Citizen Lab has uncovered forensic evidence showing that Cellebrite’s powerful mobile extraction tool was used on a Samsung Android phone owned by Kenyan activist and politician Boniface Mwangi.
The incident occurred while his device was in police custody following his arrest in July 2025.
This case raises serious concerns about how law enforcement agencies worldwide might misuse advanced forensic technology to access sensitive personal and political data after detaining critics.
Arrest, Seizure, and Charges
Boniface Mwangi stands as a bold voice against government overreach in Kenya. He has openly declared his intention to run for president in the 2027 elections, making him a target amid rising political tensions.
On July 19, 2025, officers from Kenya’s Directorate of Criminal Investigations (DCI) arrested Mwangi at his home in Nairobi.
They then escorted him to his office, where they conducted a thorough raid and seized multiple electronic devices, including his Samsung Android phone.
This arrest unfolded against a backdrop of widespread protests in June and July 2025. Demonstrators criticized police brutality and alleged abuses by authorities.
Mwangi’s detention fit into a pattern of pressure on civil society figures and protesters. Two days later, on July 21, he faced a special court handling terrorism and transnational crime cases.
Prosecutors charged him under a firearms law, after initially hinting at terrorism and money-laundering accusations linked to the protests.
International outcry led to the dismissal of terror charges. Mwangi secured bail but faced an ongoing criminal case as of the report’s release.
The DCI held the seized devices for over a month. Authorities returned them to Mwangi on September 4, 2025.
He immediately noticed something alarming: the password protection on his Samsung phone had vanished, despite his never sharing the passcode.
Forensic Evidence of Cellebrite Extraction
Citizen Lab, a digital forensics research group at the University of Toronto, conducted a detailed analysis of the returned devices.
Their findings point to Cellebrite’s mobile forensic tools being deployed on Mwangi’s phone around July 20-21, 2025, right when it was under police control.
A standout artifact was an application called “com.client.appA,” which researchers link with high confidence to Cellebrite’s extraction software.
Cellebrite’s technology excels at bypassing locks and pulling vast amounts of data from mobile devices.
In this case, it likely enabled access to messages, private files, financial records, stored passwords, and more. Such capabilities go far beyond basic searches, potentially exposing Mwangi’s political strategies, contacts, and personal life to scrutiny.
Citizen Lab notes that their probe into other seized devices continues, hinting at broader implications.
This incident underscores a disturbing trend. Cellebrite tools, sold to governments globally, have surfaced in reports of human rights abuses.
From authoritarian regimes to democracies, questions swirl about vendor oversight in high-risk settings.
Does Cellebrite perform enough due diligence on clients? The group urges stronger safeguards to prevent misuse against activists and dissidents.
Kenya’s case highlights the double-edged nature of forensic tech. While it aids legitimate investigations, unchecked access erodes privacy and chills free speech.
Mwangi’s story serves as a wake-up call for policymakers and tech firms to prioritize human rights.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google