Apple Accused of Firing Engineer Who Refused To Share User Data With AT&T

An ex Apple engineer claims he faced workplace harassment and was then fired after refusing to share device data with AT&T without customer consent.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

Toby Boardman, an employee who worked at Apple for 16 years, has sued the company for allegedly transferring sensitive personal information without users’ authorization.[1]

Boardman alleges that he faced workplace harassment and discrimination after trying to raise the issue with his managers. He was ultimately fired in June 2024, following years of alleged workplace discrimination.

As per the complaint, Apple shared serial number and International Mobile Equipment Identity (IMEI) data mappings with AT&T without obtaining users’ consent.

This kind of data could allow network operators to map your identity to your device usage patterns, along with your location history. In the wrong hands, such data could be used for extensive surveillance and even lead to targeted cyberattacks, including phishing.

Here’s everything the lawsuit accuses Apple of and what it could mean for your privacy.

In this article
Allegations regarding private data sharing at Apple
Alleged workplace harassment at Apple
Apple denies the claims
How IMEI numbers are important for privacy
Bottom line

Allegations regarding private data sharing at Apple

Boardman worked as an enterprise systems engineer at Apple from 2013 to 2024 and describes himself as an extension of the carrier sales team.

Carrier account representatives routinely asked Apple to map particular devices’ serial numbers to their corresponding IMEI numbers. However, Boardman noticed a difference in how requests from other carriers were handled compared with those from AT&T.

As reported by Runtimewire, Boardman alleges that, under Apple’s policy, representatives were required to first obtain customer authorization before the company could hand over the IMEI mapping.

However, in the case of AT&T, this protocol was allegedly overlooked, and representatives allegedly shared the IMEI mappings without customer consent.

Moreover, Boardman also alleges that the data was shared over "unsecured email communications." However, the lawsuit doesn’t specify exactly how the data was shared or in what way the emails were unsecured.

If it was a case of the data being shared over unencrypted channels, that’s even more dangerous from a privacy standpoint, as it could pave the way for hackers to intercept and steal the data.

When Boardman became aware of this, he asked his manager at the time, Meg Fisher, to escalate the matter to Apple’s legal department in late 2021. However, he says he didn’t receive any written response from the legal team, while Fisher allegedly told him to "stop being a pain" and move on.

Boardman didn’t follow his manager’s advice and instead began personally refusing to fulfill AT&T’s IMEI requests without the required customer authorization. This created friction, after which an AT&T account representative complained about his refusals.

Boardman later informed Brian DeMan, the manager who took over in late 2022, about the issue. According to the lawsuit, DeMan told him to "stay in your lane."

Alleged workplace harassment at Apple

This is, unfortunately, just one sad half of the story. Boardman also accuses Apple of workplace harassment and retaliation as a result of the friction caused by his actions.

Here’s a chronological breakdown of what the lawsuit alleges.

  • Early 2022: Boardman tells his manager, Meg Fisher, that he is experiencing obsessive-compulsive disorder (OCD) and anxiety, largely due to the unresolved privacy issue he had raised in late 2021.
  • Late 2022: Brian DeMan takes over from Fisher and reprimands Boardman over his refusal to provide AT&T with the IMEI mappings. Around this time, Boardman also received a negative annual performance review — a complete turnaround from his previous reviews, which had described his work as outstanding.
  • January 2023: Boardman discusses his OCD with DeMan directly and asks to discuss accommodations to help manage its impact on his work.
  • Mid-2023: DeMan imposes new performance goals, telling Boardman that the standards are the same for everyone. Boardman alleges that DeMan assigned him a new sales strategy project, repeatedly changed the goalposts, canceled meetings, denied support, and added work that aggravated his condition. DeMan also required Boardman to travel to Apple’s Cupertino headquarters once or twice a month. Boardman alleges that no other engineer at his level faced the same requirement.
  • March 15, 2024: During a mid-year review, DeMan tells Boardman that he requires "too much oversight" for an employee at his level. Boardman suffers a severe panic attack and breaks down in front of DeMan, gasping for air. Next, Boardman immediately contacts HR and reports disability discrimination and harassment, also saying that he’s afraid of DeMan. He’s then placed on medical leave from March 18 to March 22.
  • March 22 to April 9, 2024: After returning to work, Boardman says that nothing had changed, prompting him to complain to HR lead Sandra Sanchez, who suggested that he take another leave of absence.
  • May 1 to May 30, 2024: Boardman’s doctor places him on protected leave under the California Family Rights Act.
  • May 30, 2024: Boardman emails DeMan to confirm his return and requests a meeting to discuss workplace accommodations. He also plans to provide DeMan with a doctor’s note recommending work restrictions. According to the complaint, no such meeting takes place.
  • June 10, 2024: Apple schedules a meeting on Boardman’s calendar, where he expects that both the AT&T issue and his accommodation request will be discussed.
  • June 11, 2024: Apple terminates Boardman’s employment, one day after the meeting was scheduled and before any accommodation discussions take place. According to the complaint, during the termination meeting, DeMan acknowledged that Boardman had disclosed his anxiety. The complaint also alleges that this was corroborated by another Apple employee, Olivia Shipp.
  • January 22, 2026: Boardman files a lawsuit in San Francisco Superior Court against Apple, Meg Fisher, and Brian DeMan.
  • April 2026: Fisher and DeMan are dismissed as individual defendants by agreement, without prejudice. Apple is still required to produce both for trial testimony and depositions.

The jury trial is currently scheduled for November 15, 2027.

Apple denies the claims

Apple responded with a general denial on March 6, focusing only on the employment-related claims.

The company said that Boardman was an at-will employee and that the employment decisions were made for legitimate, non-discriminatory reasons. The company also said that it took prompt remedial measures after becoming aware of the alleged harassment.

Apple also directly disputed Boardman’s allegation that no accommodation was ever discussed. According to the company, Boardman received every accommodation he requested, and any accommodations that weren’t provided would’ve been unreasonable.

However, Apple hasn’t addressed the allegations regarding the AT&T IMEI requests. There are no details on who requested the IMEI mappings or what process the company followed before providing them.

How IMEI numbers are important for privacy

To understand the privacy risks arising from such mapping, we first need to understand what a serial number and an IMEI are.

Every physical Apple device is assigned a unique serial number by the manufacturer. This is Apple’s internal way of identifying a specific physical unit. You can check your device’s serial number by navigating to Settings > General > About on an iPhone. It’s also printed on the device or its packaging.

The serial number allows Apple to verify your purchase record, AppleCare warranty status, repair history, and business or enterprise device management.

Network providers, such as AT&T, maintain information such as call activity, cell tower pings, data sessions, and location history. This data is organized and linked using the device’s International Mobile Equipment Identity (IMEI) number.

The IMEI is a unique 15-digit number assigned to each device on a mobile network, which helps providers block access to a phone when it is reported lost or stolen. Apple’s own privacy policy classifies both serial numbers and IMEIs as personal data, so it treats this information with the same sensitivity as other identifying details tied to a user.

Now, an IMEI number in itself is not harmful or useful to an attacker or malicious party, since it doesn’t disclose any information about the person who owns the device. However, in this case, the requests were made to map serial numbers to IMEI records.

When this happens, the network carrier could gain the ability to map your identity to your phone usage patterns, along with location details. Without this mapping, a network provider could only know that a particular device was near a given cell tower at a particular time.

However, with the serial number mapping, the provider could know that "Jane Doe was near this location at this time."

The privacy risks arising from such mapping include:

  1. If this data is exposed through a data breach or any other means, it could act as a ready-made surveillance dataset in the hands of a malicious party. It could be used to locate a person at a specific time since the gap between an anonymous device and an identified person has been closed.
  2. Companies could build a behavior-based profile without the person knowing that it happened in the first place.
  3. The data could also be repurposed or shared with third parties such as advertisers, marketers, law enforcement agencies, or other organizations. In the wrong hands, it could lead to highly personalized phishing attacks, which could steal more of your data and even spiral into financial fraud.

What makes this a bigger concern is that Boardman alleges these requests were not one-offs. According to the complaint, some requests covered as many as 1,000 devices at once, pointing toward bulk data transfers.

Bottom line

The lawsuit raises serious questions about Apple’s internal data-sharing policies and highlights the broader privacy risks associated with how network providers handle user data. However, Apple hasn’t addressed the allegations regarding the serial number-to-IMEI data mappings it allegedly provided to AT&T, and this silence is certainly noteworthy.

Additionally, Boardman’s workplace discrimination allegations are also quite serious and, according to the complaint, stem from the retaliation he allegedly faced after refusing to share such data with AT&T representatives without the required authorization. "Join us in illegal data sharing or get fired" sounds like the headline here, if all of this is true.

The case is now set to go to a jury trial on November 15, 2027, with more details likely to emerge as the matter remains in the discovery stage. Right now, though, if you’re generally concerned about your digital privacy and the data that’s been collected, you can use protection tools such as an identity theft protection service and a virtual private network (VPN) to help safeguard your data.

4.8
Editorial Rating
Get Deal
On DeleteMe's website
2026 Editors’ Choice
Best Data Removal for Couples
Privacy Protection
DeleteMe
PROMOTION: Use the Code PARTNER20 for 20% Off
  • Data removal service that covers 50–986 sites and re-scans every quarter to catch anything that reappears
  • Sends quarterly privacy reports showing what info was found, which brokers had your data, and how long each removal took
  • Includes email masking so you can share a stand-in address instead of your real one

Author Details
Krishi Chowdhary specializes in digital privacy, cybersecurity, and consumer technology. He has written extensively on online privacy tools and broader cybersecurity topics, including online scams, data breaches, age verification, and emerging digital threats. Krishi believes technology reporting should empower readers, not confuse them, and is committed to making even the most technical subjects easy to understand without compromising on accuracy or depth. His work has appeared in leading technology publications, including CNET, ExpressVPN, and TechRadar, where he has covered topics ranging from cybersecurity incidents and privacy product announcements to artificial intelligence and major technology news

Citations

[1] Toby Boardman’s lawsuit against Apple [PDF]