Federal prosecutors are charging American Sam Tunick for allegedly using a duress password to erase his phone when agents tried to seize it at Atlanta's airport in January. His lawyers claim the detention was pretextual.
The US Department of Justice is prosecuting Sam Tunick for allegedly providing authorities with a "duress password" that wiped his phone during a seizure attempt at Hartsfield-Jackson International Airport on January 24, 2025.
Federal agents detained Tunick at the airport and questioned him about child exploitation images, according to court filings. When agents attempted to access his phone, Tunick allegedly provided a password that triggered an automatic data deletion.
Tunick's legal team contests the government's framing of events. In a motion filed in federal court, his lawyers argue the detention was "a pretext for a fishing expedition into Mr Tunick's connections" to the Stop Cop City movement in Atlanta—a campaign opposing a police training facility.
The charges raise questions about device security and border authority. US law enforcement claims broad search powers at borders, but the constitutional limits of those powers remain contested in courts. Duress passwords—designed to trigger data deletion under coercion—exist as a security feature in some encrypted devices, though using one to obstruct federal agents could constitute destruction of evidence or obstruction.
Tunick's case hinges partly on whether he intentionally activated the data wipe or if agents triggered it unknowingly. The motion also suggests the Stop Cop City connection indicates selective prosecution or pretextual investigation.
The case touches on tensions between digital privacy rights, border security authority, and law enforcement practice. It also reflects growing use of device security measures against government access—a topic that has divided technology companies, privacy advocates, and federal agencies for years.
Tunick remains in federal custody. The charges have not been adjudicated.
Hundreds of Customs and Border Protection employees allegedly exploited government databases to conduct unauthorized lookups on romantic interests and colleagues, according to records obtained by WIRED.
Taiwan's Ministry of Digital Affairs detected AI-assisted cyber-attacks targeting government agencies beginning July 20, marking what officials describe as a new threat category. The attacks reportedly originated overseas and have been characterized as a first-of-a-kind breach.
A data theft campaign exploits misconfigured Salesforce Experience Cloud and ServiceNow customer portals to harvest sensitive information. The attackers use custom tools to access data exposed to anonymous users.
A compromised AI package exposed credentials from 2,500 users in a large-scale supply-chain attack. Attackers scraped and exfiltrated terabytes of sensitive data.