A forensic investigation published by Citizen Lab on June 25, 2026 found that Russia's Interior Ministry used Cellebrite's UFED extraction tools to crack the iPhone 12 of opposition figure Andrey Pivovarov on or around June 17, 2021 — three months after the Israeli forensics firm announced it had halted all sales to Russia and Belarus. Pivovarov, then-director of the pro-democracy group Open Russia, had been pulled off a plane at St. Petersburg's Pulkovo Airport on May 31, 2021, and his devices seized without consent. Data extracted from his phone, including WhatsApp and Telegram messages, was later cited in the case that sent him to prison for four years on charges of running an "undesirable organization." He was freed in the August 2024 prisoner exchange that also brought home Wall Street Journal reporter Evan Gershkovich.
The forensic trail
Citizen Lab's evidence is granular, not speculative. Investigators matched MobileLockdown connection records on Pivovarov's phone to a Cellebrite "Host ID" fingerprint they had previously identified in an unrelated case in Jordan, rating the match "high confidence." That technical finding lines up with paperwork Pivovarov obtained during his own prosecution: a Russian Interior Ministry forensic center document, "Expert Report No. 1269-17," names both UFED Physical Analyzer and UFED 4PC as the tools used against him.
What Cellebrite actually promised
Cellebrite's March 18, 2021 announcement was unambiguous. The company said it would "immediately" stop selling its digital-intelligence products and services to customers in Russia and Belarus, with CEO Yossi Carmil framing the move as routine compliance review. The decision followed reporting that Russian investigators (SKRF) had used Cellebrite gear against opposition figures including Lyubov Sobol, an ally of the late Alexei Navalny. When TechCrunch put the Pivovarov findings to Cellebrite, the company's chief marketing officer repeated the same line — sales stopped in March 2021, and "any use of legacy Cellebrite hardware in Russia after March 2021 is entirely unauthorized."
That defense is technically accurate and substantively hollow. UFED units already in Russian police custody in March 2021 didn't stop functioning because a press release said so. As Citizen Lab researcher John Scott-Railton put it, via The Record:
"The historic architecture of Cellebrite forensic systems means that much of the functionality in the UFED product has continued to operate long after updates cease."
Most UFED extraction work happens offline, device-to-device, with no phone-home requirement to Cellebrite's servers. A sales embargo restricts who can buy new licenses; it does nothing to the units already in a police evidence locker.
Steelmanning the case for tighter controls
Human rights groups have a legitimate argument here, and it deserves to be stated plainly. Access Now, which amplified the Citizen Lab findings, is right that Cellebrite has now severed ties with Russia, Bangladesh, China, Hong Kong, Myanmar and Serbia — six governments — only after documented abuse, not before. A company that repeatedly discovers its tools are being used against dissidents only in hindsight has a due-diligence problem, and "we cut them off eventually" is a weak standard when the underlying hardware keeps working regardless. Advocates are also correct that neither Israeli export authorities nor the buyers who license UFED systems currently impose the kind of remote-disable or audit requirements that would make a corporate pullout meaningful rather than symbolic.
Why a blanket export ban is still the wrong tool
But the Pivovarov case actually undercuts, rather than supports, the argument for broader export bans. Cellebrite is not NSO Group or Intellexa — it isn't on the US Commerce Department's Entity List, and for good reason: UFED requires physical possession of a device, not a zero-click remote exploit. It's standard law-enforcement forensic equipment used daily by police departments from Chicago to Berlin on warranted device searches. Treating it the same as remote spyware would sweep in legitimate criminal investigations worldwide to address a problem that export controls, by design, cannot fix: hardware that already left the warehouse.
The actual failure here is enforcement architecture, not export policy. Scott-Railton's proposed fix — companies that "stop selling to autocrats, remotely-disable their tech after credible reports of abuse, and end the era of plausible deniability by implementing cryptographically-signed watermarks on all imaged devices" — targets the real gap: post-sale accountability. Regulators should condition export licenses on remote-kill capability and audit logging, and buyers should face contractual clawback if evidence surfaces of political misuse. That's a proportionate, enforceable standard. A new prohibited-technology list wouldn't have stopped a UFED unit already sitting in an FSB evidence room in June 2021 — only a kill switch Cellebrite never built would have.