Cellebrite Tools Used Against Russian Activist Andrey Pivovarov, Citizen Lab Investigation Finds

Russian authorities used Cellebrite forensic extraction tools to target prominent activist Andrey Pivovarov, according to a Citizen Lab investigation reported by Access Now published on 25 June 2026. The finding is notable because Cellebrite, the Israeli digital intelligence company, suspended all sales of its products to Russia and Belarus effective March 18, 2021.
The gap between that suspension date and the documented use against Pivovarov raises an unresolved question about supply chain provenance: whether the tools reached Russian law enforcement before the cutoff, through third-party channels afterward, or via some other route. The Access Now report does not appear to resolve that question definitively, but the documented use is the operative fact.
Pivovarov is a well-known figure in Russian civil society. His targeting fits a pattern that researchers and digital rights organizations have tracked across multiple jurisdictions. In December 2024, Amnesty International reported that Serbian authorities had deployed Cellebrite forensic extraction tools — alongside spyware — against journalists and activists in a documented surveillance campaign. The two cases are geographically distinct, but the operational profile is similar: state actors using commercially licensed forensic tooling against civil society rather than criminal suspects.
Cellebrite occupies a contested position in the digital forensics market. The company argues, on its own website, that authorized extraction of data from a device is categorically different from hacking — a framing that carries legal weight in jurisdictions where law enforcement obtains court orders, but that critics argue obscures the real-world outcome when the authorizing state is itself the threat actor. Cellebrite has also publicly acknowledged, in its 2021 investor filings, that it is a target for privacy and human rights activists who object to how its technology is deployed.
The Russia sales suspension was, at the time, framed as a values-based decision. Cellebrite issued a press release stating it had stopped selling digital intelligence offerings in the Russian Federation and Belarus as of March 18, 2021. That decision pre-dates Russia's full-scale invasion of Ukraine by roughly eleven months, which gives it a somewhat different character than the wave of corporate exits that followed February 2022.
Worth flagging here: the documented use in Russia and the earlier findings in Serbia together suggest that Cellebrite's export controls and end-user agreements have not been a reliable barrier to deployment against civil society targets. Whether that is a failure of contract enforcement, a resale problem, or a reflection of tool stockpiling before cutoffs is a question the company has not, to date, answered publicly with specificity.
Cellebrite's core technology — UFED and associated products — is designed for lawful forensic extraction: imaging device storage, recovering deleted files, parsing encrypted containers where legal authority exists. In the hands of a functional rule-of-law jurisdiction with independent courts, that capability serves a legitimate investigative purpose. The problem the Pivovarov case illustrates is not the technology itself but the absence of any technical enforcement layer that would prevent use against targets the vendor has nominally declined to serve.
This is not a new tension in dual-use security tooling. The commercial spyware sector — NSO Group, Intellexa, and others — has faced the same structural critique for years. Cellebrite's situation differs in degree: its tools are marketed explicitly to law enforcement, require physical or near-physical device access rather than remote zero-click delivery, and are subject to export licensing. But the end result, a dissident's device forensically examined by a state actor with no legitimate judicial oversight of that specific individual, is functionally the same.
Cellebrite has not, as of the publication date of this article, issued a public response to the Access Now findings. Brief has not independently verified all elements of the Citizen Lab investigation. The story will likely develop further as digital rights organizations and journalists examine the provenance of the specific tools used and the timeline of their acquisition.


