of anti-forensic mobile security features.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Tunick pleaded not guilty in the federal case and sought suppression of evidence, arguing that his detention, denial of counsel, and the seizure of his phone were unlawful. His attorneys also challenged the government's rationale for the investigation.
At Hartsfield-Jackson airport, U.S. Customs and Border Protection officers allegedly entered a passcode provided by Atlanta resident Samuel Tunick that caused his GrapheneOS phone to erase its contents during an attempted border search. The incident is described as the basis for what may be the first known U.S. federal prosecution involving a phone's duress-password wipe feature.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcescworld.com
Open sourcetechcrunch.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.