HomeinetCitizen Lab: Cellebrite tool on activist's phone in Kenya

Citizen Lab: Cellebrite tool on activist's phone in Kenya

New research from Citizen Lab has uncovered evidence that Kenyan authorities used a commercial data extraction tool made by Israeli company Cellebrite to hack the phone of a prominent dissident, marking yet another case of technology abuse targeting civil society.

See also: iPhone spyware: How to tell if you're being monitored

Citizen Lab

The interdisciplinary research unit at the University of Toronto's Munk School of Global Affairs & Public Policy reported evidence on a personal phone belonging to Boniface Mwangi , a Kenyan pro-democracy activist who has announced plans to run for president in 2027.

Celebrite's data extraction tools were specifically used on his Samsung phone while he was in police custody following his arrest in July 2025. The phone was returned to him almost two months later, in September, at which point Mwangi discovered that it was no longer password-protected and could be unlocked without a password. It has been assessed with high confidence that Celebrite's technology was used on the phone around July 20 and 21, 2025.

“The use of Cellebrite could have allowed the complete extraction of all materials from Mwangi’s device, including messages, private materials, personal files, financial information, passwords, and other sensitive information,” Citizen Lab said.

See also: GhostChat Spyware Targets Android Users

Citizen Lab: Cellebrite tool on activist's phone in Kenya

These findings follow a separate report released last month that said officials in Jordan likely used Cellebrite to extract information from the cellphones of activists and human rights defenders who were critical of Israel and supportive of the Palestinians in Gaza. The devices were seized by Jordanian authorities during detentions, arrests and interrogations and then returned to their owners.

These documented incidents occurred between late 2023 and mid-2025, according to Citizen Lab.

In response to the findings, a Cellebrite spokesperson told the Guardian that the company’s technology is used to “access private data only in accordance with due process or with appropriate consent to lawfully assist investigations following an incident.”

See also: Zoom Stealer extensions collect corporate meeting information

Citizen Lab: Cellebrite tool on activist's phone in Kenya

These two cases contribute to a growing body of evidence documenting the misuse of Cellebrite's technology by government customers and reflect a broader ecosystem of surveillance abuses by various governments worldwide, enabling highly targeted surveillance using mercenary spyware such as Pegasus and Predator.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS