Citizen Lab: Cellebrite UFED Used on Pivovarov iPhone Three Months After Russia Sales Halt
Forensic traces and a Russian court filing place a UFED extraction on the activist's device in June 2021, raising hard questions about post-sale controls on dual-use forensic kit.

Key points
- Citizen Lab published findings on June 25 concluding Russian authorities used Cellebrite's UFED on Andrey Pivovarov's iPhone in June 2021.
- Cellebrite had announced in March 2021 it would stop selling to Russia and Belarus, making the extraction three months post-cutoff.
- The finding rests on on-device traces and a corroborating Russian court filing, a pairing Citizen Lab describes as rare.
- No framework, Israeli, US or EU, cleanly covers what happens when a vendor exits a market but hardware already in country keeps working.
- Cellebrite has not published a response to the specific Pivovarov findings as of this writing.
Does an announced sales cutoff actually stop the tool working?
It doesn't, and that's the practical point regulators keep dancing around. Cellebrite's March 2021 announcement was a commercial decision, not a license condition imposed by an export authority. Once hardware and licenses are in country, ongoing controls depend on update entitlements, dongle activation and contractual terms rather than enforceable post-sale clawbacks. The Citizen Lab report, published June 25, documents exactly this gap: a UFED extraction on Pivovarov's device three months after the cutoff, corroborated by both on-device artifacts and an official Russian court filing.
Pivovarov, former head of Open Russia, was detained at Pulkovo airport in May 2021 while boarding a flight to Warsaw and was later convicted for leading an organization classified as undesirable under Russian law. He's serving a four-year sentence.
What the regulatory frameworks actually say
Israel's Defense Export Control Agency regulates UFED exports under national export-control law, but published end-use restrictions on already-delivered units are limited. The Biden-era executive order on commercial spyware restricted US government use of tools meeting certain criteria, but forensic extraction devices sit in a different category from network-injection implants. The EU's dual-use regulation captures cyber-surveillance items and places end-user due diligence obligations on exporters, yet neither framework addresses deployed units that outlast a vendor's commercial exit.
This is the gap the Pivovarov case puts on paper. Citizen Lab's report doesn't allege Cellebrite directly enabled the June 2021 extraction; it documents that an extraction occurred, with that tool, on that device, after the announced exit. The distinction matters for what regulators can actually do about it.
Cellebrite has previously said it terminates customer access when misuse is identified and conducts human-rights due diligence on sales. The company hadn't responded to the specific findings by publication time.
Should you worry about dual-use forensic tools in repressive states?
The worry isn't theoretical anymore. This case gives advocates and regulators a concrete, document-backed example to cite. Three things are worth watching: whether Israeli authorities open any review of post-March 2021 service or license arrangements for Russian customers; whether US Commerce, which placed NSO Group and Candiru on its Entity List in November 2021, treats forensic vendors differently in future actions; and whether the next round of EU export-control guidance names UFED-class tools by category rather than leaving them to case-by-case interpretation.
Threat Vectr first covered Citizen Lab's work on June 26, 2026, and this report is the kind of output that shifts those policy conversations from the abstract to the specific. The real test isn't what Cellebrite announced in March 2021. It's what obligations attach to the kit that was already shipped.



