Russian Authorities Used Israeli Forensic Tools Against Activist—After Vendor's Sales Ban

Russian authorities used Cellebrite forensic extraction tools to target prominent activist Andrey Pivovarov, according to a Citizen Lab investigation reported by Access Now published on 25 June 2026. Cellebrite, an Israeli digital intelligence company, suspended all sales of its products to Russia and Belarus effective March 18, 2021.
The timing is the question. The suspension was announced more than a year before Russia's invasion of Ukraine. The company has not publicly explained whether the tools used against Pivovarov were acquired before the cutoff, resold by intermediaries afterward, or obtained through some other route. Access Now's report documents the use but does not definitively establish how the tools arrived.
Pivovarov is a prominent figure in Russian civil society. His case follows a similar pattern identified by human rights organizations elsewhere. In December 2024, Amnesty International reported that Serbian authorities had deployed Cellebrite tools against journalists and activists in a documented surveillance campaign. The two cases are geographically separate, but operationally alike: state actors using commercially licensed forensic software against civil society figures rather than criminal suspects.
Cellebrite operates in the digital forensics market, where a fundamental disagreement exists about the nature of its work. The company argues that authorized data extraction—pulling information from a device with legal permission—is fundamentally different from hacking. This distinction has legal standing in jurisdictions with functional courts and warrant requirements. Critics counter that the real-world outcome is identical when the state doing the authorizing is itself the threat to the person being targeted. Cellebrite acknowledged in its 2021 investor filings that it faces opposition from privacy and human rights groups who object to how its technology is used in the field.
The 2021 sales suspension was announced as a values-based decision. Whether that decision reflected geopolitical concerns or principled opposition to Russian law enforcement practices, the company did not specify. What is clear from both the Russia case and the Serbian findings is that Cellebrite's contractual controls and export restrictions have not prevented deployment against civil society targets.
At a broader level, there is a structural pattern worth examining here. Cellebrite's tools—primarily UFED and related products—perform lawful forensic functions: they image device storage, recover deleted files, and unlock encrypted containers when legal authority exists to do so. When deployed by courts with genuine judicial independence, these capabilities serve legitimate investigative purposes. The problem the Pivovarov case illustrates is simpler: nothing in the technology prevents a state from using it against targets the vendor has declined to serve.
This tension is familiar in the dual-use security tooling space. The commercial spyware industry—NSO Group, Intellexa, and others—has faced the same structural critique for years. Cellebrite differs in important details. Its tools are marketed explicitly to law enforcement; they require hands-on or near-hands-on access to a device rather than remote delivery; and they are subject to export licensing regimes. But when a dissident's phone is forensically examined by state authorities without legitimate judicial review of that specific individual, the functional outcome remains the same.
Cellebrite has not publicly responded to the Access Now findings as of this writing. Brief has not independently verified every detail of the Citizen Lab investigation. The story is likely to develop as digital rights groups and journalists trace where these specific tools came from and when they were acquired.


