Thursday, 23 July 2026 · Europe
EUR/USD 1.139 EUR/GBP 0.8532 EUR/CHF 0.9295 EUR/PLN 4.327 All rates →
Sign in · Join
EUROPES The European Report
European Edition Thursday, 23 July 2026
LATEST
Tech & Startups

Cellebrite tech used in Russia despite firm's exit pledge

Cellebrite tech used in Russia despite firm's exit pledge

A Russian court document proves government hackers used Cellebrite software to crack an activist's phone months after the company claimed it cut ties, exposing a critical flaw in how Western surveillance firms enforce export bans.

Russian investigators used Cellebrite’s UFED phone-cracking tool to break into the iPhone of detained opposition politician Andrey Pivovarov in June 2021. The hack occurred three months after the Israeli surveillance firm publicly announced it had stopped selling to Moscow. A court document from Pivovarov's prosecution, reviewed by the University of Toronto's Citizen Lab, explicitly states authorities used the tool to extract WhatsApp and Telegram messages and search for political terms.

The significance for the surveillance technology sector lies not in the breach itself, but in the paper trail that contradicts corporate claims of control. Cellebrite has stated that when it cuts ties with a customer, it can stop a device from functioning or receiving updates. In this instance, the hardware remained fully operational long after the company claims to have terminated existing licenses in March 2021.

Cellebrite did not dispute that its tool was used. Chief marketing officer David Gee stated that the company “stopped all sales and services to the Russian Federation in March 2021, terminating existing licenses,” and that “any use of legacy Cellebrite hardware in Russia after March 2021 is entirely unauthorized.” Gee and a company spokesperson declined to answer further questions about why the hardware was not disabled.

This gap between severing a contract and actually rendering a product useless poses a growing dilemma for European regulators and investors. As the EU tightens controls on dual-use technology and surveillance exports, the Cellebrite case demonstrates that contractual terminations do not guarantee physical compliance. If a firm cannot or will not remotely brick its own machines when a relationship sours, its ethical pledges and export compliance mechanisms are effectively hollow.

Human-rights lawyer Eitay Mack noted that Cellebrite refuses to say whether it even asks customers to dismantle tools after a contract ends. “It’s not surprising, and is the result of the policies of Cellebrite,” Mack said. Citizen Lab senior researcher John Scott-Railton argued the company should remotely disable deployments after credible abuse reports and watermark extracted data to trace it to a specific device, ending what he called an era of plausible deniability.

Cellebrite, which maintains a second headquarters in Virginia and sells to governments globally, has a documented history of its tools being turned on dissidents in Hong Kong, Kenya, and Jordan. The company has since cut ties with customers in Bangladesh, Myanmar, and Serbia. Pivovarov, the former director of the now-defunct group Open Russia, was ultimately sentenced to four years in prison. He was freed in August 2024 in a prisoner exchange that also secured the release of Wall Street Journal reporter Evan Gershkovich.

More from Tech & Startups