EXCLUSIVE: Apple engineer says he was fired after refusing to send customer device IDs to AT&T
A 16-year employee alleges Apple’s carrier team shared IMEI numbers through unsecured email without required customer releases. Apple denies wrongdoing and says he was fired for just cause. A jury trial is set for November 2027.
By Ryan Merket · Published · Updated
Scoop: RuntimeWire original reporting.
Why it matters
The case puts Apple's privacy controls under scrutiny in the carrier-support operation where customer authorization depends on employees enforcing policy. Discovery could expose how serial numbers and mobile-network identifiers moved between Apple and AT&T.

On June 10, 2024, Apple placed a meeting on Toby Boardman’s calendar.
Boardman had just returned from a month of protected medical leave. He had asked to discuss accommodations for anxiety and obsessive-compulsive disorder. He had also repeatedly complained about his manager, whom he accused of punishing him for raising a customer-privacy concern. Boardman believed the meeting would finally address both issues.
Apple fired him the next day.
The company said his performance was the reason, according to a lawsuit Boardman filed in San Francisco Superior Court. Boardman says that explanation was a pretext. His version of the story begins three years earlier, inside Apple’s technical relationship with the largest wireless carriers in the United States, with a category of data capable of identifying nearly every phone on the network.
Boardman was an Enterprise Systems Engineer. When carrier technicians could not resolve a difficult problem involving an iPhone or cellular iPad, Apple’s account representatives could turn to engineers like him. One recurring request, the complaint says, was for Apple to take a device serial number and return its corresponding International Mobile Equipment Identity, or IMEI. Some requests concerned one device. Others involved batches of as many as 1,000.
Apple considered serial numbers and IMEIs personally identifiable information under its internal policies, Boardman alleges. Representatives working with carriers other than AT&T required the carrier to obtain a customer release before Apple supplied the data. The Apple representative assigned to AT&T did not enforce that requirement, according to the complaint. Boardman says the identifiers were then transmitted through “unsecured email communications.”
He reported the practice to his manager and sought guidance from Apple’s legal department. He alleges that the company never gave him a written response. When he raised the issue directly with his manager, Meg Fisher, Boardman says she told him to “stop being a pain” and move on.
Boardman did the opposite. He began refusing the AT&T requests.
The allegations appear in an employment lawsuit filed on January 22, 2026, against Apple and two of Boardman’s former managers. The case appears to have received no press coverage. Apple filed a general denial in March and said Boardman was terminated for “just cause and business reasons.” On July 14, Judge Rochelle East scheduled a jury trial for November 15, 2027.
No court has found that Apple or AT&T mishandled customer information, that the requested releases were legally required, or that Apple fired Boardman because he objected. The public file does not contain the disputed emails, the report Boardman says he made, the internal privacy policy he relied upon or an example of a customer whose data was shared. Apple’s answer does not specifically address the IMEI allegation.
The documents instead capture the beginning of a test. Apple has built its identity around the idea that privacy can be engineered into a product. Boardman’s case asks what happens when protecting personal information depends on an employee saying no to another employee.
Former Apple engineer Toby Boardman alleges that carrier requests could seek IMEI numbers for as many as 1,000 devices and that Apple’s AT&T representative failed to require customer releases. Source file: 10019732.pdf
The number behind the phone
Most people never need to know their phone’s IMEI. It appears in the device settings and, on some models, the packaging or hardware. Wireless networks use it to distinguish the physical device from the subscriber and the SIM card. AT&T describes the IMEI as a unique fingerprint for a phone. A carrier can use it to block a stolen device from its network. AT&T says carriers and law enforcement may also use it to help locate a device in some circumstances.
An IMEI is not a password. Possessing one does not provide access to the photos, messages or accounts on a phone. Its value comes from persistence and context. The identifier stays with the physical device. When joined with a serial number, customer record, service ticket or subscriber account, it can help connect hardware to an owner and to activity on a cellular network.
Apple’s current privacy policy says data capable of identifying a device, including its serial number, is personal data. A separate Apple Support privacy notice expressly includes a device’s serial and IMEI numbers among the personal data Apple may provide to an authorized service provider troubleshooting a particular issue. AT&T’s business privacy notice likewise includes IMEI and serial numbers in a category it calls “Device Identification Data.”
The sharing itself can be ordinary. Phones break. Enterprise customers enroll thousands of devices. Carriers need to investigate provisioning, activation and network failures. Apple’s support notice describes a defined process in which information is shared with a service provider working on the user’s case.
Consent and authorization determine whether that process is protective or promiscuous. A current AT&T agreement for automated device enrollment, published in 2025, requires a business customer to authorize AT&T before it supplies order information including IMEIs to an enrollment service. That agreement may have nothing to do with the support workflow Boardman encountered in 2021. It does show how an identifier can move lawfully between companies when the customer, purpose and destination are established.
Boardman alleges that Apple’s own release requirement served that role. His concern was not simply that AT&T knew an IMEI. Carriers necessarily process device identifiers. He says an Apple representative was requesting mappings from serial numbers to IMEIs without proving that the customer had authorized the disclosure, sometimes in large batches, and that Apple transmitted the results through email.
The phrase “unsecured email” carries more certainty than the complaint supports. It does not say whether the data appeared in the body of a message or an attachment, whether Apple’s mail systems encrypted the message in transit, whether the file was password-protected, or who received it at AT&T. The filing alleges an absence of consent and an unsafe channel without providing the underlying communications.
The potential consequence is still concrete. The National Institute of Standards and Technology has warned that IMEI and subscriber identifiers can be intercepted and used to track a phone or user. A list linking Apple serial numbers to mobile-network identifiers could be more useful than either list alone. Boardman says it could also end up with an unintended third party.
His lawsuit does not allege that this happened. It alleges that Apple was accepting the risk.
The carrier engineer
Boardman joined Apple in June 2008 and spent approximately 16 years at the company. His public professional profile closely matches the role described in the lawsuit. From 2013 through June 2024, he says he worked with Verizon, AT&T and T-Mobile, solving technical and business problems and helping their business customers deploy Apple devices at scale.
He operated, in the profile’s words, as an extension of carrier sales teams. That position placed him in the gap between a carrier’s account representative and Apple’s internal engineering organization. He could understand the customer’s problem, know what Apple data might resolve it and recognize when an ordinary request crossed an internal boundary.
The profile also complicates the word “customer.” Boardman worked heavily with business-to-business carrier teams and corporate deployments. A request involving 1,000 devices sounds more like an enterprise fleet than 1,000 unrelated consumers. The complaint repeatedly describes customer consent and safety risks to consumers, but it does not say whether the devices belonged to individuals, businesses or a mixture of both.
That distinction could affect the applicable contracts, the authorization chain and the harm. It does not erase the privacy question. An employer-owned phone can still be assigned to a person, associated with a line and linked to corporate information. It does mean the public record cannot support the broadest version of the allegation—that Apple exposed the identifiers of random iPhone owners to AT&T.
Boardman says the process looked different at other carriers. Their Apple account representatives required the carrier to secure a release from the customer before Apple provided the requested IMEIs. In 2021, he became aware that the representative assigned to AT&T was not requiring one.
The complaint does not identify that representative. It also does not explain how Boardman learned the releases were missing. An email requesting 1,000 identifiers would not necessarily show whether authorization had been collected elsewhere. The strongest version of his claim depends on records that have not yet entered the public file: the request, the policy, the release procedure and his internal report.
Boardman says he asked Fisher, then his manager, to forward his concerns to Apple’s legal department in late 2021. Fisher’s own website says she led Apple’s U.S. Enterprise Carrier Engineering team, corroborating the chain of command described in the lawsuit. Boardman alleges that he repeatedly asked both supervisors and Apple Legal for guidance and never received a written answer.
Then came the instruction he interpreted as Apple’s answer: stop being a pain.
Boardman says Apple and AT&T transmitted IMEI information through unsecured email and that his manager told him to ‘stop being a pain’ when he sought legal guidance. Apple denies the complaint’s allegations.
“Stay in your lane”
Boardman continued supporting the AT&T account, but he says he would no longer provide IMEIs when asked. He believed doing so without a release would be unlawful. The refusals brought complaints from the Apple representative working with AT&T, according to the lawsuit.
The dispute followed him into his next reporting line. Brian DeMan took over the team in late 2022. Boardman says DeMan reprimanded him over the refusals and told him to “stay in [his] lane.” Around the same period, Apple gave Boardman a negative annual performance review, a sharp departure from reviews that had described him as a valuable contributor who produced “truly outstanding work,” according to the complaint.
The lawsuit joins that whistleblower narrative with an unusually intimate account of Boardman’s mental health. In early 2022, he told Fisher that he was experiencing anxiety, obsessive-compulsive disorder and related symptoms. He said the unresolved privacy concern had become a fixation and was causing him distress. In January 2023, he disclosed his OCD to DeMan and asked to discuss ways to manage its effect on his work.
Those disclosures can be read in opposing ways. Boardman says Apple knew that he had a disability and failed to begin the interactive process required to identify reasonable accommodations. Apple’s answer says he received every accommodation he requested, while pleading that any additional accommodation may have been unreasonable or caused an undue hardship. The company also contends that its actions were taken for legitimate business reasons.
The pleadings leave open a question that will run through the case: Did Boardman’s persistence expose a privacy failure, or did Apple reasonably view that persistence as part of a performance problem?
Boardman says DeMan began changing the conditions around him. In mid-2023, DeMan imposed new performance goals across the team and told Boardman that the goalposts would be the same for everyone. Later, he assigned Boardman a project to develop a strategy for increasing product sales. Boardman alleges that DeMan moved the project’s requirements, added work that aggravated his condition, cancelled his meetings, denied support and undermined his progress.
He also says DeMan began requiring him to appear at Apple’s Cupertino headquarters once or twice a month. Boardman had worked remotely for years and traveled around the country. No other engineer at his level faced the same requirement, he alleges.
Apple denies that it discriminated, harassed or retaliated against Boardman. Its answer invokes managerial discretion and says changes in his employment were made in good faith for legitimate reasons. The company has not publicly supplied the performance metrics, project records or travel policies that would allow an outsider to compare the two accounts.
The privacy dispute and disability dispute eventually became inseparable. Boardman says Apple treated his fixation as evidence that he was difficult. He treated the same fixation as the reason the risk could no longer be ignored.
After disclosing OCD and anxiety, Boardman says he was reprimanded for refusing the AT&T requests and received a sharply worse performance review. Apple says its decisions were legitimate and nonretaliatory.
The meeting on June 11
On March 15, 2024, the conflict broke into the open during a midyear review. Boardman says DeMan criticized his performance and told him that he needed too much oversight for someone at his level. Boardman suffered what the complaint describes as a severe panic attack and mental breakdown. He was gasping for air. DeMan witnessed it, according to the lawsuit.
Boardman contacted human resources immediately afterward. He reported disability-based discrimination and harassment, said he was afraid of DeMan and asked Apple to intervene. His medical provider placed him on leave from March 18 through March 22.
When he returned, Boardman says nothing changed. On April 9, he reported DeMan again to Sandra Sanchez, identified in the complaint as an Apple human-resources lead. Sanchez suggested that he take another leave of absence, the lawsuit says. Boardman’s provider then placed him on leave from May 1 through May 30 under the California Family Rights Act.
The sequence matters because Boardman asked for accommodations as he came back. On May 30, he emailed DeMan to confirm his return and requested a discussion. He had obtained a doctor’s note recommending work restrictions and planned to provide it when DeMan returned from vacation.
Nobody held that discussion, according to the complaint.
Apple scheduled the meeting on June 10 and terminated Boardman on June 11. During the termination meeting, DeMan allegedly acknowledged that Boardman had told him “early last year” about his anxiety. Boardman says another Apple employee, Olivia Shipp, corroborated that statement.
Apple’s answer says the termination was supported by just cause and business reasons. It denies that Boardman was injured by any Apple act or omission and says its employment decisions were made in good faith. The answer raises 39 affirmative defenses, including that Boardman may not have been able to perform the essential functions of the job, failed to provide adequate information during the accommodations process, did not engage in protected activity and would have been terminated for legitimate reasons regardless.
Many of those defenses are pleaded conditionally and contain no supporting facts. They preserve arguments Apple may develop during discovery. They do not constitute evidence that Boardman committed misconduct or was unable to do the job.
The complaint contains a small but meaningful date conflict. An introductory paragraph says Boardman remained employed until June 18, 2024. The detailed chronology says he was fired June 11. His public profile lists only the month. The exact date should be established through his termination records before publication.
Boardman alleges that Apple fired him days after he returned from protected leave and before discussing his requested accommodations.
What Apple answered—and what it did not
Apple responded to the lawsuit on March 6 with a general denial. Its answer does not tell a competing story about the AT&T requests. There is no explanation of who requested the IMEIs, whether releases existed, how Apple transmitted the data or what its legal department did with Boardman’s report.
The company focused on the employment claims. It says its conduct was justified, that it discharged its legal obligations and that it took prompt remedial measures after learning of any alleged harassment. It denies authorizing or ratifying unlawful behavior by its employees. It says Boardman was an at-will employee and that legitimate reasons alone would have produced the same employment decisions.
Apple also alleges that Boardman received every accommodation he requested during his tenure. If he requested one he did not receive, the company says, it would have been unreasonable or created an undue hardship. The complaint’s assertion that no accommodations discussion occurred before the termination sits in direct conflict with that defense.
Boardman originally sued DeMan and Sanchez individually for harassment and intentional infliction of emotional distress. In April, the parties agreed to dismiss them without prejudice. The agreement does not exonerate either manager. It states that neither side will be treated as the prevailing party, bars the parties from telling the jury that the managers were once defendants and requires Apple to produce both of them for depositions and trial. Apple also agreed not to seek federal removal or another venue without first conferring with Boardman’s lawyers.
The arrangement leaves Apple as the defendant while preserving the testimony of the people Boardman accuses of carrying out the retaliation. It also keeps the case in San Francisco Superior Court, where a trial is now scheduled.
A trial date is an administrative milestone. It does not mean the judge has found Boardman’s claims likely to succeed, and many civil cases settle or end on motions before a jury is seated. The July order does establish that, six months after the complaint, the case remains active and is entering the long period of discovery in which the missing records can be demanded.
Apple generally denied every allegation and said it terminated Boardman for ‘just cause and business reasons.’ The answer does not specifically address the alleged IMEI-sharing process.
Judge Rochelle East scheduled a San Francisco jury trial for November 15, 2027. The scheduling order contains no finding on the merits.
The records that would decide the story
Boardman’s complaint is unusually specific about dialogue and dates. It is thin where the privacy allegation should eventually become verifiable.
The most important missing item is his late-2021 report. Its contents could show what Boardman knew, which Apple and AT&T employees were involved, whether he identified particular devices or accounts, and which laws or policies he thought were being violated. A delivery record could show whether it reached Apple Legal. Any response would reveal whether Apple investigated, rejected or corrected his concern.
The customer-release policy is equally important. Boardman says it existed and that representatives for other carriers followed it. The filing does not quote or attach it. Discovery could produce the policy, training materials, carrier-specific procedures and examples of completed releases.
Then there are the requests themselves. A support ticket or email could show whether AT&T sought a serial-to-IMEI mapping, how large the batches were and what authorization accompanied them. Email headers, attachment controls and access logs could clarify what “unsecured” meant in practice. Apple and AT&T should be able to say whether the process still exists and what changed after Boardman raised the concern.
Finally, the employment records could separate a whistleblower sequence from an ordinary performance dispute. Apple’s reviews before and after the report, the metrics applied to Boardman’s peers, the Cupertino attendance requirement, his accommodation correspondence and the final termination memorandum could either reinforce his chronology or dismantle it.
None of those records are attached to the complaint or Apple’s answer. That limitation should shape the reporting. This is a story about a serious allegation inside an active lawsuit. It is not evidence of a data breach. Boardman does not claim that hackers intercepted the IMEIs, that a customer suffered identity theft, or that AT&T used the data for an unauthorized commercial purpose.
His allegation is narrower and institutionally uncomfortable: An internal rule designed to establish consent allegedly became optional when a powerful carrier asked for data, and the engineer who refused to treat it that way says Apple removed him instead.
Privacy at human scale
Apple’s privacy engineering is most visible where software can make the decision. An iPhone can limit tracking, encrypt a message, isolate biometric data or require an app to request permission. These controls are repeatable. They operate whether the user is important, impatient or connected to the right employee.
Enterprise support is built from exceptions. A carrier needs an engineer to resolve an unusual activation failure. A large customer has hundreds of devices that must be enrolled. A serial number needs to be mapped to a network identifier. The work crosses companies, systems and professional roles. Someone has to decide whether the requester is authorized and whether the data can move.
The complaint describes a privacy control that lived at this human layer. The release did not prevent Apple from helping AT&T. It forced the request to carry evidence of consent. If Boardman’s account is accurate, the system failed because the evidence stopped being demanded.
Apple’s public policy says the company communicates privacy and security guidelines to employees and “strictly enforce[s]” safeguards across the company. Its support notice acknowledges that IMEIs can be shared with outside providers when they are troubleshooting a particular issue. These statements are compatible. They also reveal how much rests on the particular issue being real, the provider being the right one and the customer knowing that the exchange is happening.
Boardman’s lawsuit will turn on a narrower legal question: why Apple fired him. The public importance reaches past one engineer’s employment. The case may expose how one of the world’s most privacy-conscious companies handled device-identification data in the part of its business where policy met sales, support and a carrier important enough to have its own Apple team.
At 9:21 p.m. CDT on August 2, 2026, RuntimeWire sent detailed questions by email to Apple Media, Apple litigation counsel Karyn R. Moore, AT&T Media and Toby Boardman’s counsel, Mahru Madjidi. Apple was asked to forward the questions to Meg Fisher, Brian DeMan and Sandra Sanchez. None had responded by publication. RuntimeWire will update this story if responses arrive.
For now, Apple has supplied a legal answer rather than a technical one. It says Boardman was fired for just cause. It denies discrimination and retaliation. It has not explained in the public record whether the AT&T representative obtained releases, whether serial numbers were mapped to IMEIs in batches of 1,000, or whether those results traveled through ordinary email.
Those answers may exist in the records Boardman tried to create in 2021 and in the discovery that now lies ahead.
He says Apple told him to stop being a pain. If the case reaches trial, a jury will be asked whether his refusal to stop is why the company ended his career there.