Russian state authorities breached the iPhone of prominent opposition politician Andrey Pivovarov in June 2021 whilst he was in custody, utilising forensic technology manufactured by Israeli firm Cellebrite despite the company’s public pledge to terminate its operations within Vladimir Putin’s jurisdiction.
This development serves as a stark warning for technology firms supplying software to state actors. Cellebrite, an Israel-based digital intelligence firm with secondary headquarters in Virginia, US, maintains a global client base—including federal law enforcement agencies in the United States. Despite previously declaring a complete cessation of its hardware and software supplies to the Russian Federation, the firm seemingly failed to enforce this restriction.
The Citizen Lab Exposes Forensic Breach
Academic researchers at The Citizen Lab, a digital security watchdog based at the University of Toronto, uncovered forensic evidence indicating that a Russian government investigative department deployed Cellebrite’s hacking apparatus to infiltrate Pivovarov’s mobile device.
Intriguingly, the security breach occurred mere months after Cellebrite announced in March 2021 that it would “immediately” halt all technology sales to Russian state clients. On its official portal, the company claims it possesses the capability to remotely deactivate its devices or prevent software updates once licensing agreements are terminated.
The Uncontrollable Proliferation of Surveillance Tech
The failure to deactivate the system highlights a systemic vulnerability within the surveillance industry: once highly sophisticated hacking tools are distributed to external clients, restricting their subsequent deployment becomes exceptionally difficult. These digital weapons frequently proliferate and remain active in the field, long after the manufacturing company purports to have severed ties with the abusive regime.
Eitay Mack, an Israeli human rights lawyer who has spent years campaigning against surveillance developers such as Cellebrite and the Pegasus spyware creator NSO Group, remarked that this outcome was entirely predictable and stems directly from the company’s operational policies.
According to Mack, merely halting sales or officially revoking a software licence is insufficient to prevent a former client from exploiting the technology. He emphasised that Cellebrite consistently declines to clarify whether it demands the physical return or decommissioning of its hardware once partnerships are dissolved—a major loophole in its public-relations pledges.
Calls for Remote Deactivation and Digital Watermarking
This specific incident demonstrates that legacy clients can continue utilising Cellebrite’s signature Universal Forensic Extraction Device (UFED) even in the absence of active developer support or official licensing. Whilst the lack of updates should theoretically diminish the tool’s efficacy over time, it remains highly functional for unauthorised state actors.
John Scott-Railton, a senior researcher at The Citizen Lab, argued that Cellebrite must implement stricter controls. He suggested the firm should remotely disable deployed units following credible allegations of human rights abuses. Furthermore, he urged the industry to end the era of plausible deniability by introducing cryptographically signed watermarks on all extracted data, allowing investigators to trace precisely which hardware unit was used in any given breach.
A Global Pattern of Surveillance Misuse
Cellebrite specialises in manufacturing physical hardware designed to bypass security protocols and extract data from connected mobile phones. Over several years, independent investigators have documented the deployment of these tools against journalists, political dissidents, and human rights defenders in nations such as Kenya, Jordan, and Hong Kong. Following public exposure of these incidents, Cellebrite has previously terminated sales to regimes in Bangladesh, China and Hong Kong, Myanmar, and Serbia.
The Corporate Response
In correspondence shared with TechCrunch, Cellebrite’s Chief Marketing Officer, David Gee, asserted that the company ceased all commercial transactions and services within the Russian Federation in March 2021, rendering any subsequent use of its legacy hardware entirely unauthorised. However, both Gee and company spokesperson Victor Cooper declined to address a series of detailed inquiries regarding how the technology remained operational in Russia post-ban.
The Prosecution of Andrey Pivovarov
In the case of Pivovarov, forensic analysis of his confiscated iPhone 12 and MacBook—seized by Russian authorities during his detention in May 2021—confirmed the active deployment of Cellebrite UFED software. This finding was further corroborated by official Russian prosecution documents provided to the researchers by Pivovarov himself.
The state’s Criminalist Expert Center openly detailed its reliance on the UFED system to extract WhatsApp and Telegram communications. Investigators used the tool to execute targeted searches for political terminology and the names of prominent opposition figures, aligning with broader state-sponsored hacking patterns documented by digital watchdogs.
Pivovarov, who previously led the now-disbanded pro-democracy group Open Russia, was subsequently sentenced to four years in a penal colony. He was eventually released in August 2024 as part of a high-profile multinational prisoner exchange that also secured the release of Wall Street Journal reporter Evan Gershkovich. The Russian Embassy in Washington, D.C., has declined to comment on the findings.
