Chips & Hardware
Cellebrite tools used in Russia despite company's exit claims
Russian authorities used Cellebrite tools to hack a political opponent’s phone, raising questions about why the technology remained functional after the company claimed to cut ties.
In June 2021, Russian authorities used a phone-hacking tool made by Cellebrite to break into the iPhone of Andrey Pivovarov, a local human rights dissident and opposition politician. According to a report by digital rights research group The Citizen Lab, forensic evidence showed that Russian authorities hacked into the phone of a prominent political opponent after detaining him and confiscating his iPhone 12 and MacBook in May 2021. The hack occurred despite the Israeli forensics firm’s announcement in March 2021 that it would stop selling its technology to Russian government customers. Russian authorities used Cellebrite’s phone-unlocking tool, known as UFED (Universal Forensic Extraction Device), to extract WhatsApp and Telegram messages. They also searched the device for political terms and names of opposition figures who were targets of alleged Russian government hacking campaigns. Pivovarov, the director of the defunct opposition group Open Russia, was later sentenced to four years in prison before being freed in August 2024 as part of a prisoner exchange.
The incident highlights the persistent risks of surveillance technology remaining active after a vendor claims to withdraw. Eitay Mack, an Israeli human rights lawyer, argued that former customers can still abuse Cellebrite’s phone-unlocking tool even after the company stops supporting the customer and presumably revokes its software license. Mack noted that ceasing sales and revoking licenses does not stop former customers from abusing the technology. To address this, John Scott-Railton, a senior researcher at The Citizen Lab, stated that Cellebrite “should also remote-disable deployments following credible reports of abuse, and end the era of plausible deniability by implementing cryptographically-signed watermarks on all imaged devices.” While Cellebrite claims it can stop its devices from functioning or receiving software updates, it remains unclear why Cellebrite’s tools continued to function in Russia after the company claimed to have cut ties.
Cellebrite, which sells its hardware to governments around the world, including in the U.S., has previously cut ties with other regions following reports of abuse. The company has stopped sales or cut ties with Bangladesh, China, Hong Kong, Kenya, Jordan, and Serbia. In response to the findings, Cellebrite’s chief marketing officer David Gee stated that the company terminated existing licenses and stopped all sales and services to the Russian Federation in March 2021, and that any subsequent use of its legacy hardware there is unauthorized. The Russian Embassy in Washington, D.C. did not respond to a request for comment.
Why it matters
The report raises questions about whether Western tech companies can truly control how their surveillance tools are used once they are in the wild. It highlights the difficulty of clawing back powerful hacking technologies after they have been sold to customers.