Citizen Lab: Cellebrite UFED Used on Pivovarov iPhone Three Months After Russia Sales Halt

Forensic traces and a Russian court filing place a UFED extraction on the activist's device in June 2021, raising hard questions about post-sale controls on dual-use forensic kit.

ThreatVectr Newsdesk· 3 min read
Citizen Lab: Cellebrite UFED Used on Pivovarov iPhone Three Months After Russia Sales Halt
Share

A new Citizen Lab analysis published June 25 concludes that Russian authorities used Cellebrite's Universal Forensic Extraction Device on the iPhone of jailed opposition activist Andrey Pivovarov in June 2021. That date matters. Cellebrite had announced in March 2021 that it would stop selling to Russia and Belarus.

The finding rests on a rare pairing: artifacts recovered from the device itself and a Russian official record corroborating the extraction.

Pivovarov, the former head of Open Russia, was pulled off a Warsaw-bound flight at Pulkovo in May 2021 and later convicted under Article 284.1 of the Russian Criminal Code for leading an "undesirable organization." He is serving a four-year sentence.

Citizen Lab's researchers identified on-device traces consistent with UFED's extraction process. A Russian court filing referenced in the report describes the forensic procedure performed on the handset, including the tool used. The two data points line up on timing and method.

The gap between an announced sales cutoff and an apparent in-field use is the part regulators will want to read closely.

Cellebrite's March 2021 statement was a commercial decision, not a license condition imposed by an export authority. Israel's Defense Export Control Agency regulates UFED exports under the Defense Export Control Law, 5767-2007, but published end-use restrictions on already-delivered units are limited. Once hardware and licenses are in country, ongoing controls depend on update entitlements, dongle activation and contractual terms — not all of which translate into enforceable post-sale clawbacks.

That distinction matters for the current US and EU policy conversation on mercenary spyware and forensic tooling. The Biden-era Executive Order 14093 (March 27, 2023) restricted US government use of commercial spyware meeting certain criteria, but forensic extraction tools sit in a different bucket from network-injection implants. The EU's dual-use regulation, Regulation (EU) 2021/821, captures "cyber-surveillance items" under Article 5, with end-user due diligence obligations on exporters. Neither framework cleanly addresses what happens when a vendor publicly exits a market but deployed units keep working.

Citizen Lab's writeup is available here: https://citizenlab.ca/.

Cellebrite has previously said it terminates customer access when misuse is identified and that it conducts human-rights due diligence on sales. The company has not, as of this writing, published a response to the specific Pivovarov findings.

A few things to watch.

Whether Israeli regulators open any review of the post-March 2021 service or license posture for Russian customers. Whether US Commerce, which added NSO Group and Candiru to the Entity List in November 2021, treats forensic vendors differently going forward. And whether the next round of EU export-control guidance under 2021/821 names UFED-class tools explicitly.

The report does not allege Cellebrite directly enabled the June 2021 extraction. It documents that an extraction occurred, on that device, with that tool, after the announced exit.

© 2026 Threat Vectr