Russian authorities used Cellebrite UFED phone-forensics technology to access the iPhone of jailed opposition figure Andrey Pivovarov in June 2021, months after Cellebrite said it had ended sales and services to Russian government customers over human rights concerns. A Citizen Lab investigation, supported by forensic evidence from Pivovarov’s device and Russian court records, found investigators extracted data including WhatsApp and Telegram messages and searched for political terms and opposition figures; authorities reportedly could not unlock his MacBook.
The findings renewed scrutiny of how surveillance and forensic tools remain usable after vendors cut ties with government clients. Researchers said Cellebrite’s legacy architecture and offline functionality allowed older systems to keep operating without vendor support, and warned that data taken from Pivovarov’s phone may also have aided surveillance of other dissidents, including Anastasiya Burakova, who was later targeted in a hacking campaign linked to Russia’s FSB. Cellebrite said any post-March 2021 use in Russia was unauthorized, involved legacy hardware, and would now be ineffective against modern devices.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
In response to the report, Cellebrite said any use of its legacy hardware in Russia after March 2021 was unauthorized and unsupported, and it argued such hardware would now be ineffective against modern devices. The statement directly addressed the allegations raised by Citizen Lab and news outlets.
On 2026-06-25, multiple outlets reported Citizen Lab's findings that Russian authorities used Cellebrite technology against dissident Andrey Pivovarov after the company had cut off Russian government customers. The report argued that offline functionality and legacy architecture made it difficult for Cellebrite to effectively disable problematic customers.
In March 2021, Cellebrite announced that it would stop sales and services to Russian government customers over human rights concerns. Later reporting said Russian authorities nonetheless retained the ability to use legacy UFED systems.
On 2022-10-21, Haaretz reported that Russia's Investigative Committee was still using Cellebrite mobile extraction tools against detainees despite the company's 2021 halt of Russian operations. The report said online-accessible Russian documents indicated ongoing use of the Israeli firm's technology.
Around 2021-06-17, while Andrey Pivovarov was in custody, Russian authorities used Cellebrite UFED technology to extract data from his iPhone. Forensic evidence and court records indicated the extraction included app data such as WhatsApp and Telegram messages and was used in the political case against him.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcethehackernews.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcebloomberg.com
Open sourcetherecord.media
Open sourcehaaretz.com
Open sourcecellebrite.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.