Back Mezha Citizen Lab reveals Cellebrite tool helped Russian authorities hack opposition phone
A court case shows forensic tools meant for law enforcement can be reused by hostile actors, revealing limits to vendor bans and monitoring.
As reported by Techcrunch
A new investigation raises questions whether Western companies that supply governments with tools to access mobile devices can reliably control their use once they fall into the hands of state authorities. According to Citizen Lab, Russia’s investigative authorities used a Cellebrite phone-hacking tool to crack the iPhone of local rights defender and opposition politician Andrey Pivovarov in June 2021, when he was in detention.
Three months earlier, Cellebrite announced that it would “immediately” suspend sales of its technologies to Russian government clients. On the company’s official site, the statement noted that as of March 2021, after breaking with Putin’s government, it “could disable device functionality or prevent software updates.”
This is not surprising, and it is a consequence of Cellebrite’s policies.
According to case materials, in May 2021 Russian authorities confiscated Pivovarov’s iPhone 12 and MacBook, after which investigators used UFED to extract data, including messages on WhatsApp and Telegram, as well as to for political terms and surnames of opposition figures.
Judicial documents also described the use of UFED to access data from the device, confirming potential abuse of the technology.
According to John Scott-Railton of Citizen Lab, Cellebrite should also remotely disable deployment after credible reports of abuse and end the era of plausible deniability by introducing cryptographically signed watermarks on all device images.
should also remotely disable deployment after credible reports of abuse and end the era of plausible deniability by introducing cryptographically signed watermarks on all device images.
In response to the Citizen Lab material, a Cellebrite spokesperson said they stopped all sales and services to the Russian Federation in March 2021, terminated existing licenses and began contract terminations, but the fact that UFED was used in the Pivovarov case casts doubt on the effectiveness of these statements.
From the case materials it is known that in May 2021 Russian investigators confiscated from Pivovarov’s personal devices the iPhone 12 and MacBook during the investigation.
Pivovarov was sentenced to four years in prison, but in August 2024 he was released as part of a prisoner exchange between Russia and Western countries, which also included the release of journalist Evan Gershkovich. The Russian Embassy in Washington did not respond to a request for .
This case demonstrates that even after announcements of severing ties and a ban on sales, former customers can continue to use the technology. It underscores the need for more transparent oversight mechanisms and traceability of the use of such tools by manufacturers.
The Cellebrite case underscores the need to strengthen accountability and precautionary mechanisms by cybersecurity technology manufacturers to prevent misuse and ensure control over the use of their products even after contract terminations.
Other news you may find interesting:
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
