Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cellebrite Tools Used on Activist’s iPhone in Russia

Cellebrite Tools Used on Activist’s iPhone in Russia

Posted on June 26, 2026 By CWS

Russian authorities reportedly utilized Cellebrite’s forensic technology to access the iPhone of opposition activist Andrey Pivovarov in June 2021. This incident occurred three months after Cellebrite declared it would cease sales of its tools to Russia and Belarus. The Citizen Lab brought this to light on June 25, citing both digital traces on the device and a corroborating Russian government report.

Forensic Examination Revealed

Investigators were discovered to have combed through the extracted data for connections to political figures, opposition groups, and activist organizations. Unlike remote spyware, this was a forensic examination conducted on a seized device, forming part of a political prosecution. Pivovarov was involved with Open Russia, an organization labeled “undesirable” by the Kremlin, resulting in criminal charges for continued association.

In May 2021, Pivovarov was detained at St. Petersburg airport, and his iPhone 12 along with a MacBook were confiscated. Despite not consenting to their search or providing passwords, the devices remained in custody until 2023. He was sentenced to four years in July 2022, later released in August 2024 as part of a prisoner exchange.

Evidence of Unauthorized Use

The phone was handed to Citizen Lab researchers in fall 2025, revealing traces from 2021 when it was under Russian control. MobileLockdown records, which document an iPhone’s trusted USB connections, indicated a link on June 17, 2021, with a host ID consistent with a Cellebrite fingerprint recognized from a prior Jordan case, establishing high-confidence evidence of the tool’s use.

Russia’s documentation corroborated these findings. Pivovarov received a “Forensic Expert Report No. 1269-17” during prosecution, prepared by the Interior Ministry’s forensic center for the Investigative Committee. The report explicitly named Cellebrite’s UFED Physical Analyzer and UFED 4PC, detailing data extraction from apps like WhatsApp and Telegram, and searches for opposition figures including Mikhail Khodorkovsky.

Implications of Continued Use

Cellebrite had announced in March 2021 it would halt sales to Russia and Belarus, effectively discontinuing updates but leaving existing hardware functional. Much of UFED’s functionality persists offline post-support, highlighting risks associated with existing installations in law enforcement offices. Previous reports indicated that Russia continued to employ Cellebrite’s tools on detainees’ phones beyond the sales ban.

Cellebrite responded on June 22, asserting that any use of its legacy hardware in Russia post-March 2021 was “unauthorized.” While the hardware operates without Cellebrite’s support or consent, the company maintains Russia on its restricted-customer list, transitioning to subscription licenses that deactivate upon expiration.

Future Outlook and Recommendations

Names retrieved from Pivovarov’s phone were later targeted in a phishing operation linked to Russian intelligence. The Citizen Lab advises potential seizure targets to adopt strong security measures, such as using alphanumeric passcodes, updating operating systems, activating Lockdown Mode on iPhones, and ensuring devices are powered off in high-risk situations. This case is part of a broader pattern of Cellebrite misuse, underscoring the limitations of sales cutoffs when legacy tools remain operational.

The Hacker News Tags:activist, Cellebrite, Citizen Lab, data extraction, forensic tools, Investigation, iPhone, opposition, Pivovarov, political prosecution, Privacy, Russia, sales ban, Security, Technology

Post navigation

Previous Post: Southeast Asian Governments Targeted by TinyRCT Backdoor
Next Post: Russian APT Utilizes New Backdoor Against Ukraine

Related Posts

SEC Drops SolarWinds Case After Years of High-Stakes Cybersecurity Scrutiny SEC Drops SolarWinds Case After Years of High-Stakes Cybersecurity Scrutiny The Hacker News
CISA Adds 3 Flaws to KEV Catalog, Impacting AMI MegaRAC, D-Link, Fortinet CISA Adds 3 Flaws to KEV Catalog, Impacting AMI MegaRAC, D-Link, Fortinet The Hacker News
Stealthy Python Backdoor Targets Cloud Credentials Stealthy Python Backdoor Targets Cloud Credentials The Hacker News
Qilin Ransomware Combines Linux Payload With BYOVD Exploit in Hybrid Attack Qilin Ransomware Combines Linux Payload With BYOVD Exploit in Hybrid Attack The Hacker News
Critical ASP.NET Core Vulnerability Patched by Microsoft Critical ASP.NET Core Vulnerability Patched by Microsoft The Hacker News
Over 100,000 WordPress Sites at Risk from Critical CVSS 10.0 Vulnerability in Wishlist Plugin Over 100,000 WordPress Sites at Risk from Critical CVSS 10.0 Vulnerability in Wishlist Plugin The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Linux Foundation Launches Akrites for Open Source Security
  • Miasma Malware Targets npm and GitHub in New Attack
  • Python.org Flaw Exposed Admin API Access Risks
  • Polymarket Hack Exposes $3 Million Security Breach
  • Microsoft Highlights Hotel Phishing Threat with Node.js

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Linux Foundation Launches Akrites for Open Source Security
  • Miasma Malware Targets npm and GitHub in New Attack
  • Python.org Flaw Exposed Admin API Access Risks
  • Polymarket Hack Exposes $3 Million Security Breach
  • Microsoft Highlights Hotel Phishing Threat with Node.js

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark