Categories: Web and IT News

Scotland Yard Pauses Russian-Linked Phone Forensics Tool After US Charges Reveal Hidden Moscow Ties

The Metropolitan Police has suspended its use of digital forensics software from Oxygen Forensics. The move follows explosive US allegations that the Virginia-based firm was secretly controlled by Russian nationals and developed its tools in Moscow, with connections to Russia’s FSB security service.

Scotland Yard confirmed the pause and a full review last week. A spokesperson told The Times the software ran on a closed system with no internet connection. Its deployment accounted for less than 0.2 percent of more than 23,000 digital forensics actions in the past year. “We have paused our use of the tool while we carry out a full review,” the spokesperson said. “At this time, we believe any impact to ongoing investigations will be extremely limited. The Met does not share any data obtained from investigations with Oxygen Forensics Inc.”

Short pause. Limited exposure. Yet the episode exposes deeper cracks in how Western law enforcement sources its most sensitive extraction technology. The three-year contract dated to December 2023. Oxygen’s Forensic Detective software pulls data from seized phones and devices in criminal, terrorism and espionage probes. The Met leads many such cases.

US prosecutors last week charged Oxygen CEO Lee Reiber and Russian national Oleg Sergeyevich Davydov. They allege the pair concealed the company’s true ownership and development operations after Russia’s full-scale invasion of Ukraine. Documents show the firm was controlled through a Cyprus holding company by five Russian nationals, including Davydov. A related Moscow firm, MKO, counted the FSB among its customers, according to the charges reported by Cybernews.

But the story runs wider. POLITICO revealed Oxygen participated in EU-backed digital evidence projects before supplying the technology to police in multiple member states. Romania’s National Anticorruption Directorate has started procedures to terminate its contract after buying a license as recently as August 2026. Other buyers included forces in Germany, Spain, Italy, Poland and Hungary. The National Police Chiefs’ Council urged UK forces to review their own use.

And this isn’t the first time forensics vendors face questions over Russian access. Six months earlier, researchers at the Citizen Lab documented how Russian authorities used Cellebrite’s UFED tool on the iPhone of opposition activist Andrey Pivovarov in June 2021. That came three months after Cellebrite publicly announced it had cut all sales and services to Russian government customers. The firm insisted any post-cutoff use was unauthorized. Yet court records from Pivovarov’s prosecution explicitly cited Cellebrite extraction of WhatsApp, Telegram and other data. Reports from TechCrunch and Forbes laid out the forensic artifacts and official documents.

Prosecutors have not alleged Oxygen’s software contained backdoors or malicious code. No claims of unauthorized data exfiltration appear in the public filings. Still, the ownership deception raises immediate national security flags for agencies handling terrorism and espionage. Data extracted from suspects’ devices can include encrypted chats, location history, contacts and deleted files. Trust in the vendor matters.

Oxygen presented itself as an independent American company to win government business. That facade held until the Justice Department investigation peeled it back. Reiber and Davydov appeared in court on extradition matters. The case continues.

Law enforcement’s hunger for mobile extraction capabilities grows each year. Phones hold the raw material of modern investigations. Vendors like Oxygen, Cellebrite and others promise fast, comprehensive access even to locked and encrypted devices. But supply chains prove opaque. Corporate structures cross borders. Sanctions and export controls create incentives to hide ownership.

European forces reacted quickly once the allegations surfaced. Romania acted decisively. The Met’s limited usage offers some comfort. Yet the review must examine not just this contract but the broader procurement process that allowed a firm with such concealed ties to secure UK police business in late 2023, well after the invasion began.

So questions linger. How many other tools carry similar hidden risks? Can agencies verify vendor claims about development locations and ownership? The closed IT system used by the Met reduces some exposure. No data went back to Oxygen. That design choice now looks prescient.

Yet the incident underscores a persistent vulnerability. Digital forensics sits at the intersection of law enforcement capability and intelligence risk. When the vendor’s true controllers include nationals tied to adversarial security services, even limited use invites scrutiny. UK forces beyond the Met have used the software too. Their assessments are underway.

The Oxygen affair follows a pattern seen with Cellebrite. Public commitments to cut ties with Russia failed to prevent continued use by Moscow’s investigators. Legacy hardware, unofficial channels and determined state actors undermine corporate controls. Forensic tools don’t simply stop working when a vendor flips a switch.

Police leaders now face a balancing act. They cannot abandon mobile forensics. Investigations would grind to a halt. Alternatives exist, but switching carries costs in time, training and capability. Some forces may accelerate moves toward domestic or allied providers.

The Met’s statement struck a calm tone. Limited impact expected. Full review in progress. For an organization still recovering from multiple scandals, another technology controversy arrives at an awkward moment. But the facts support measured response. Minimal usage. Isolated system. No data sharing.

That doesn’t erase the procurement failure. Someone signed that 2023 contract. Due diligence either missed or downplayed the risks. In an era of heightened concern over Russian influence operations, such oversights carry consequences.

Further details may emerge as the US case proceeds and reviews conclude. For now, the suspension stands. European allies take similar steps. The forensics industry confronts fresh calls for transparency on ownership, development practices and end-user controls.

Short term, the Met will lean on other tools. Longer term, the episode may drive tighter vetting standards across UK policing. Oxygen’s software once promised efficiency in cracking devices. Its hidden Russian connections now deliver a different kind of lesson.

Scotland Yard Pauses Russian-Linked Phone Forensics Tool After US Charges Reveal Hidden Moscow Ties first appeared on Web and IT News.

awnewsor

Recent Posts

Suno’s Speech Beta Pushes AI Audio Beyond Songs Into Narrated Soundtracks

Suno built its name on turning simple text prompts into complete songs. Now the company…

1 hour ago

Meta’s Muse Sets Record for Data Appetite as Privacy Fears Mount

Meta launched Muse barely a month ago. The personal AI agent, styled as a helpful…

1 hour ago

ChatGPT Mac App Flaw Exposed Chat Logs and Browser Sessions to Local Attacks

Security researchers uncovered a vulnerability in OpenAI’s ChatGPT application for macOS that could have handed…

1 hour ago

AI’s Token Tax Upends SaaS Margins: How Vayu Arms CFOs With Real-Time Customer Profitability

Software used to be simple. One customer, one seat, almost zero incremental cost. Finance teams…

1 hour ago

AI Agents Now Write CUDA Kernels That Humans Struggle to Explain

Elite programmers who coax peak performance from Nvidia chips once spent their days crafting intricate…

1 hour ago

Cyberattacks Expose the Fragile State of Business Continuity Planning

Business leaders once treated cyberattacks as distant threats best left to the IT department. No…

1 hour ago

This website uses cookies.