All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
Toby Boardman, an employee who worked at Apple for 16 years, has sued the company for allegedly transferring sensitive personal information without users’ authorization.[1]
Boardman alleges that he faced workplace harassment and discrimination after trying to raise the issue with his managers. He was ultimately fired in June 2024, following years of alleged workplace discrimination.
As per the complaint, Apple shared serial number and International Mobile Equipment Identity (IMEI) data mappings with AT&T without obtaining users’ consent.
This kind of data could allow network operators to map your identity to your device usage patterns, along with your location history. In the wrong hands, such data could be used for extensive surveillance and even lead to targeted cyberattacks, including phishing.
Here’s everything the lawsuit accuses Apple of and what it could mean for your privacy.
Alleged workplace harassment at Apple
Apple denies the claims
How IMEI numbers are important for privacy
Bottom line
Allegations regarding private data sharing at Apple
Boardman worked as an enterprise systems engineer at Apple from 2013 to 2024 and describes himself as an extension of the carrier sales team.
Carrier account representatives routinely asked Apple to map particular devices’ serial numbers to their corresponding IMEI numbers. However, Boardman noticed a difference in how requests from other carriers were handled compared with those from AT&T.
As reported by Runtimewire, Boardman alleges that, under Apple’s policy, representatives were required to first obtain customer authorization before the company could hand over the IMEI mapping.
However, in the case of AT&T, this protocol was allegedly overlooked, and representatives allegedly shared the IMEI mappings without customer consent.
Moreover, Boardman also alleges that the data was shared over "unsecured email communications." However, the lawsuit doesn’t specify exactly how the data was shared or in what way the emails were unsecured.
If it was a case of the data being shared over unencrypted channels, that’s even more dangerous from a privacy standpoint, as it could pave the way for hackers to intercept and steal the data.
When Boardman became aware of this, he asked his manager at the time, Meg Fisher, to escalate the matter to Apple’s legal department in late 2021. However, he says he didn’t receive any written response from the legal team, while Fisher allegedly told him to "stop being a pain" and move on.
Boardman didn’t follow his manager’s advice and instead began personally refusing to fulfill AT&T’s IMEI requests without the required customer authorization. This created friction, after which an AT&T account representative complained about his refusals.
Boardman later informed Brian DeMan, the manager who took over in late 2022, about the issue. According to the lawsuit, DeMan told him to "stay in your lane."
Alleged workplace harassment at Apple
This is, unfortunately, just one sad half of the story. Boardman also accuses Apple of workplace harassment and retaliation as a result of the friction caused by his actions.
Here’s a chronological breakdown of what the lawsuit alleges.
- Early 2022: Boardman tells his manager, Meg Fisher, that he is experiencing obsessive-compulsive disorder (OCD) and anxiety, largely due to the unresolved privacy issue he had raised in late 2021.
- Late 2022: Brian DeMan takes over from Fisher and reprimands Boardman over his refusal to provide AT&T with the IMEI mappings. Around this time, Boardman also received a negative annual performance review — a complete turnaround from his previous reviews, which had described his work as outstanding.
- January 2023: Boardman discusses his OCD with DeMan directly and asks to discuss accommodations to help manage its impact on his work.
- Mid-2023: DeMan imposes new performance goals, telling Boardman that the standards are the same for everyone. Boardman alleges that DeMan assigned him a new sales strategy project, repeatedly changed the goalposts, canceled meetings, denied support, and added work that aggravated his condition. DeMan also required Boardman to travel to Apple’s Cupertino headquarters once or twice a month. Boardman alleges that no other engineer at his level faced the same requirement.
- March 15, 2024: During a mid-year review, DeMan tells Boardman that he requires "too much oversight" for an employee at his level. Boardman suffers a severe panic attack and breaks down in front of DeMan, gasping for air. Next, Boardman immediately contacts HR and reports disability discrimination and harassment, also saying that he’s afraid of DeMan. He’s then placed on medical leave from March 18 to March 22.
- March 22 to April 9, 2024: After returning to work, Boardman says that nothing had changed, prompting him to complain to HR lead Sandra Sanchez, who suggested that he take another leave of absence.
- May 1 to May 30, 2024: Boardman’s doctor places him on protected leave under the California Family Rights Act.
- May 30, 2024: Boardman emails DeMan to confirm his return and requests a meeting to discuss workplace accommodations. He also plans to provide DeMan with a doctor’s note recommending work restrictions. According to the complaint, no such meeting takes place.
- June 10, 2024: Apple schedules a meeting on Boardman’s calendar, where he expects that both the AT&T issue and his accommodation request will be discussed.
- June 11, 2024: Apple terminates Boardman’s employment, one day after the meeting was scheduled and before any accommodation discussions take place. According to the complaint, during the termination meeting, DeMan acknowledged that Boardman had disclosed his anxiety. The complaint also alleges that this was corroborated by another Apple employee, Olivia Shipp.
- January 22, 2026: Boardman files a lawsuit in San Francisco Superior Court against Apple, Meg Fisher, and Brian DeMan.
- April 2026: Fisher and DeMan are dismissed as individual defendants by agreement, without prejudice. Apple is still required to produce both for trial testimony and depositions.
The jury trial is currently scheduled for November 15, 2027.
Apple denies the claims
Apple responded with a general denial on March 6, focusing only on the employment-related claims.
The company said that Boardman was an at-will employee and that the employment decisions were made for legitimate, non-discriminatory reasons. The company also said that it took prompt remedial measures after becoming aware of the alleged harassment.
Apple also directly disputed Boardman’s allegation that no accommodation was ever discussed. According to the company, Boardman received every accommodation he requested, and any accommodations that weren’t provided would’ve been unreasonable.
However, Apple hasn’t addressed the allegations regarding the AT&T IMEI requests. There are no details on who requested the IMEI mappings or what process the company followed before providing them.
How IMEI numbers are important for privacy
To understand the privacy risks arising from such mapping, we first need to understand what a serial number and an IMEI are.
Every physical Apple device is assigned a unique serial number by the manufacturer. This is Apple’s internal way of identifying a specific physical unit. You can check your device’s serial number by navigating to Settings > General > About on an iPhone. It’s also printed on the device or its packaging.
The serial number allows Apple to verify your purchase record, AppleCare warranty status, repair history, and business or enterprise device management.
Network providers, such as AT&T, maintain information such as call activity, cell tower pings, data sessions, and location history. This data is organized and linked using the device’s International Mobile Equipment Identity (IMEI) number.
The IMEI is a unique 15-digit number assigned to each device on a mobile network, which helps providers block access to a phone when it is reported lost or stolen. Apple’s own privacy policy classifies both serial numbers and IMEIs as personal data, so it treats this information with the same sensitivity as other identifying details tied to a user.
Now, an IMEI number in itself is not harmful or useful to an attacker or malicious party, since it doesn’t disclose any information about the person who owns the device. However, in this case, the requests were made to map serial numbers to IMEI records.
When this happens, the network carrier could gain the ability to map your identity to your phone usage patterns, along with location details. Without this mapping, a network provider could only know that a particular device was near a given cell tower at a particular time.
However, with the serial number mapping, the provider could know that "Jane Doe was near this location at this time."
The privacy risks arising from such mapping include:
- If this data is exposed through a data breach or any other means, it could act as a ready-made surveillance dataset in the hands of a malicious party. It could be used to locate a person at a specific time since the gap between an anonymous device and an identified person has been closed.
- Companies could build a behavior-based profile without the person knowing that it happened in the first place.
- The data could also be repurposed or shared with third parties such as advertisers, marketers, law enforcement agencies, or other organizations. In the wrong hands, it could lead to highly personalized phishing attacks, which could steal more of your data and even spiral into financial fraud.
What makes this a bigger concern is that Boardman alleges these requests were not one-offs. According to the complaint, some requests covered as many as 1,000 devices at once, pointing toward bulk data transfers.
Bottom line
The lawsuit raises serious questions about Apple’s internal data-sharing policies and highlights the broader privacy risks associated with how network providers handle user data. However, Apple hasn’t addressed the allegations regarding the serial number-to-IMEI data mappings it allegedly provided to AT&T, and this silence is certainly noteworthy.
Additionally, Boardman’s workplace discrimination allegations are also quite serious and, according to the complaint, stem from the retaliation he allegedly faced after refusing to share such data with AT&T representatives without the required authorization. "Join us in illegal data sharing or get fired" sounds like the headline here, if all of this is true.
The case is now set to go to a jury trial on November 15, 2027, with more details likely to emerge as the matter remains in the discovery stage. Right now, though, if you’re generally concerned about your digital privacy and the data that’s been collected, you can use protection tools such as an identity theft protection service and a virtual private network (VPN) to help safeguard your data.