Russian authorities illegally accessed the iPhone of prominent opposition activist Andrey Pivovarov using Cellebrite’s Universal Forensic Extraction Device (UFED) and did so months after the Israeli surveillance firm publicly claimed it had severed all ties with Russia.
The finding, published by the Citizen Lab, is corroborated by an official Russian government forensic document from Pivovarov’s own criminal prosecution.
On May 31, 2021, Russian security services detained Pivovarov at St. Petersburg Airport, confiscating his iPhone 12 and Apple MacBook.
The former director of the pro-democracy nonprofit Open Russia never consented to a search of his devices and never provided his passwords. His devices remained in official Russian state custody until 2023.
Cellebrite UFEDUsed Against Activist’s iPhone
In July 2022, a Russian court sentenced Pivovarov to four years in prison on charges of running an “undesirable” organization, charges widely condemned as politically motivated by Amnesty International and Human Rights Watch. He was released on August 1, 2024, as part of a high-profile international prisoner exchange.
After connecting with Citizen Lab researchers at the World Liberty Congress in Berlin in the fall of 2025, Pivovarov submitted his iPhone for forensic analysis.
The investigation identified traces of Cellebrite’s UFED on the device on or around June 17, 2021, while it remained in Russian state custody.

MobileLockdown records revealed a USB connection to Host ID 9016926980658937761372207 a Cellebrite identifier previously attributed by the Citizen Lab in a separate investigation involving Jordanian civil society.
This digital fingerprint was independently confirmed by Forensic Expert Report No. 1269-17, a document commissioned by Russia’s own Ministry of Interior (MVD) Forensic Expert Center.
The official report explicitly names Cellebrite’s UFED Physical Analyzer and UFED 4PC toolkit and documents the extraction of data from WhatsApp, Telegram, and Viber.
Russia’s MVD used Cellebrite’s tooling to conduct targeted keyword searches across Pivovarov’s device for specific political organizations and individuals, including Open Russia founder Mikhail Khodorkovsky and human rights lawyer Anastasiya Burakova.
Researchers flagged a troubling overlap: Burakova later became a target of COLDRIVER, an FSB-linked phishing campaign, suggesting that Cellebrite-extracted data may have seeded further targeting of regime opponents abroad.
Russian authorities had less success with Pivovarov’s MacBook. The MVD report itself admits that full-disk encryption prevented any extraction of the filesystem.
Citizen Lab’s forensic analysis confirmed multiple failed login attempts on June 17, 2021, consistent with the MVD’s own account authorities never obtaining Pivovarov’s MacBook password.
Cellebrite officially canceled its Russian contracts in March 2021, a full three months before the confirmed June 2021 extraction. Yet Russia’s authorities continued leveraging UFED tooling regardless.
Cellebrite’s legacy offline-capable architecture allowed full functionality to persist without updates or vendor authorization.
In response, Cellebrite stated: “Any use of legacy Cellebrite hardware in Russia after March 2021 is entirely unauthorized… Russia remains permanently on our restricted-customer list.”
Russia now joins Serbia, Jordan, Kenya, Myanmar, and Bahrain on a growing list of countries where Cellebrite tools have been forensically confirmed in politically motivated prosecutions.
Senior Citizen Lab researcher John Scott-Railton called on Cellebrite to implement remote disabling of tools following credible abuse reports and cryptographically signed watermarks on all imaged devices, measures that would close the plausible deniability loophole the company has historically relied upon.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.