Russia Used Cellebrite to Hack Phones After Ban
Published:
Russian authorities used expired phone-cracking technology from Cellebrite to access the device of imprisoned opposition figure Andrei Pivovarov, according to a report from Citizen Lab. The finding raises concerns about how long powerful forensic tools can remain usable after a company says it has stopped working with a government.
What the report found
Cellebrite, an Israeli company, makes tools that help law enforcement extract data from mobile devices. These systems are used by police forces around the world, including in the UK and the US. They can recover messages, contacts, app data and other information.
The concern in this case is not normal criminal investigation, but political surveillance. Pivovarov, who led the organization Open Russia, was arrested in 2021, later sentenced, and released in 2024 as part of a prisoner exchange. While his phone was in Russian government custody, investigators reportedly used Cellebrite’s UFED product to examine its contents.
Citizen Lab said it found strong evidence that Cellebrite technology was used on Pivovarov’s phone in June 2021. Researchers also reviewed court documents provided by Pivovarov, which they said confirmed the use of Cellebrite’s forensic tools during the criminal case against him.
The extracted information reportedly included details about Pivovarov’s contacts, messages and personal and professional communications. Data from messaging apps including WhatsApp and Viber was also said to be among the material gathered by authorities.

Fig 1. A Cellebrite UFED device used for forensic data extraction. (Source: Cellebrite)
Why phone data can put others at risk
A phone rarely contains information about just one person. Contacts, chats, call records and shared files can expose friends, colleagues, journalists, activists and family members. In political cases, that kind of access can put an entire network of people at risk.
Citizen Lab also said some people connected to Pivovarov were later targeted by Coldriver, a hacking group linked to Russia. The researchers did not say this proved Cellebrite data directly enabled those attacks, but said the connection deserved further investigation.
The timing is important. Cellebrite said in March 2021 that it had stopped selling its products and services to Russia and Belarus. The reported use of its tool after that point has raised questions about whether companies can effectively shut off older digital forensic systems once they are already in government hands.
Citizen Lab said Cellebrite’s older systems historically included offline capabilities, meaning they could continue to function without ongoing updates or direct support. That design may make it difficult for a company to immediately stop a former customer from using previously purchased hardware or software.
What Cellebrite says and what users can learn
Cellebrite has said any use of its legacy hardware in Russia after March 2021 was unauthorized. The company also said older tools sold before that date would now be incompatible with modern devices and would operate without its support, consent or legal approval. Russia remains permanently restricted as a customer.
The case highlights a wider cybersecurity and human rights issue. Tools built to help police investigate crime can become dangerous when used by governments against critics, campaigners or journalists. Once a phone is unlocked, the information inside can be copied, searched and used in ways the owner cannot control.
For everyday phone users, the risk of being targeted by a government forensic tool is low. But the case is a reminder that phones hold extremely sensitive information, often far beyond what people realize. Strong passcodes, encrypted messaging apps and regular software updates cannot stop every advanced attack, but they can make unauthorized access harder.