Cellebrite A.I CyberSecurity Scoring
Cellebrite
Company Information
Website:http://www.cellebrite.com/
Employees number:1,274
Number of followers:100,903
NAICS:92219
Industry Type:Public Safety
Homepage:cellebrite.com
Cellebrite Risk Score (AI oriented)
Between 600 and 649
CellebritePublic Safety
Updated:
26/06/2026
26/06/2026
630/1000
Poor
Caa
Cellebrite Global Score (TPRM)
xxxx
CellebritePublic Safety
Score locked

CellebritePoor
Current Score
630Caa (POOR)
01000
5 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
637
JUNE 2026
628
MAY 2026
627
APRIL 2026
625
MARCH 2026
622
FEBRUARY 2026
619
JANUARY 2026
617
DECEMBER 2025
611
NOVEMBER 2025
610
OCTOBER 2025
607
SEPTEMBER 2025
604
AUGUST 2025
601
JANUARY 2025
670
Breach
01 Jan 2025 • Cellebrite
Tata Electronics, Cellebrite, Apple, OpenAI, Delta and Coupang: In Other News: Chinese Mythos-Like AI, Tata Electronics Breach, Snyk Layoffs
Cybersecurity Roundup: Key Threats, Breaches, and Industry Shifts
579
CRITICAL-91
DELOPETATAPPCELCOU1782491615
Cybersecurity Roundup: Key Threats, Breaches, and Industry Shifts
This week’s cybersecurity landscape saw significant developments across state-sponsored attacks, corporate breaches, regulatory interventions, and emerging AI-driven threats.
State-Backed Surveillance & Hacking
Citizen Lab revealed that Russian authorities exploited Cellebrite software to extract data from the iPhone of opposition activist Andrey Pivovarov, despite the vendor’s 2021 contract termination. The breach targeted apps like Telegram and WhatsApp, with harvested data suspected to have fueled ColdRiver a state-linked threat group phishing campaigns against Pivovarov’s associates.
Two members of the Scattered Spider hacking group pleaded guilty to the 2024 breach of Transport for London, disrupting fare refund systems and administrative networks. The attack forced 28,000 employees to reset passwords in person, incurring millions in remediation costs.
Corporate Espionage & Data Leaks
A Tata Electronics breach led to the dark web leak of 630 GB of proprietary data, including Apple and Tesla manufacturing schematics and confidential designs. The extortion group World Leaks published the trove, exposing sensitive intellectual property.
AI & National Security Concerns
The Five Eyes alliance issued an urgent advisory warning that frontier AI models are accelerating cyber threats, compressing attack timelines from years to months. The coalition urged organizations to adopt zero-trust architectures, expedite patching, and decommission legacy systems to counter machine-speed intrusions.
The White House intervened in OpenAI’s GPT-5.6 rollout, mandating government-vetted access during its preview phase due to national security risks. This follows regulatory pressures on Anthropic’s advanced AI, reflecting heightened scrutiny over cutting-edge models.
Malware & Evasion Tactics
A North Korean-linked macOS backdoor, macOS.Gaslight, was discovered using adversarial prompt injection to disrupt automated security analysis. The Rust-based malware deploys deceptive error messages to evade LLM-assisted triage tools, while also harvesting data and providing an interactive shell.
Industry & Policy Updates
- Android’s developer verification framework will launch on September 30, 2026, introducing automated registration APIs and mandatory sideloading checkpoints to combat coercion scams. A limited hobbyist tier will allow restricted app distribution.
- CISA is poised for a 600-person recruitment push under a new director, following workforce reductions since January 2025.
- Qihoo 360, a blacklisted Chinese cybersecurity firm, unveiled Tulongfeng, an AI system claimed to rival Western models like Mythos in vulnerability discovery, raising concerns over its potential use in offensive operations.
- Snyk conducted layoffs as part of a restructuring, with reports estimating 90–200 employees affected amid leadership consolidation.
Additional Notes
- Apple patched a Beats eavesdropping flaw, while the DOT closed its Delta-CrowdStrike probe.
- Google’s security layoffs, an AudiA6 takedown, and a $400M fine for Coupang rounded out the week’s secondary developments.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2023
678
Data Leak
01 Jan 2023 • Cellebrite
Cellebrite
Data Leak of Cellebrite Tools and Documentation
611
CRITICAL-67
CEL225381023
Online leaks of 1.7 TB of Cellebrite, a provider of tools for law enforcement and a digital intelligence company, data have been reported.
Numerous allegations assert that the government violated human rights by using the technology provided by Cellbrite to eavesdrop on civilians and journalists.
Hacktivists asserted that the technologies had historically been used against journalists, activists, and dissidents all across the world.
Software and documentation from Cellebrite and MSAB for phone forensics were supplied to us anonymously.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
AUGUST 2022
734
Breach
01 Aug 2022 • Cellebrite
Cellebrite
Cellebrite Data Security Incident
668
CRITICAL-66
CEL224371122
Israel-based smartphone hacking company Cellebrite suffered a data security incident after an anonymous source leaked around 4TB of proprietary data.
The affected products were the company’s flagship product, Cellebrite Mobilogy, and the Cellebrite Team Foundation server.
The exposed data included 430 GB of data from the Cellebrite Team Foundation Server and around 3.6TB of data was compromised and leaked from Cellebrite Mobilogy.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JUNE 2021
746
Cyber Attack
17 Jun 2021 • Cellebrite
Cellebrite and Open Russia: Russia Used Cellebrite Tool to Hack Activist’s iPhone Despite Contract Cancellation
Russian Authorities Used Cellebrite Tools to Extract Data from Opposition Politician’s iPhone Despite Contract Termination
726
HIGH-20
CELOPE1782411871
Russian Authorities Used Cellebrite Tools to Extract Data from Opposition Politician’s iPhone Despite Contract Termination
In June 2021, Russian security services deployed Cellebrite’s Universal Forensic Extraction Device (UFED) to breach the iPhone 12 of Andrey Pivovarov, former director of the pro-democracy nonprofit Open Russia, according to a forensic investigation by Citizen Lab at the University of Toronto. The extraction occurred three months after Cellebrite publicly announced it had ceased all sales to Russian authorities amid human rights concerns.
Pivovarov was detained at St. Petersburg Airport on May 31, 2021, after dissolving Open Russia’s Russian branch to shield staff from prosecution under new laws targeting "undesirable organizations." His devices an iPhone 12 and MacBook were confiscated without consent or passwords and held until 2023, following his four-year prison sentence. He was released in August 2024 as part of a U.S.-Russia prisoner exchange.
Citizen Lab’s analysis, initiated after Pivovarov flagged potential tampering in 2025, uncovered forensic traces of Cellebrite’s UFED on his device, including a Host ID (90161926980658937761372207) linked to the company in prior investigations. The findings were corroborated by Russian forensic documents, including a Ministry of Interior report (No. 1269-17) explicitly naming Cellebrite’s UFED Physical Analyzer and UFED 4PC as the tools used to extract data.
The extraction targeted WhatsApp, Telegram, and Viber communications, along with keyword searches for opposition figures, including Mikhail Khodorkovsky and human rights lawyer Anastasiya Burakova. Cellebrite had publicly terminated Russian contracts in March 2021, with an executive stating that any post-exit use was "unauthorized." However, the offline functionality of UFED tools allowed Russian authorities to continue operations despite the ban.
The incident raises concerns about downstream surveillance risks: individuals flagged in Pivovarov’s data, such as Burakova, were later targeted in phishing campaigns by COLDRIVER, an FSB-linked hacking group, as documented in a 2024 Citizen Lab-Access Now investigation. Researchers suggest the extracted data may have informed subsequent FSB operations against regime critics abroad.
This case adds to a growing pattern of Cellebrite tool misuse in countries like Serbia, Kenya, Jordan, Myanmar, Bahrain, and Botswana, despite partial contract cancellations. While Access Now and Citizen Lab have urged Cellebrite to implement technical safeguards and human rights due diligence, the company has not announced structural changes to its export controls.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2017
772
Breach
01 Jan 2017 • Cellebrite
Cellebrite
Cellebrite Data Breach
701
CRITICAL-71
CEL325131123
The Israeli mobile phone data extraction company Cellebrite was hacked by unknown hackers that provided the 900GB database to Motherboard.
Vice Motherboard said that it received a request from an unidentified source for Cellebrite's 900GB database.
Hashed passwords, technical information about Cellebrite's products, and basic contact details for users who subscribed to receive notifications from the company have all been made public.
To notify its clients about the data breach that impacted an external web server hosting the business' licence management system, Cellebrite released a statement.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Cellebrite ??
What was Cellebrite's A.I Rankiteo Cyber Score in June 2026 ??
What was Cellebrite's A.I Rankiteo Cyber Score in May 2026 ??
What was Cellebrite's A.I Rankiteo Cyber Score in April 2026 ??
What was Cellebrite's A.I Rankiteo Cyber Score in March 2026 ??
What was Cellebrite's A.I Rankiteo Cyber Score in February 2026 ??
What was Cellebrite's A.I Rankiteo Cyber Score in January 2026 ??
What was Cellebrite's A.I Rankiteo Cyber Score in December 2025 ??
What was Cellebrite's A.I Rankiteo Cyber Score in November 2025 ??
What was Cellebrite's A.I Rankiteo Cyber Score in October 2025 ??
What was Cellebrite's A.I Rankiteo Cyber Score in September 2025 ??
What was Cellebrite's A.I Rankiteo Cyber Score in August 2025 ??
What is the average per-incident point impact on Cellebrite's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Cellebrite ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Cellebrite's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?