RUSSIAN AUTHORITIES USED CELLEBRITE TOOLS TO HACK ACTIVIST'S PHONE
Russian authorities used digital forensics software made by Israeli company Cellebrite to access the mobile phone of Andrey Pivovarov, a human rights defender and former director of non-profit organisation Open Russia, according to an investigation by the University of Toronto's Citizen Lab. The researchers found traces of Cellebrite's forensic tools on Pivovarov's iPhone 12 on or around 17 June 2021, when the device was in possession of the Russian government. Pivovarov did not consent to the access and had not provided passwords for either his iPhone 12 or MacBook. His devices were not returned to his legal representatives until 2023, two years after initial seizure, whilst he was serving a prison sentence.
The Citizen Lab's analysis identified use of Cellebrite's UFED Physical Analyser and UFED 4PC toolkit, findings corroborated by official documentation published by Russian authorities titled "Forensic Expert Report No. 1269-17". The tools enable extraction and analysis of data from a broad range of devices. Russian authorities allegedly accessed WhatsApp, Telegram and Viber to gather information about Pivovarov that could support his prosecution, searching for terms including "Open Russia Civic Movement" and the names of opposition figures such as Mikhail Khodorkovsky. The researchers found evidence of failed login attempts on Pivovarov's encrypted MacBook on the same day the iPhone was successfully accessed.
Cellebrite stated the hardware used predates current sanctions and was deployed without company consent. The company previously cancelled its contracts with Russian customers following international sanctions. Pivovarov has since been released from prison and retrieved his devices after first contacting the Citizen Lab last year. The findings raise questions about enforcement of technology export restrictions during geopolitical conflicts.