Skip to content
Authorities Used Israeli Technology to Spy on Boniface Mwangi, Citizen Lab Report Reveals

Authorities Used Israeli Technology to Spy on Boniface Mwangi, Citizen Lab Report Reveals

Kenyans.Co.Ke February 17, 2026

A new report has revealed details of advanced digital forensic technology allegedly being used by the government to access data from mobile phones, raising renewed concerns over privacy and state surveillance.

The findings were published on Tuesday, February 17, by Citizen Lab, a research centre that tracks digital threats against civil society. The Researchers working on the report say they have ‘high confidence’ that authorities deployed phone extraction tools capable of unlocking and copying data from seized devices.

The technology referenced in the report is developed by Cellebrite, an Israeli digital forensics company whose products are widely used by law enforcement agencies around the world to bypass phone security and retrieve stored information for investigations.

According to the researchers, such tools can allow for the full extraction of messages, call logs, emails, photos, financial records, saved passwords, and other sensitive files, depending on the condition and model of the device.

The revelations emerge amid concerns over digital surveillance in Kenya. In 2024, Citizen Lab revealed that spyware had been planted on the phones of Kenyan filmmakers while the devices were held in police custody during investigations tied to a documentary probing protest-related killings.

In that case, researchers concluded that the spyware was deployed while the phones were seized by authorities, prompting questions how confiscated electronics are handled and whether safeguards exist to prevent unauthorised access.

The latest report suggests that, beyond spyware, forensic extraction technology may also have been used in cases involving activists and government critics.

Among those cited is Boniface Mwangi, an activist and 2027 presidential hopeful who was apprehended in July last year and had his phones confiscated during the process.

Mwangi said that when his devices were returned to him, one of his personal phones was no longer password-protected, raising concerns that its contents may have been accessed while in state custody.

Citizen Lab researchers say the circumstances surrounding the device are consistent with the use of Cellebrite’s extraction tools, although the government has not publicly confirmed using the technology in this case.

Cellebrite has previously stated in response to similar allegations in other countries that its technology is intended for lawful investigations conducted under due process and that it reviews credible claims of misuse.

''Our analysis of the Samsung Android phone confiscated by the Kenyan police, belonging to Mwangi, shows signs that Cellebrite was used on the phone on or around July 20, 2025, and July 21, 2025. The device was in the custody of the Kenyan police during this timeframe,'' read part of the report.

Adding that, ''We observed traces of an application named com.client.appA on the Android phone. The Citizen Lab associates this application name with high confidence with Cellebrite’s forensic extraction technology. Other sources have also linked this indicator with Cellebrite’s forensic extraction technology.''

However, according to The Guardian , when the government was asked to respond to the revelations, it declined.

Extracted Entities

Attack Types (1)

Countries (1)

Platforms (1)

Tools (1)