Cellebrite and Open Russia: Russia Used Cellebrite Tool to Hack Activist’s iPhone Despite Contract Cancellation

Cellebrite and Open Russia: Russia Used Cellebrite Tool to Hack Activist’s iPhone Despite Contract Cancellation

Russian Authorities Used Cellebrite Tools to Extract Data from Opposition Politician’s iPhone Despite Contract Termination

In June 2021, Russian security services deployed Cellebrite’s Universal Forensic Extraction Device (UFED) to breach the iPhone 12 of Andrey Pivovarov, former director of the pro-democracy nonprofit Open Russia, according to a forensic investigation by Citizen Lab at the University of Toronto. The extraction occurred three months after Cellebrite publicly announced it had ceased all sales to Russian authorities amid human rights concerns.

Pivovarov was detained at St. Petersburg Airport on May 31, 2021, after dissolving Open Russia’s Russian branch to shield staff from prosecution under new laws targeting "undesirable organizations." His devices an iPhone 12 and MacBook were confiscated without consent or passwords and held until 2023, following his four-year prison sentence. He was released in August 2024 as part of a U.S.-Russia prisoner exchange.

Citizen Lab’s analysis, initiated after Pivovarov flagged potential tampering in 2025, uncovered forensic traces of Cellebrite’s UFED on his device, including a Host ID (90161926980658937761372207) linked to the company in prior investigations. The findings were corroborated by Russian forensic documents, including a Ministry of Interior report (No. 1269-17) explicitly naming Cellebrite’s UFED Physical Analyzer and UFED 4PC as the tools used to extract data.

The extraction targeted WhatsApp, Telegram, and Viber communications, along with keyword searches for opposition figures, including Mikhail Khodorkovsky and human rights lawyer Anastasiya Burakova. Cellebrite had publicly terminated Russian contracts in March 2021, with an executive stating that any post-exit use was "unauthorized." However, the offline functionality of UFED tools allowed Russian authorities to continue operations despite the ban.

The incident raises concerns about downstream surveillance risks: individuals flagged in Pivovarov’s data, such as Burakova, were later targeted in phishing campaigns by COLDRIVER, an FSB-linked hacking group, as documented in a 2024 Citizen Lab-Access Now investigation. Researchers suggest the extracted data may have informed subsequent FSB operations against regime critics abroad.

This case adds to a growing pattern of Cellebrite tool misuse in countries like Serbia, Kenya, Jordan, Myanmar, Bahrain, and Botswana, despite partial contract cancellations. While Access Now and Citizen Lab have urged Cellebrite to implement technical safeguards and human rights due diligence, the company has not announced structural changes to its export controls.

Source: https://cybersecuritynews.com/russia-cellebrite-tool-iphone/

Cellebrite cybersecurity rating report: https://www.rankiteo.com/company/cellebrite

OpenDoors Asheville cybersecurity rating report: https://www.rankiteo.com/company/opendoors

"id": "CELOPE1782411871",
"linkid": "cellebrite, opendoors",
"type": "Cyber Attack",
"date": "6/2021",
"severity": "60",
"impact": "2",
"explanation": "Attack limited on finance or reputation"
{'affected_entities': [{'industry': 'Nonprofit, Political Activism',
                        'location': 'Russia',
                        'name': 'Andrey Pivovarov',
                        'type': 'Individual'},
                       {'industry': 'Pro-Democracy Advocacy',
                        'location': 'Russia',
                        'name': 'Open Russia',
                        'type': 'Nonprofit Organization'}],
 'attack_vector': 'Physical access to device, Forensic tool exploitation',
 'data_breach': {'data_exfiltration': 'Likely (used to inform subsequent FSB '
                                      'operations)',
                 'personally_identifiable_information': 'Yes (names of '
                                                        'opposition figures, '
                                                        'activists)',
                 'sensitivity_of_data': 'High (political communications, PII '
                                        'of activists)',
                 'type_of_data_compromised': ['Messaging app communications',
                                              'Keyword searches for opposition '
                                              'figures',
                                              'Personally identifiable '
                                              'information (PII)']},
 'date_detected': '2025',
 'description': 'In June 2021, Russian security services deployed Cellebrite’s '
                'Universal Forensic Extraction Device (UFED) to breach the '
                'iPhone 12 of Andrey Pivovarov, former director of the '
                'pro-democracy nonprofit Open Russia, despite Cellebrite '
                'terminating its contracts with Russian authorities in March '
                '2021. The extraction targeted communications and '
                'opposition-related data, which may have informed subsequent '
                'FSB operations against regime critics.',
 'impact': {'brand_reputation_impact': 'Reputational damage to Open Russia and '
                                       'associated individuals',
            'data_compromised': 'WhatsApp, Telegram, and Viber communications; '
                                'keyword searches for opposition figures',
            'identity_theft_risk': 'High (extracted PII used in subsequent '
                                   'phishing campaigns)',
            'legal_liabilities': 'Potential violations of human rights and '
                                 'privacy laws',
            'operational_impact': 'Compromised personal and organizational '
                                  'communications of a pro-democracy nonprofit',
            'systems_affected': ['iPhone 12', 'MacBook']},
 'initial_access_broker': {'entry_point': 'Physical confiscation of devices',
                           'high_value_targets': 'Opposition politicians, '
                                                 'activists, human rights '
                                                 'lawyers'},
 'investigation_status': 'Completed (Citizen Lab, 2025)',
 'lessons_learned': 'Cellebrite tools can be misused by state actors even '
                    'after contract termination due to offline functionality. '
                    'Extracted data may inform subsequent cyber operations '
                    'against dissidents.',
 'motivation': 'Surveillance of political opposition, suppression of dissent',
 'post_incident_analysis': {'corrective_actions': ['Advocate for technical '
                                                   'safeguards in forensic '
                                                   'tools',
                                                   'Enhance export controls '
                                                   'and human rights due '
                                                   'diligence'],
                            'root_causes': ['Unauthorized use of Cellebrite '
                                            'UFED tools by Russian authorities '
                                            'post-contract termination',
                                            'Lack of technical safeguards in '
                                            'forensic tools']},
 'recommendations': ['Implement technical safeguards in forensic tools to '
                     'prevent unauthorized use',
                     'Enhance human rights due diligence for exports',
                     'Monitor downstream misuse of extracted data'],
 'references': [{'source': 'Citizen Lab (University of Toronto)'},
                {'source': 'Access Now'},
                {'source': 'Russian Ministry of Interior Report (No. '
                           '1269-17)'}],
 'regulatory_compliance': {'regulations_violated': ['Potential violations of '
                                                    'human rights and privacy '
                                                    'laws (e.g., GDPR if EU '
                                                    'citizens affected)']},
 'response': {'communication_strategy': 'Public disclosure by Citizen Lab and '
                                        'Access Now',
              'third_party_assistance': 'Citizen Lab (University of Toronto), '
                                        'Access Now'},
 'stakeholder_advisories': 'Cellebrite urged to implement export controls and '
                           'technical safeguards to prevent misuse.',
 'threat_actor': 'Russian security services (FSB-linked)',
 'title': 'Russian Authorities Used Cellebrite Tools to Extract Data from '
          'Opposition Politician’s iPhone Despite Contract Termination',
 'type': 'Unauthorized Data Extraction',
 'vulnerability_exploited': 'Offline functionality of Cellebrite UFED tools'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.