Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Cellebrite

Cellebrite Vendor Cyber Rating & Cyber Score

cellebrite.com

Cellebrite is the leader in digital intelligence and investigative analytics, partnering with public and private organizations to transform how they manage data in investigations to accelerate justice and ensure data security.


Cellebrite A.I CyberSecurity Scoring

Cellebrite
Company Information
Website:http://www.cellebrite.com/
Employees number:1,274
Number of followers:100,903
NAICS:92219
Industry Type:Public Safety
Homepage:cellebrite.com
Cellebrite Risk Score (AI oriented)
Between 600 and 649
logo
CellebritePublic Safety
Updated:
26/06/2026
630/1000
Poor
Caa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Cellebrite Global Score (TPRM)
xxxx
logo
CellebritePublic Safety
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Cellebrite
CellebritePoor
Current Score
630Caa (POOR)
01000
5 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
637Before Incident
JUNE 2026
628Before Incident
MAY 2026
627Before Incident
APRIL 2026
625Before Incident
MARCH 2026
622Before Incident
FEBRUARY 2026
619Before Incident
JANUARY 2026
617Before Incident
DECEMBER 2025
611Before Incident
NOVEMBER 2025
610Before Incident
OCTOBER 2025
607Before Incident
SEPTEMBER 2025
604Before Incident
AUGUST 2025
601Before Incident
JANUARY 2025
670Before Incident
Breach
01 Jan 2025Cellebrite
Tata Electronics, Cellebrite, Apple, OpenAI, Delta and Coupang: In Other News: Chinese Mythos-Like AI, Tata Electronics Breach, Snyk Layoffs

Cybersecurity Roundup: Key Threats, Breaches, and Industry Shifts

579After Incident
CRITICAL-91
DELOPETATAPPCELCOU1782491615
Cybersecurity Roundup: Key Threats, Breaches, and Industry Shifts This week’s cybersecurity landscape saw significant developments across state-sponsored attacks, corporate breaches, regulatory interventions, and emerging AI-driven threats. State-Backed Surveillance & Hacking Citizen Lab revealed that Russian authorities exploited Cellebrite software to extract data from the iPhone of opposition activist Andrey Pivovarov, despite the vendor’s 2021 contract termination. The breach targeted apps like Telegram and WhatsApp, with harvested data suspected to have fueled ColdRiver a state-linked threat group phishing campaigns against Pivovarov’s associates. Two members of the Scattered Spider hacking group pleaded guilty to the 2024 breach of Transport for London, disrupting fare refund systems and administrative networks. The attack forced 28,000 employees to reset passwords in person, incurring millions in remediation costs. Corporate Espionage & Data Leaks A Tata Electronics breach led to the dark web leak of 630 GB of proprietary data, including Apple and Tesla manufacturing schematics and confidential designs. The extortion group World Leaks published the trove, exposing sensitive intellectual property. AI & National Security Concerns The Five Eyes alliance issued an urgent advisory warning that frontier AI models are accelerating cyber threats, compressing attack timelines from years to months. The coalition urged organizations to adopt zero-trust architectures, expedite patching, and decommission legacy systems to counter machine-speed intrusions. The White House intervened in OpenAI’s GPT-5.6 rollout, mandating government-vetted access during its preview phase due to national security risks. This follows regulatory pressures on Anthropic’s advanced AI, reflecting heightened scrutiny over cutting-edge models. Malware & Evasion Tactics A North Korean-linked macOS backdoor, macOS.Gaslight, was discovered using adversarial prompt injection to disrupt automated security analysis. The Rust-based malware deploys deceptive error messages to evade LLM-assisted triage tools, while also harvesting data and providing an interactive shell. Industry & Policy Updates - Android’s developer verification framework will launch on September 30, 2026, introducing automated registration APIs and mandatory sideloading checkpoints to combat coercion scams. A limited hobbyist tier will allow restricted app distribution. - CISA is poised for a 600-person recruitment push under a new director, following workforce reductions since January 2025. - Qihoo 360, a blacklisted Chinese cybersecurity firm, unveiled Tulongfeng, an AI system claimed to rival Western models like Mythos in vulnerability discovery, raising concerns over its potential use in offensive operations. - Snyk conducted layoffs as part of a restructuring, with reports estimating 90–200 employees affected amid leadership consolidation. Additional Notes - Apple patched a Beats eavesdropping flaw, while the DOT closed its Delta-CrowdStrike probe. - Google’s security layoffs, an AudiA6 takedown, and a $400M fine for Coupang rounded out the week’s secondary developments.
INCIDENT DETAILS -
TYPE
State-Backed Surveillance & HackingCorporate Espionage & Data LeaksAI & National Security ConcernsMalware & Evasion Tactics
MOTIVATION
SurveillanceEspionageFinancial ExtortionIntellectual Property TheftNational Security
IMPACT
Financial Loss: Millions in remediation costs (Transport for London)630 GB of proprietary data (Tata Electronics)Telegram and WhatsApp data (Andrey Pivovarov)Apple and Tesla manufacturing schematicsTransport for London fare refund systemsAdministrative networksmacOS systems28,000 employees forced to reset passwords in person (Transport for London)
DATA BREACH
Proprietary dataManufacturing schematicsMessaging app dataIntellectual propertySensitivity Of Data: High630 GB of data (Tata Electronics)Telegram and WhatsApp data (Andrey Pivovarov)
JANUARY 2023
678Before Incident
Data Leak
01 Jan 2023Cellebrite
Cellebrite

Data Leak of Cellebrite Tools and Documentation

611After Incident
CRITICAL-67
CEL225381023
Online leaks of 1.7 TB of Cellebrite, a provider of tools for law enforcement and a digital intelligence company, data have been reported. Numerous allegations assert that the government violated human rights by using the technology provided by Cellbrite to eavesdrop on civilians and journalists. Hacktivists asserted that the technologies had historically been used against journalists, activists, and dissidents all across the world. Software and documentation from Cellebrite and MSAB for phone forensics were supplied to us anonymously.
INCIDENT DETAILS -
TYPE
Data Leak
MOTIVATION
Expose alleged human rights violations
IMPACT
SoftwareDocumentation
DATA BREACH
SoftwareDocumentation
AUGUST 2022
734Before Incident
Breach
01 Aug 2022Cellebrite
Cellebrite

Cellebrite Data Security Incident

668After Incident
CRITICAL-66
CEL224371122
Israel-based smartphone hacking company Cellebrite suffered a data security incident after an anonymous source leaked around 4TB of proprietary data. The affected products were the company’s flagship product, Cellebrite Mobilogy, and the Cellebrite Team Foundation server. The exposed data included 430 GB of data from the Cellebrite Team Foundation Server and around 3.6TB of data was compromised and leaked from Cellebrite Mobilogy.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
430 GB from Cellebrite Team Foundation Server3.6TB from Cellebrite MobilogyCellebrite MobilogyCellebrite Team Foundation server
DATA BREACH
Type Of Data Compromised: Proprietary Data
JUNE 2021
746Before Incident
Cyber Attack
17 Jun 2021Cellebrite
Cellebrite and Open Russia: Russia Used Cellebrite Tool to Hack Activist’s iPhone Despite Contract Cancellation

Russian Authorities Used Cellebrite Tools to Extract Data from Opposition Politician’s iPhone Despite Contract Termination

726After Incident
HIGH-20
CELOPE1782411871
Russian Authorities Used Cellebrite Tools to Extract Data from Opposition Politician’s iPhone Despite Contract Termination In June 2021, Russian security services deployed Cellebrite’s Universal Forensic Extraction Device (UFED) to breach the iPhone 12 of Andrey Pivovarov, former director of the pro-democracy nonprofit Open Russia, according to a forensic investigation by Citizen Lab at the University of Toronto. The extraction occurred three months after Cellebrite publicly announced it had ceased all sales to Russian authorities amid human rights concerns. Pivovarov was detained at St. Petersburg Airport on May 31, 2021, after dissolving Open Russia’s Russian branch to shield staff from prosecution under new laws targeting "undesirable organizations." His devices an iPhone 12 and MacBook were confiscated without consent or passwords and held until 2023, following his four-year prison sentence. He was released in August 2024 as part of a U.S.-Russia prisoner exchange. Citizen Lab’s analysis, initiated after Pivovarov flagged potential tampering in 2025, uncovered forensic traces of Cellebrite’s UFED on his device, including a Host ID (90161926980658937761372207) linked to the company in prior investigations. The findings were corroborated by Russian forensic documents, including a Ministry of Interior report (No. 1269-17) explicitly naming Cellebrite’s UFED Physical Analyzer and UFED 4PC as the tools used to extract data. The extraction targeted WhatsApp, Telegram, and Viber communications, along with keyword searches for opposition figures, including Mikhail Khodorkovsky and human rights lawyer Anastasiya Burakova. Cellebrite had publicly terminated Russian contracts in March 2021, with an executive stating that any post-exit use was "unauthorized." However, the offline functionality of UFED tools allowed Russian authorities to continue operations despite the ban. The incident raises concerns about downstream surveillance risks: individuals flagged in Pivovarov’s data, such as Burakova, were later targeted in phishing campaigns by COLDRIVER, an FSB-linked hacking group, as documented in a 2024 Citizen Lab-Access Now investigation. Researchers suggest the extracted data may have informed subsequent FSB operations against regime critics abroad. This case adds to a growing pattern of Cellebrite tool misuse in countries like Serbia, Kenya, Jordan, Myanmar, Bahrain, and Botswana, despite partial contract cancellations. While Access Now and Citizen Lab have urged Cellebrite to implement technical safeguards and human rights due diligence, the company has not announced structural changes to its export controls.
INCIDENT DETAILS -
TYPE
Unauthorized Data Extraction
MOTIVATION
Surveillance of political opposition, suppression of dissent
IMPACT
Data Compromised: WhatsApp, Telegram, and Viber communications; keyword searches for opposition figuresiPhone 12MacBookOperational Impact: Compromised personal and organizational communications of a pro-democracy nonprofitBrand Reputation Impact: Reputational damage to Open Russia and associated individualsLegal Liabilities: Potential violations of human rights and privacy lawsIdentity Theft Risk: High (extracted PII used in subsequent phishing campaigns)
DATA BREACH
Messaging app communicationsKeyword searches for opposition figuresPersonally identifiable information (PII)Sensitivity Of Data: High (political communications, PII of activists)Data Exfiltration: Likely (used to inform subsequent FSB operations)Personally Identifiable Information: Yes (names of opposition figures, activists)
JANUARY 2017
772Before Incident
Breach
01 Jan 2017Cellebrite
Cellebrite

Cellebrite Data Breach

701After Incident
CRITICAL-71
CEL325131123
The Israeli mobile phone data extraction company Cellebrite was hacked by unknown hackers that provided the 900GB database to Motherboard. Vice Motherboard said that it received a request from an unidentified source for Cellebrite's 900GB database. Hashed passwords, technical information about Cellebrite's products, and basic contact details for users who subscribed to receive notifications from the company have all been made public. To notify its clients about the data breach that impacted an external web server hosting the business' licence management system, Cellebrite released a statement.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Hashed passwordsTechnical information about Cellebrite's productsBasic contact details for usersExternal web server hosting the business' licence management system
DATA BREACH
Hashed passwordsTechnical informationBasic contact details

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Cellebrite ?
?
What was Cellebrite's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Cellebrite's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Cellebrite's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Cellebrite's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Cellebrite's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Cellebrite's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Cellebrite's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Cellebrite's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Cellebrite's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Cellebrite's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Cellebrite's A.I Rankiteo Cyber Score in August 2025 ?
?
What is the average per-incident point impact on Cellebrite's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Cellebrite ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Cellebrite's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Cellebrite Cyber Scoring History | Rankiteo