Citizen Lab reported forensic evidence indicating Kenyan authorities used Cellebrite phone-extraction technology on the personal device of Kenyan activist and prospective presidential candidate Boniface Mwangi following his arrest amid mass protests. After his phone was returned, Mwangi observed that password protection had been removed, prompting him to submit the device for analysis; researchers concluded the artifacts were consistent with Cellebrite-enabled access intended to extract data from the handset, exposing sensitive personal and political communications.
The investigation identified traces of an application associated with Cellebrite tooling, including an app artifact appearing as com.client.appA, and framed the case as part of a broader pattern in which journalists and civil-society figures have allegedly been targeted with Cellebrite-assisted extractions while detained. Citizen Lab argued that Cellebrite’s stated safeguards—such as ethics review processes—have not prevented repeated alleged misuse in multiple countries, and warned that sales to security services with documented human-rights concerns increase the risk of abuse against activists and dissidents.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
After Citizen Lab’s report, Cellebrite said it has a process to review substantiated misuse allegations and can terminate licenses, but it did not directly answer key questions about Kenya. In subsequent comments, the company argued that Citizen Lab’s findings were not direct evidence and distinguished the case from prior action it took in Serbia.
On February 17, 2026, Citizen Lab published forensic findings saying it had high confidence that Cellebrite technology was used on Mwangi’s phone after his arrest. The report framed the case as part of a broader pattern of alleged misuse of commercial phone-extraction tools against activists and civil society.
On September 4, 2025, authorities returned Mwangi’s seized devices. He reported that his Samsung phone no longer required a password even though he had not provided the passcode, raising concerns that its contents had been accessed.
Citizen Lab found indicators consistent with Cellebrite forensic extraction being used on Mwangi’s Samsung phone while it was in police custody, likely on or around July 20–21, 2025. The artifacts included traces of the app "com.client.appA," which researchers linked to Cellebrite tooling.
On July 19, 2025, Kenya’s Directorate of Criminal Investigations arrested activist and politician Boniface Mwangi, raided his home and Nairobi office, and confiscated multiple electronic devices. He was later released on bail while the case remained active.
Following the June 25, 2025 protests in Kenya, authorities signaled they were investigating Boniface Mwangi for alleged terrorism and money-laundering offenses tied to the demonstrations. The case later shifted to firearms-law charges.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
citizenlab.ca
Open sourcetechcrunch.com
Open sourcethehackernews.com
Open sourcecitizenlab.ca
Open sourcecyberscoop.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.