Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Russia’s Use of Cellebrite to Access Activist’s iPhone

Russia’s Use of Cellebrite to Access Activist’s iPhone

Posted on June 25, 2026 By CWS

Russia’s Continued Use of Cellebrite Technology

In June 2021, Russian authorities employed Cellebrite’s Universal Forensic Extraction Device (UFED) to access the iPhone of opposition figure Andrey Pivovarov. This action occurred despite Cellebrite’s public announcement in March 2021 that it had ceased all business with Russian clients, as uncovered by a forensic investigation by the Citizen Lab at the University of Toronto.

Detention and Device Confiscation

On May 31, 2021, Pivovarov, who led the pro-democracy group Open Russia, was detained by Russian security forces at St. Petersburg Airport. This followed his decision to disband Open Russia’s Russian operations to shield staff from legal repercussions under new laws on “undesirable organizations.” During his detention, his iPhone 12 and Apple MacBook were seized without his consent or provision of passwords. These devices remained with authorities until they were returned in 2023, following his sentencing to four years in prison for his involvement with an “undesirable” group. Pivovarov was eventually released during a notable U.S.-Russia prisoner exchange in August 2024.

Forensic Evidence and Investigations

While attending the World Liberty Congress in Berlin in the fall of 2025, Pivovarov consulted Citizen Lab researchers. Initial examinations of his iPhone revealed signs of forensic data extraction, prompting a deeper investigation. The analysis identified traces of Cellebrite’s UFED on his device around June 17, 2021, three months after the company stated it would no longer sell to Russian or Belarusian entities.

The forensic evidence included a specific Host ID found in MobileLockdown USB records, which Citizen Lab had previously linked to Cellebrite in a separate investigation concerning Jordanian civil society. Russian official documents corroborated these findings, referencing Cellebrite’s tools as instrumental in data extraction from Pivovarov’s devices.

Implications and Responses

Investigators discovered that Russian authorities extracted communications from applications like WhatsApp, Telegram, and Viber, leveraging Cellebrite’s tools to search for politically sensitive keywords. Despite Cellebrite’s contract termination, Russian continued use of the UFED platform suggests that its offline capabilities and self-sustaining architecture rendered the cessation ineffective.

Citizen Lab highlighted a troubling connection: individuals searched on Pivovarov’s device, including notable opposition figures, were later targeted by phishing campaigns linked to Russia’s FSB, as documented in a 2024 joint investigation by Citizen Lab and Access Now. This correlation suggests a need for further inquiry into whether Cellebrite’s extracted data may have facilitated broader FSB surveillance operations.

Call for Accountability

This incident is part of a broader pattern of Cellebrite technology misuse identified in countries like Serbia, Kenya, and Jordan. In response, Access Now and Citizen Lab have urged Cellebrite to introduce technical “kill switches” and enhance human rights due diligence in their sales processes. Despite these calls, Cellebrite, listed on the Nasdaq, has yet to announce strategic changes to its export controls following the revelations about Pivovarov.

Cyber Security News Tags:activist, Cellebrite, Citizen Lab, forensic investigation, FSB, Hack, human rights, iPhone, opposition, Pivovarov, Russia, Security, Surveillance, UFED

Post navigation

Previous Post: Microsoft Secure Boot Certificate Expiry Impacts Billions
Next Post: AWS Phishing Kit Exploits MFA for Real-Time Access

Related Posts

Threat Actors Attacking Azure Blob Storage to Compromise Organizational Repositories Threat Actors Attacking Azure Blob Storage to Compromise Organizational Repositories Cyber Security News
New Persistence Technique Allows Attackers to Hide Malware Within AWS Cloud Environment New Persistence Technique Allows Attackers to Hide Malware Within AWS Cloud Environment Cyber Security News
Bots Dominate Global Web Traffic, Surpassing Humans Bots Dominate Global Web Traffic, Surpassing Humans Cyber Security News
CISA Warns of Windows Privilege Escalation Vulnerability Exploited in Attacks CISA Warns of Windows Privilege Escalation Vulnerability Exploited in Attacks Cyber Security News
Critical Dell Storage Manager Vulnerabilities Let Attackers Compromise System Critical Dell Storage Manager Vulnerabilities Let Attackers Compromise System Cyber Security News
Kibana Crowdstrike Connector Vulnerability Exposes Protected Credentials Kibana Crowdstrike Connector Vulnerability Exposes Protected Credentials Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AWS Phishing Kit Exploits MFA for Real-Time Access
  • Russia’s Use of Cellebrite to Access Activist’s iPhone
  • Microsoft Secure Boot Certificate Expiry Impacts Billions
  • Curl’s 25-Year Security Flaw Patched in Major Update
  • Popular Chrome Ad Blocker Raises Security Concerns

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AWS Phishing Kit Exploits MFA for Real-Time Access
  • Russia’s Use of Cellebrite to Access Activist’s iPhone
  • Microsoft Secure Boot Certificate Expiry Impacts Billions
  • Curl’s 25-Year Security Flaw Patched in Major Update
  • Popular Chrome Ad Blocker Raises Security Concerns

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark