A look at the FBI's January 6 investigation geofence warrant: Google identified 5K+ devices; dozens appear to have been in airplane mode or had data deleted
Google provided investigators with location data for more than 5,000 devices as part of the federal investigation into the attack on the US Capitol.
Context & Ripple Effects
The January 6 geofence warrant is the largest known use of the technique Google itself disclosed when it first published request volumes — 8.3K geofence warrants in 2019 rising to 11K in 2020. It converts that volume into a single case: one warrant, 5,000+ devices, most of whom were near the Capitol rather than suspects.
The arc runs from resistance to routine compliance: Google refused a comparable blanket location demand back in 2018, then supplied the data here, and an investigation found 45 criminal cases resting on Google geolocation evidence from this warrant. Years later Google lost a court fight against an even broader keyword-search warrant in the pipe bomb probe — the perimeter keeps widening.
First-order effects
- Dozens of the 5,000+ devices showing airplane mode or deleted data directly weaken the evidentiary base of the 45 cases already citing Google geolocation data, giving defense counsel a concrete gap-and-deletion argument.
Second-order effects
- The airplane-mode finding teaches every future subject of a geofence warrant the countermeasure, degrading the technique's yield just as federal agencies lean on it harder — pressure that shows up again in Google's lost fight over the 300+-user keyword warrant.
Third-order effects
- If device-level evasion scales while courts side with investigators, the battleground shifts from whether Google complies to how far warrants reach — from passive location sweeps toward active data like search queries, with bystander privacy as the standing casualty.
The trend: Law enforcement is escalating from geofenced location dragnets to broader digital-evidence demands, and courts are increasingly letting them through.