Cellebrite and Russia: the contract ended. The tool did not.
5 min read
On 18 March 2021, Cellebrite, the Israeli company that makes the UFED systems for forensic data extraction from smartphones, announced it had halted “with immediate effect” its sales to Russia and Belarus. The decision followed a Haaretz investigation and a complaint by human rights lawyer Eitay Mack: Russian authorities had used the company’s technology more than twenty-six thousand times against activists and minorities. Three months after that announcement, on 17 June 2021, the same tools — UFED Physical Analyzer and UFED 4PC — extracted WhatsApp, Telegram and Viber data from the phone confiscated from Andrey Pivovarov, then executive director of the NGO Open Russia, detained as he was about to board a flight to Warsaw. This was revealed, five years later, by a forensic analysis by Citizen Lab published on 25 June 2026 — corroborated by the same Russian court records filed against Pivovarov. The supplier had closed the door. The tool, already delivered, kept working.
The facts, in order
- 18 March 2021: Cellebrite announces a halt to sales to Russia and Belarus, following the Haaretz investigation into the use of its tools against opposition figures and minorities. CEO Yossi Carmil speaks of an update to “compliance policies”.
- 31 May 2021: Pivovarov is taken off a flight bound for Warsaw at Pulkovo Airport in St Petersburg. His iPhone 12 and MacBook are confiscated without him providing the passwords.
- 17 June 2021: with the device in custody, forensic traces show the use of UFED Physical Analyzer and UFED 4PC on WhatsApp, Telegram and Viber, including searches for the name Open Russia and other opposition figures. A prosecution document, on the trial record, confirms the tool’s use.
- 15 July 2022: a court in Krasnodar sentences Pivovarov to four years in prison for directing an organisation deemed “undesirable”. Amnesty International describes it as a crackdown on freedom of expression.
- 1 August 2024: Pivovarov is freed in a prisoner exchange between Russia and Western countries.
- 25 June 2026: Citizen Lab publishes the forensic analysis of the phone, returned to Pivovarov in 2023, alongside a similar case in Kenya, where a device belonging to activist Boniface Mwangi was found to have been accessed with the same type of tool following an arbitrary arrest.
- Cellebrite’s position: “any use of legacy Cellebrite hardware in Russia after March 2021 is entirely unauthorised”; Russia “remains permanently on the restricted customer list”. The company maintains that the dated hardware would be incompatible with modern devices and unsupported.
- Citizen Lab’s response: Cellebrite has a documented history of selling to governments known for persecuting activists; the lab is calling for a remote deactivation capability and unique per-client cryptographic markers on every device that performs an extraction.
Nobody disputes the date of the cut-off: Cellebrite did indeed cut ties with Russia in March 2021. The real issue lies elsewhere: the tool, once delivered, kept working for years without the supplier being able to know it, verify it, or stop it.
Lesson one: a terminated contract deactivates nothing if the tool stays offline
The technical point is simple and uncomfortable: UFED units already sold operate without a permanent connection to the supplier. No central server is needed, no licence to renew online: the box keeps working even in isolation, for years. Cellebrite was able to stop selling. It was not able to switch off what it had already delivered. The same holds for much critical on-premise technology: a supplier can terminate a contract, but if the tool runs autonomously, that termination remains administrative, not operational. Before adopting systems destined for sensitive settings, ask how the real shutdown works: a verifiable remote deactivation, not a customer list updated at intervals. It is the difference between an architecture that stays under control and one that merely claims to.
Lesson two: the end client is a risk you inherit, not one you can delegate to the supplier
Cellebrite had — and still has — a restricted customer list. It did not prevent hardware already in circulation from ending up used in a politically motivated prosecution. Due diligence on the end client, however rigorous on paper, does not cover the secondary market, nor devices that remain operational long after a commercial relationship ends. For those who purchase or distribute technology capable of affecting people’s rights — recognition, tracking, data extraction — the lesson is that a supplier’s assurances do not exempt the adopter from their own duty of verification: internal audits, traceability of every use, an impact assessment before deployment, especially in fields such as the public sector or defence, where the use touches fundamental rights.
Lesson three: technological sovereignty is proven with verifiable markers, not press releases
Citizen Lab’s request to Cellebrite — unique per-client cryptographic markers, remote deactivation — is, in substance, a request for governance built into the tool, not declared after the fact. The same holds for any system handling sensitive data: control is not proven with a press release, it is proven with a verifiable log — who used what, when, on what basis. A data and AI infrastructure that does not leave this trail from the design stage onward exposes its adopter to Cellebrite’s problem: having to answer, years later, for a use it could neither see nor prevent. Compliance that holds up starts there, not in trust in the supplier’s word.
What to do
- Ask for technical proof, not a declaration, of how a contract termination actually deactivates a tool already installed with third parties.
- Check your dependence on the supplier: a tool that operates offline or air-gapped for years cannot be governed by a customer list updated after the fact.
- Keep an internal log of every critical deployment — who uses it, where, on what data — independent of, and stricter than, the supplier’s own.
- Carry out a rights impact assessment before adopting surveillance, data extraction, or automated decision-making tools — not just a commercial due diligence check.
Do you use technology capable of affecting sensitive data or people’s rights, and want to check what remains under your control after signing? Half an hour with one of our experts for an initial map of risks and clauses.