# Russia Used Cellebrite Forensic Tools on Jailed Activist's iPhone Months After Sales Cutoff
A new investigation reveals Russian authorities leveraged Cellebrite's UFED digital forensic platform to extract data from opposition activist Andrey Pivovarov's iPhone in June 2021—three months after the Israeli firm announced it would halt sales to Russia and Belarus. The finding, published by the Citizen Lab on June 25, 2026, exposes a critical vulnerability in corporate export restrictions: existing hardware continues operating long after official supply chains are severed, providing authoritarian governments with persistent access to sophisticated surveillance tools.
## The Incident: Forensic Evidence of State Surveillance
Andrey Pivovarov, director of Open Russia, an opposition movement the Kremlin had designated "undesirable" under Russian law, was detained on May 31, 2021, when Russian Federal Security Service (FSB) agents removed him from a flight at St. Petersburg airport. Authorities confiscated his iPhone 12 and MacBook Pro without his consent and without obtaining his device passwords.
The Citizen Lab's investigation, conducted in partnership with Access Now, uncovered evidence that Cellebrite's UFED (Universal Forensic Extraction Device) Physical Analyzer and UFED 4PC were used to extract data from Pivovarov's phone while it remained in Russian custody. The research identified this through two converging lines of evidence:
1. Device forensics: MobileLockdown records on the iPhone revealed a USB pairing to a host device on June 17, 2021, with a fingerprint matching previously identified Cellebrite UFED hardware
2. Official documentation: Russian authorities provided Pivovarov with a "Forensic Expert Report No. 1269-17," prepared by the Interior Ministry's forensic center for the Investigative Committee, which explicitly names Cellebrite tools and documents the extraction process
## Technical Details: What Was Extracted
The official Russian forensic report documents a comprehensive data extraction from Pivovarov's device, including:
| Data Source | Status |
|---|---|
| WhatsApp | Successfully extracted |
| Telegram | Successfully extracted |
| Viber | Successfully extracted |
| Contact databases | Successfully extracted |
| iPhone system logs | Captured for analysis |
| MacBook Pro | Extraction failed (encrypted) |
The forensic analysts then conducted targeted searches within the extracted data for:
- Mikhail Khodorkovsky (imprisoned oligarch and Putin critic)
- Anastasiya Burakova (human rights attorney)
- Tatiana Usmanova (Pivovarov's partner)
The MacBook, protected by full-disk encryption, resisted the extraction attempt. Matching failed login attempts in the forensic record confirm authorities lacked Pivovarov's password and could not bypass the encryption.
## Background: The Supply Chain Gap
Cellebrite, the world's largest commercial digital forensics vendor, announced in March 2021 that it would cease selling to Russia and Belarus in response to geopolitical tensions and concerns over human rights abuses. The decision was widely praised as a rare example of corporate accountability in the surveillance technology space.
However, the announcement created a critical blind spot: existing hardware already deployed in Russian law enforcement and intelligence agencies continued to function offline. Unlike cloud-dependent or subscription-based systems, UFED devices can extract data independently once physically connected to a seized device. They require no internet connectivity, no license server validation, and no ongoing technical support.
Cellebrite's response to the Citizen Lab's findings on June 22, 2026, acknowledged this limitation obliquely. The company stated:
> "Any use of Cellebrite legacy hardware in Russia after March 2021 is entirely unauthorized. This hardware runs without our support or consent and would be incompatible with modern devices today."
The key phrase—"legacy hardware"—underscores the problem: tools sold before March 2021 remain fully operational years later, providing persistent forensic access regardless of corporate policy changes.
## Implications for Digital Rights and Authoritarian Practice
The Pivovarov case illustrates several troubling trends:
Political Persecution Enabled by Digital Forensics
Pivovarov's prosecution relied heavily on evidence extracted without consent using Cellebrite. He was sentenced to four years in prison in July 2022 based partially on data extracted from his phone. While he was freed in a prisoner exchange in August 2024, the extraction of his communications provided Russian prosecutors with a roadmap of his political network—precisely what the searches for opposition figures suggest authorities were seeking.
Pattern Overlap with Targeted Phishing
The Citizen Lab notes that several people whose names appear in Pivovarov's extracted data later became targets of COLDRIVER, an FSB-linked phishing operation. Specifically, human rights lawyer Anastasiya Burakova was targeted but did not fall for the phishing attempt. While the Citizen Lab stops short of claiming a direct causal link, the pattern is suggestive: digital forensics on one activist's device can yield contact lists and social networks that inform future targeting of other activists.
Export Control Loopholes in Surveillance Technology
The case exposes a systemic problem with how democracies regulate dual-use surveillance technology:
## Why This Matters: The Surveillance Technology Supply Chain
This incident reveals that corporate export restrictions on surveillance technology carry inherent limitations. When a tool requires no ongoing connectivity, licensing, or updates, merely stopping new sales does not prevent abuse by existing customers. Governments that already purchased such tools before restrictions took effect have zero incentive to comply with the spirit of the ban.
The pattern extends beyond Russia. Similar forensic tools from Israeli vendors (Cellebrite, NSO Group) and other manufacturers have been linked to abuses in Egypt, the UAE, India, and dozens of other countries. In many cases, these tools were sold legally before human rights violations became widely known or before export restrictions were imposed.
## Recommendations for Defenders and Policymakers
For Organizations and Digital Rights Groups
For Technology Companies
For Policymakers
---
## HackWire Analysis
The Pivovarov case demonstrates a fundamental gap in how Western democracies regulate surveillance technology exports: supply chain restrictions work only if we control the supply chain. The moment a tool is sold and deployed, the clock stops for corporate and government controls alike.
Cellebrite's March 2021 cutoff announcement was treated as a victory for human rights advocates. But the investigation reveals it was largely performative. The company could stop selling, but it could not prevent Russian authorities from using thousands of hours of extraction time on devices already in their possession. This is not a failure unique to Cellebrite—it's a structural flaw in export control regimes for any technology that operates offline and requires no ongoing licensing.
What matters is not just *who sells surveillance tools*, but where those tools end up. A UFED device sitting in a Moscow police lab in June 2021 was arguably more dangerous than one sitting on a warehouse shelf. The tool had years of operational life ahead of it, and authorities had every incentive to maximize its use before supply chains or hardware degraded.
The overlap between Pivovarov's extracted contacts and later COLDRIVER targets is particularly revealing. It suggests that forensic extractions serve a dual purpose: immediate prosecution of the seized individual, but also long-term intelligence gathering on their entire network. One activist's phone becomes a roadmap for targeting dozens of others.
For defenders, the lesson is stark: encryption at rest and in transit is no longer sufficient if the device itself can be seized and subjected to forensic extraction without your consent. For policymakers, the message is equally clear—export restrictions are a necessary but insufficient control on surveillance technology. The hard part is managing the installed base that already exists.
— HackWire Editorial
---
## Related Coverage