HomeSecurityCellebrite: Russia used UFED tool on detained activist's iPhone

Cellebrite: Russia used UFED tool on detained activist's iPhone

Cellebrite is at the center of a new revelation about the misuse of forensic tools by governments . According to an investigation by Citizen Lab published on June 25, 2026, Russian authorities used Cellebrite ’s UFED to hack the iPhone 12 of imprisoned opposition activist Andrey Pivovarov in June 2021 — three months after the company announced it was halting sales in Russia and Belarus. The case highlights a critical security flaw: the forensic tools lack a mechanism for remote deactivation and continue to operate offline even after the contract expires.

Cellebrite: Russia used UFED tool on detained activist's iPhone

Pivovarov led the Open Russia organization , an opposition group that the Kremlin has labeled “undesirable,” making it a criminal offense to join. He was arrested on May 31, 2021, at St. Petersburg airport while attempting to board a flight. Authorities confiscated his iPhone 12 and MacBook , without ever obtaining his consent or passwords. In July 2022, he was sentenced to four years in prison and released in August 2024 in a prisoner exchange.

See also: Citizen Lab: Cellebrite tool on activist's phone in Kenya

The activist turned over his phone to Citizen Lab researchers in the fall of 2025. Traces found on the device dated back to 2021, when he was in Russian custody. MobileLockdown files , which record trusted USB connections on an iPhone, showed a connection on June 17, 2021, to a host ID that matched a Cellebrite fingerprint found in a previous case in Jordan — providing strong evidence that the company’s UFED was used

Cellebrite UFED: What the official Russian report reveals

The Russian side indirectly confirms the findings. Pivovarov received during his trial the “ Forensic Expert Report No. 1269-17 ”, prepared for the Investigative Committee of Russia by the forensic center of the Ministry of Internal Affairs. The report explicitly mentions Cellebrite’s UFED Physical Analyzer and UFED 4PC tools, documenting the extraction of data from WhatsApp , Telegram and Viber . It also reveals searches for the “ Open Russia Civic Movement ” and names of opposition figures, such as Mikhail Khodorkovsky , lawyer Anastasiya Burakova and Pivovarov’s partner, Tatiana Usmanova .

Notably, the MacBook data extraction failed, as the encryption prevented access. Citizen Lab detected similar failed login attempts on the same date, confirming that authorities never had the activist’s password. This highlights the importance of strong encryption as a line of defense against forensic tools.

See also: Pegasus Spyware: Targeted iPhones of Journalists and Activists in Jordan

Cellebrite UFED forensic tool Russia activist Pivovarov

Cellebrite announced in March 2021 that it was halting sales to Russia and Belarus, following intense pressure following the revelation that Russian authorities had used the tool against Yulia Navalnaya and other associates of Alexei Navalny in 2020. However, this decision only applied to new sales and software updates — existing hardware remained functional . UFED operates offline and has no “ kill switch ” or remote deactivation mechanism, a fact that human rights organizations have been pointing out for years .

Cellebrite and the Threat to Activists: Wider Implications

The Pivovarov case is not an isolated one. It is estimated that Cellebrite legacy equipment remains operational in at least 12 countries after the expiration of their respective contracts, without any ability to remotely deactivate it. Ronald Deibert, director of Citizen Lab, has emphasized that “’s systems Cellebrite are designed to operate offline, and the company has not deployed any kill switch, despite the recommendations of human rights organizations.” For its part, Cellebrite stated that any use of legacy hardware in Russia after March 2021 is “completely unauthorized,” acknowledging, however, that it cannot prevent offline use.

Particularly worrisome is the connection to subsequent cyberespionage operations . The individuals whose names were searched on Pivovarov’s phone later appeared as targets of Operation COLDRIVER , a phishing campaign linked to the FSB . Burakova , for example, was targeted but did not respond to the attempts. While Citizen Lab does not claim a direct causal link, the mechanism is clear: extracting an activist’s contacts provides a ready-made list of targets for future campaigns.

See also: How to use NameDrop to exchange iPhone contacts

Cellebrite: Russia used UFED tool on detained activist's iPhone

Cellebrite is now moving to a subscription model with licenses that expire after their expiration — a change that has more legal than operational implications for cases like this one in 2021. Experts and organizations like Access Now are calling on forensic tool manufacturers to adopt mandatory remote deactivation mechanisms, regular checks of legacy equipment in high-risk countries, and stricter sales policies that align with international human rights standards. The Pivovarov case, according to The Hacker News, is a stark reminder that ethical sales policies alone are not enough — they also require technical enforcement.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS