An investigation by the University of Toronto’s Citizen Lab, published in coordination with OCCRP, reported that Jordanian authorities used Cellebrite digital forensic tools to gain nonconsensual access to the phones of domestic activists and human rights defenders. Based on forensic analysis of seized-and-returned devices and corroborating court records, Citizen Lab assessed with “high confidence” that multiple devices were subjected to Cellebrite forensic extraction during cases tied to enforcement actions under Jordan’s cybercrime framework, including proceedings under the 2023 Cybercrime Law.
Citizen Lab documented at least seven cases between late 2023 and mid-2025 (four supported by device forensics and three by court records), involving three iPhones and one Android in the forensically analyzed set, and said it is aware of dozens of additional instances. The report states the extractions occurred while individuals were interrogated or detained for speech critical of Israel’s campaign in Gaza, and it argues Cellebrite use against civil society in Jordan appears broader and longer-running, with forensic indicators suggesting deployment dating back to at least 2020; Citizen Lab called on Cellebrite to review its Jordan-related customer use in light of alleged rights abuses.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Following publication of the report, Cellebrite said it does not comment on specific customers or cases, maintained that it vets customers and licenses its technology only for lawful and ethical use, and disputed broader criticism of its accountability.
On January 22, 2026, Citizen Lab published findings based on forensic analysis of four returned phones and three court cases, concluding with high confidence that Jordanian authorities used Cellebrite against civil society members.
Jordanian court records in multiple prosecutions described Cellebrite 'Advanced Logical Image' extractions and use of Cellebrite Physical Analyzer, including at least one case where the tool could not bypass a passcode.
Between late 2023 and mid-2025, Jordanian authorities used Cellebrite forensic tools to extract data from at least seven activists, journalists, and human rights defenders after seizing their devices during interrogations or detention tied to speech and protests related to Gaza.
Jordan expanded its cybercrime law in 2023, a legal framework that reporting says was later used to prosecute online speech and formed part of the context for phone seizures and data extraction cases.
Citizen Lab said forensic indicators on activists’ devices suggest Jordanian authorities have deployed Cellebrite mobile forensic tools against civil society since at least 2020, indicating the practice predates the later documented cases.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
citizenlab.ca
Open sourcescworld.com
Open sourcecyberscoop.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.