Vendor Cutoff Failed to Stop Seized-Device Forensics

A sales cutoff does not stop abuse once the forensic gear is already in government hands. The new piece here is confirmation, not a new exploit: Citizen Lab now ties Russian authorities’ June 2021 access to Cellebrite UFED on a seized iPhone, showing the tool kept working offline months after Cellebrite said it would stop selling to Russia and Belarus. The evidence comes from two places that line up: traces on the phone itself and a Russian prosecution report that names UFED Physical Analyzer and UFED 4PC. The report also shows searches for opposition contacts and failed login attempts against the MacBook, which fits the picture of custody-side extraction rather than remote intrusion. The gap is the one vendor cutoffs do not close. If a device is already seized, offline forensic systems can still pull data from it long after support ends, so the control is weaker than it looks when the hardware remains in the field.

Part of the PlainSec briefing for 2026-06-26

Sources