Russian authorities hacked the cellphones of prominent political opponents in custody using technology created by forensics firm Celebrite, even after the firm announced it had severed ties with Putin's government agencies, according to a new report. A new report raises new questions about whether Western tech companies really have control over how their tools are used once they're in the wild.
The incident is a warning for technology companies selling to governments. Celebrite, an Israeli company with a second headquarters in Virginia that sells to governments around the world, including the United States, announced it would stop providing hardware and software to Russia. Apparently it didn't or couldn't be done.
Researchers at Citizen Lab, a digital rights organization based at the University of Toronto, announced in June 2021 that they found evidence that Russian government investigative agencies used a phone hacking tool made by Celebrite to hack into the iPhone of local human rights activist and opposition politician Andrei Pivovarov.
Three months before the hack, Celebrite announced it would “immediately” stop selling its technology to Russian government customers. On its official website, Celebrite claims that as of March 2021, when it severed ties with Putin's government, the company could “stop receiving device functionality and software updates.”
It's unclear why that didn't happen in this case, but the episode exposes an uncomfortable truth about surveillance technology. That means once powerful hacking and surveillance techniques reach the wrong customers, it's not that easy to get them back. Tools can proliferate, be exploited, and often continue to be exploited long after the companies that created them have left their customers.
“It's not surprising, and [it] This is the result of Cerebright's policies,” said Eitai Mak, an Israeli human rights lawyer who has campaigned for years against surveillance technology makers such as Cerebright and spyware maker NSO Group.
Contact Us Want more information about Cellebrite? Or how Cellebrite customers are abusing its technology? We'd love to hear from you. You can contact Lorenzo Franceschi-Bicchierai securely from any non-work device or network on Signal (+1 917 257 1382), Telegram and Keybase @lorenzofb, or email.
As the lawsuit shows, Mack argued that ceasing sales or revoking software licenses would not stop former Cellebrite customers from misusing the company's technology. Mack also noted that Celebrite declines to say whether it will require it to dismantle the hacking tools it sells to customers, a critical gap that is not addressed in its own cutback announcement.
Mack added that this means former customers could still abuse Cellebrite's phone unlocking tool (called UFED) even after the company has ended support for the customer and possibly revoked the software license. In theory, this should make the company's devices less useful.
Citizen Lab senior researcher John Scott-Railton told TechCrunch that Cellebrite should “end the era of justified deniability by remotely disabling deployments and implementing cryptographically signed watermarks on all imaged devices in the event of a credible report of fraudulent activity.” In layman's terms, Cellebrite needs to be able to remotely brick its tools if they fall into the wrong hands, and the data extracted with its technology needs to include a kind of digital fingerprint so that it can track which specific device was used.
Cellebrite sells a hardware device designed to unlock and hack connected mobile phones. Over the years, researchers have documented how corporate customers have used the company's technology against dissidents, human rights activists and journalists in Hong Kong, Kenya and Jordan. As a result of some of these findings, Celebrite severed ties with Bangladesh, China, Hong Kong, Myanmar, and Serbia.
David Gee, Cellebrite's chief marketing officer, said in an email to Citizen Lab shared with TechCrunch that the company “ceased all sales and services to the Russian Federation in March 2021, terminated existing licenses, and immediately began terminating all legal agreements. As of March 2021, the use of legacy Cellebrite hardware in Russia is completely disallowed.”
Gee and Cellebrite spokesperson Victor Cooper did not respond to a series of specific questions sent to them by TechCrunch.
In Pivovarov's case, after Russian authorities detained him in May 2021 and confiscated his iPhone 12 and MacBook, Citizen Lab researchers said they were able to find forensic evidence that his phone was hacked by Cellebrite UFED.
Pivovarov also shared with researchers court documents he received as part of the prosecution. In it, the Russian government's Center of Crime Experts detailed the use of Cellebrite UFED to break into his mobile phone and said authorities used UFED to extract data, including WhatsApp and Telegram messages. They also searched the phones for political terms and the names of opposition figures, including targets of what researchers say is a hacking operation by the Russian government.
Pivovarov was the director of the now-defunct opposition group Open Russia. He was later sentenced to four years in prison, but was released in August 2024 as part of a prisoner exchange between Russia and the West, along with Wall Street Journal reporter Evan Gershkovich.
The Russian embassy in Washington, D.C., did not respond to a request for comment.
If you buy through links in our articles, we may earn a small commission. This does not affect editorial independence.

