Activist Phone Hacked With Cellebrite After Russia Contract Cancellation


Activist Phone Hacked With Cellebrite After Russia Contract Cancellation

Pierluigi Paganini
June 26, 2026

Russian authorities used Cellebrite tools to unlock an activist’s iPhone and analyze private data despite canceled support, raising abuse concerns.

On May 31, 2021, Russian security services pulled opposition activist Andrey Pivovarov off a flight at St. Petersburg airport and confiscated his iPhone 12 and MacBook. He never consented to a search and never gave up his passwords. Three weeks later, on June 17, while his devices sat in custody, Russian authorities used Cellebrite ‘s forensic tools to break into his phone. Cellebrite had announced it was stopping sales to Russia three months earlier.

The Citizen Lab published its findings on June 25, 2026. What makes this case unusual is that the evidence comes from two independent sources that line up exactly.

“Our analysis found traces of the use of Cellebrite’s forensic tools with high confidence on Pivovarov’s iPhone 12 on or around June 17, 2021, during a period when the device was in the custody of the Russian authorities.” reads the report published by Citizen Lab. “Our forensic analysis of MobileLockdown records from Pivovarov’s iPhone show USB connections to a device with a Host ID on June 17, 2021 that we previously attributed to Cellebrite.”

The second source is Russia’s own paperwork. Pivovarov received a prosecution document, Forensic Expert Report No. 1269-17, prepared by the Interior Ministry’s forensic center, and he gave a copy to the Citizen Lab. It names Cellebrite UFED Physical Analyzer and UFED 4PC by product name.

The investigators didn’t just extract data. They searched it.

“The authorities documented gathering extensive information from the device, including data from apps like WhatsApp, Telegram, and Viber.” continues the report.

The MVD report shows searches for “Open Russia Civic Movement” and for named individuals including Mikhail Khodorkovsky, who founded Open Russia, human rights lawyer Anastasiya Burakova, and Pivovarov’s partner Tatiana Usmanova. This was a political map-building exercise disguised as a criminal investigation.

The MacBook resisted. Russia’s own report documents a failed extraction attempt, blocked by disk encryption, and Citizen Lab forensics found matching failed login attempts on June 17, confirming the authorities never had the password. Pivovarov was sentenced to four years in July 2022 on charges of running an “undesirable” organization — a label Russia applied to Open Russia, and one the European Court of Human Rights later found incompatible with the European Convention on Human Rights. He was freed in August 2024 in a prisoner exchange.

The timing raises a question Cellebrite can’t easily answer. The company cancelled its Russian contracts in March 2021, which cut off future updates but left existing hardware running.

The Russian and Belarusian authorities would cease to receive updates for their Cellebrite devices, but evidence demonstrates that more than a year later, Russian autorities were still using the tool to hack political detainees’ cellphones.

“Our forensic findings confirm the reports that Russian authorities developed a range of methods to continue leveraging Cellebrite in political prosecutions (as well as other device hacking tools) despite the contract cancellation. The historic architecture of Cellebrite forensic systems means that much of the functionality in the UFED product has continued to operate long after updates cease.” continues the report. “Furthermore, Cellebrite systems have historically featured an offline mode. Consequently, the way Cellebrite’s technology was designed appeared to make it difficult for the company to meaningfully cut off problematic customers.”

Cellebrite told the Citizen Lab that any use of its legacy hardware after March 2021 is “entirely unauthorized” and that the hardware runs without its support or consent. That’s legally accurate and operationally irrelevant: the tool worked, the phone was open, and the extraction happened.

There’s an additional thread worth following. The names pulled from Pivovarov’s phone later appeared as targets in a COLDRIVER phishing campaign, the FSB-linked operation that went after Russian opposition figures abroad. Burakova was targeted but didn’t open the attachment. The Citizen Lab doesn’t claim a direct causal link, but the mechanism is straightforward: extract one activist’s contact list and you have a ready-made target list for the next operation.

Russia now joins Serbia, Kenya, and Jordan on the Citizen Lab’s list of Cellebrite abuse cases backed by hard forensic evidence. Cellebrite says it’s moving to subscription licenses that stop working when they expire, which would prevent the installed-base problem from recurring.

The company’s track record, selling to repressive governments, cancelling contracts only after third-party exposure, and reacting selectivelym makes that commitment worth watching rather than simply trusting.

“Cellebrite’s record suggests it is comfortable pursuing contracts with governments that are likely to use its technology to commit human rights abuses. Cellebrite previously sold to autocratic and repressive countries including RussiaBelarusChinaJordanKenyaMyanmarSerbia, and Botswana, among others.” concludes the report. “There is also a growing list of forensically-documented cases in which Cellebrite technology was used for political repression, from Serbia and Kenya to Jordan and now Russia, and where the company has shown a mixed record of contract cancellations.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, mobile)







Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


Summer is kicking in with full force, and with the temperature rising, Netflix’s summer slate of releases, too, picks up heat. It’s time for your watch list to get a new look, whether you’re looking forward to a cozy romance watch or an addictive new series.

Between long-awaited returning series, nostalgic movie additions, true-crime documentaries, and originals that are sure to stun, there’s a little bit of everything arriving on Netflix. The second season of the highly awaited live-action series, Avatar: The Last Airbender, returns at the end of the month.

Other titles coming this month include The Witness (a true-crime show), Office Romance (a rom-com starring Jennifer Lopez), and I Will Find You (another Harlan Coben thriller).

Plus, licensed additions like Poor Things and Little Miss Sunshine will be available to stream from the beginning of the month. Here’s the Netflix schedule for June.

Everything coming to Netflix in June 2026

Your watchlist gets a summer refresh

Arrival Date

Title

June 1

Bee Movie

Creed I-III

Father of the Bride: Part I & II

Friday Night Lights

Fried Green Tomatoes

Hawaii Five-0: Seasons 1-5

Inside Man 1 & 2

Little Miss Sunshine

Miracle

Muriel’s Wedding

My Best Friend’s Wedding

Rocky 1-5

Rudy

Runaway Bride

Scooby-Doo 1 & 2

The Big Lebowski

The Karate Kid Part I-III

The Wedding Planner

June 4

The Murder of Rachel Nickell

The Witness

June 5

Office Romance

June 6

Grey’s Anatomy: Season 22

Resident Alien: Season 4

June 7

Poor Things

June 8

Shrill: Seasons 1-3

June 10

Outlast: The Jungle

The Rest is Football

June 11

Sweet Magnolias: Season 5

June 12

Maternal Instinct

June 13

Song Sung Blue

June 15

Percy Jackson 1 & 2

June 16

America’s Sweethearts: Dallas Cowboys Cheerleaders: Season 3

Beavis and Butt-Head: The Mike Judge Collection Vol. 1-3

Mike Judge’s Beavis and Butt-Head: Seasons 1-2

June 18

I Will Find You

June 19

Color Book

Voicemails for Isabelle

June 24

The American Experiment

In the Hand of Dante

June 25

Avatar: The Last Airbender: Season 2

June 26

Chris & Martina: The Final Set

Little Brother

June 30

Sullivan’s Crossing: Season 4


If you’re on the lookout for new Netflix titles, make sure you enable desktop or mobile app notifications. You can also browse the “New and Popular” tab regularly to refresh your watchlist with new titles.

Subscription with ads

Yes, $8/month

Simultaneous streams

Two or four

Stream licensed and original programming with a monthly Netflix subscription.




Source link