JC JC Mobile App Studio
JC

Privacy , Tuesday July 28, 2026

His phone wiped itself during a border search. Now he is facing federal charges.

A US citizen returning through Atlanta was pulled into secondary inspection, handed over a passcode, and the phone erased itself. Prosecutors say that was a deliberate duress code and charged him with destroying property to prevent a seizure. It is reportedly the first case of its kind in the country, and it is a very clear window into what your phone's legal status actually is at the border. General information, not legal advice. Verified July 28, 2026.

An empty airport inspection area at night, a gray counter with a single empty tray, polished floor reflecting overhead lights.

Samuel Tunick, an Atlanta resident and US citizen, returned to the country through Hartsfield-Jackson in January 2025. CBP agents took him to secondary inspection and took his phone. He provided a passcode, and the contents were erased. The device ran GrapheneOS, a privacy-focused Android build that supports a duress passcode, a second code that wipes the device when entered.

Prosecutors charged him under 18 U.S.C. section 2232, which covers knowingly destroying property to prevent its seizure. His public defender argues the seizure was unlawful and that he was repeatedly denied access to a lawyer and never informed of his rights. A federal judge in Atlanta is expected to rule on the suppression motion later this year. Nothing here is proven, this is an active case and he has not been convicted of anything. (TechCrunch)

This is the part people do not want to hear. Inside the country, police generally need a warrant to search your phone. At the border, and that includes the international arrivals area of any airport, courts have long recognized a border search exception to the Fourth Amendment. Agents can look through your device without a warrant and without probable cause.

CBP's own policy splits this into two kinds of search. A basic search is an agent scrolling through your phone by hand, and it requires no suspicion at all. An advanced search means connecting your device to equipment that copies and analyzes its contents, and CBP policy requires reasonable suspicion of a legal violation plus a supervisor's sign off. Courts have not fully agreed on whether that reasonable suspicion standard is constitutionally required, and the answer has genuinely differed depending on which federal circuit you are in. The Seventh Circuit reaffirmed broad CBP authority again this month. (Global Immigration Blog)

Your status matters enormously here, and this is the single most important thing in this post.

US citizens cannot be denied entry into the country. You have a right to come home. You can decline to give up a passcode. What you cannot prevent is the consequence: agents can detain you for hours, and they can seize the device and keep it, sometimes for weeks or months, while they try to get into it. You go home, your phone does not.

Lawful permanent residents also generally cannot be denied entry, but refusing can trigger extended questioning and pressure, and green card status has more exposure than citizenship.

Visa holders and visitors have the weakest position by far. Refusing to unlock a device can be treated as a reason to deny you entry, full stop. If you are not a citizen or a resident, refusal is a much heavier decision.

Declining to provide a passcode and actively destroying data are treated as very different things. The first is a refusal to assist. The second is what this prosecution is about. Once a seizure is in progress, taking an action that wipes the device is the conduct the destruction of property statute reaches for. Whether a duress code counts, and whether it counts when the person may not have known the phone had been formally seized, is exactly what the court will decide.

There is a second trap: lying. Telling an agent you do not have a phone when you do, or giving a false statement about the device, is its own federal exposure under the false statements statute. Silence and declining are legally different from lying. If you take nothing else from this, take that.

The reliable protection here is not a clever trick at the checkpoint. It is not having the data on the device when you cross. A few things that work:

Travel light on data. The strongest position is a phone that genuinely has very little on it. Some people carry a separate clean travel phone. That is not paranoid, it is the same logic as not carrying your whole wallet on vacation.

Sign out and remove, do not just hide. Cloud data that is not downloaded to the phone is generally outside the scope of a border device search, and CBP policy directs agents to put devices in airplane mode or otherwise disable network access so the search covers what is on the device. Signing out of accounts and clearing local caches before you fly does real work.

Power the phone fully off before you land. A phone that has not been unlocked since boot is in its hardest cryptographic state on both iOS and Android. This is a meaningful difference, not a placebo.

Use a passcode, not just your face. Courts have generally treated compelling a passcode very differently from compelling a fingerprint or a face scan, because a passcode is something you know. Biometrics are convenient and they are also the easiest thing in the world to use on you while you are standing there. Turn off Face ID or fingerprint unlock before you get to the checkpoint. On an iPhone, holding the side button and a volume button until the power slider appears forces passcode-only unlock.

Do not use a duress wipe at a border checkpoint. Whatever you think of the prosecution in this case, the existence of the prosecution is the lesson. A feature that is smart protection against a thief is now a documented path to a federal charge when the person holding your phone is a federal agent.

Write down the details if it happens. Names, badge numbers, time, what was taken, and get a receipt for any device they keep, CBP uses Form 6051D. If it goes badly, ask for a lawyer clearly and out loud, and say it again even if you are told it does not apply.

I build apps that keep data on the device instead of on somebody's server, and stories like this are a reminder that on-device is a tradeoff, not a magic shield. Data on your phone is out of a company's reach, which is the whole point. It is also physically in your hand at a checkpoint. The right answer is not to give up on privacy, it is to be deliberate about what travels with you and to know the rules before you are standing in secondary inspection trying to figure them out.

This is general information, not legal advice. If you are facing an actual border search issue, talk to an attorney who does this work.

Sources: TechCrunch, Newsweek, Global Immigration Blog, and FindLaw. You can see what this studio builds at jcmobileappstudio.com/apps.

JC

Written by Josuam Collazo

A lifelong tech enthusiast in his mid-thirties who builds privacy-first iOS apps in his spare time and writes plain-language pieces on tech, money, on-device AI, and your rights at work, drawn from his own experience at work and in life. More about Josuam

More from the blog

Plain-language writing on tech, workers' rights, investing, and on-device AI.

Read the blog

Comments

Be kind and stay on topic. Comments are reviewed before they appear.

Contact

Get in touch.

Beta access, app ideas, bug reports, or partnership questions, the inbox is open.

Support available in English and Espanol.