Sunday, October 4, 2026

Russian Authorities Used Cellebrite UFED to Break Into Human Rights Activist’s iPhone

Russian authorities leveraged Cellebrite’s Universal Forensic Extraction Device (UFED) to gain access to a detained human rights activist’s iPhone, according to a detailed forensic investigation that raises fresh concerns over the use of commercial digital forensics tools in political repression.

The findings as per reported by CitizenLabs, based on technical analysis and corroborated by official Russian documents, show that activist Andrey Pivovarov’s iPhone 12 was subjected to non-consensual data extraction while in state custody following his arrest in May 2021.

Russian Authorities Used Cellebrite UFED

Pivovarov, a prominent opposition figure and former director of the Open Russia movement, was detained at St. Petersburg Airport and later sentenced to four years in prison under laws targeting so-called “undesirable organizations.”

During his detention, authorities confiscated his devices, including an iPhone and MacBook, without consent or passwords. These devices remained in government custody until 2023, creating a window during which forensic exploitation occurred.

Forensic analysis conducted after the devices were returned identified clear traces of Cellebrite UFED activity on the iPhone. Investigators discovered MobileLockdown artifacts indicating USB connections to a host system previously attributed to Cellebrite, including a specific Host ID: 9016926980658937761372207.

The activity was timestamped around June 17, 2021, which aligns with the period during which Russian authorities held the device. This provides high-confidence evidence that Cellebrite tools were used to extract data from the device.

The technical findings are directly supported by an official Russian forensic report titled “Forensic Expert Report No. 1269-17,” produced by the Ministry of Interior’s forensic unit.

Russian Authorities Used Cellebrite UFED to Break Into Human Rights Activist’s iPhone(Source: citizenlab)
Russian Authorities Used Cellebrite UFED to Break Into Human Rights Activist’s iPhone(Source: citizenlab)

The document explicitly confirms the use of UFED 4PC and UFED Physical Analyzer, two core components of Cellebrite’s toolkit designed for full-device extraction and analysis.

These tools enable investigators to bypass device protections and parse large volumes of data, including encrypted application content where possible.

According to the report, authorities extracted extensive datasets from messaging platforms such as WhatsApp, Telegram, and Viber. They then conducted targeted keyword searches tied to political entities and individuals, including “Open Russia Civic Movement,” Mikhail Khodorkovsky, and other opposition-linked figures.

This pattern indicates deliberate intelligence gathering focused on mapping Pivovarov’s political network and affiliations rather than a standard criminal investigation.

An important technical contrast emerged in the handling of Pivovarov’s MacBook. The same report documents failed attempts to access the laptop’s encrypted file system, with forensic evidence suggesting unsuccessful login attempts.

Researchers concluded that authorities were unable to bypass Apple’s disk encryption protections, highlighting the differing levels of resistance between mobile and desktop platforms.

The investigation also raises concerns about “blended targeting,” where data extracted from one individual may facilitate broader surveillance campaigns.

Notably, several individuals identified in the Cellebrite-assisted searches were later targeted in phishing operations attributed to the Russia-linked COLDRIVER group. While causality is not definitively established, the overlap suggests that device extraction may have contributed to downstream intelligence operations.

Despite Cellebrite’s public announcement in March 2021 that it had terminated sales to Russia and Belarus, evidence indicates that Russian authorities continued to use UFED systems well after the cutoff.

This persistence is likely due to the platform’s offline capabilities and the long operational lifespan of previously deployed hardware, which can function without ongoing vendor support or updates.

The case adds to a growing body of evidence linking Cellebrite technology to human rights abuses globally. Prior forensic investigations have documented similar use against activists and journalists in multiple jurisdictions, raising systemic concerns about export controls and corporate accountability.

The ability of such tools to extract comprehensive personal data, including communications, contacts, and behavioral patterns, makes them particularly powerful in environments where legal safeguards are weak or absent.

Cellebrite has responded by stating that any use of its technology in Russia after March 2021 is unauthorized and that legacy systems would be ineffective against modern devices.

However, the successful extraction from Pivovarov’s iPhone challenges that assertion. It underscores the difficulty of enforcing restrictions once such capabilities are deployed. The findings ultimately highlight how digital forensic technologies, designed for lawful investigations, can be repurposed for surveillance and repression in politically motivated prosecutions.

Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devices

A newly identified IoT botnet, Cling, disguises its command-and-control...

Microsoft Warns ClickFix Attacks Use Fake CAPTCHA Lures to Execute Malicious Commands

Microsoft Threat Intelligence has identified a ClickFix campaign in...

Critical GitLab AI Gateway Flaw Lets Attackers Execute Arbitrary Commands

GitLab has issued emergency security updates for a critical...

AWS AI Agent Vulnerabilities Let Attackers Bypass Authentication and Steal Credentials

AWS has released security fixes for four vulnerabilities affecting...

Citrix NetScaler Appliances Reboot Repeatedly After 0-Day Security Update

Citrix NetScaler administrators report repeated appliance crashes and forced...

Sony PS5 Relapse Jailbreak Exploit Uses JSC Memory Corruption and Kernel UAF

A newly released PlayStation 5 jailbreak chain, called Relapse,...

Zammad Vulnerabilities Let Attackers Execute Code and Escalate Privileges to Root

Two critical vulnerabilities in the open-source Zammad helpdesk and...

Safari History Database Tags Can Reveal Users’ Browsing Themes in Forensic Investigations

Safari's History database contains a lesser-known tagging artifact that...

Related Articles

Recent News