Cellebrite said it has suspended the use of some of its digital forensic products by certain customers in Serbia after Amnesty International reported that Serbian police and intelligence services allegedly used the technology to unlawfully extract data from the phones of activists and journalists. Amnesty said its December 2024 investigation found that authorities used mobile device extraction tools outside legally sanctioned procedures and, in some cases, that targeted phones were later infected with spyware.
The dispute has intensified scrutiny of Serbia’s treatment of civil society and independent media, with Amnesty arguing that the surveillance activity occurred amid anti-government protests and a broader pattern of pressure on government critics. Amnesty welcomed Cellebrite’s move but called on the company to strengthen human-rights due diligence and urged a halt to exports of surveillance and digital forensics technology to Serbia until effective independent oversight is in place.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
In December 2024, Amnesty International reported that Serbian police and intelligence services used Cellebrite digital forensic tools to unlawfully extract data from activists' and journalists' phones and, in some cases, those devices were subsequently infected with spyware.
By 2025-02-26, Cellebrite had decided to stop some Serbian customers from using its digital forensic products following Amnesty International's allegations of misuse by Serbian authorities.
On 2025-02-25, Cellebrite published a statement addressing Amnesty International's report about alleged misuse of its products in Serbia.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.