Full Report
U.S. authorities have accused executives of Oxygen Forensics, a company that sold software to the Pentagon and Immigration and Customs Enforcement (ICE), of…
Analysis Summary
# Incident Report: Supply Chain Integrity & Illicit Foreign Control of Forensic Software
## Executive Summary
U.S. authorities have arrested the CEO and CTO of Oxygen Forensics for allegedly concealing that the company was controlled by Russian nationals and that its software was developed in Russia. While the company secured sensitive contracts with the Pentagon and ICE, it simultaneously provided the same smartphone-extraction tools to the Russian FSB to target journalists and activists. The incident represents a significant supply chain compromise where U.S. government forensic capabilities were shared with a foreign adversary.
## Incident Details
- **Discovery Date:** September 20, 2026 (Date of arrests/Public unsealing)
- **Incident Date:** March 2022 – September 2026
- **Affected Organization:** U.S. Department of Defense (Pentagon), U.S. Immigration and Customs Enforcement (ICE)
- **Sector:** Government / Law Enforcement / Defense
- **Geography:** United States (Virginia, Idaho), Russia, United Kingdom
## Timeline of Events
### Initial Access
- **Date/Time:** 2013 (Founding) / March 2022 (Start of formal conspiracy)
- **Vector:** Supply Chain Fraud / Misrepresentation
- **Details:** Executives allegedly falsified corporate records to claim the company was U.S.-owned and the software was U.S.-developed to pass federal procurement requirements.
### Lateral Movement
- **Details:** By embedding software into federal networks (ICE and Pentagon), the company gained "inside" status. The "movement" was not digital but organizational, moving through the federal procurement process to gain trust and access to sensitive law enforcement environments.
### Data Exfiltration/Impact
- **Details:** While specific U.S. data theft is not yet detailed, the software was used by the Russian FSB to exfiltrate private WhatsApp messages and data from locked iPhones belonging to opposition figures and journalists (e.g., Alsu Kurmasheva).
### Detection & Response
- **Discovery:** U.S. federal investigation into ownership structures and software origins.
- **Response Actions:** Arrest of CEO Lee Reiber in Idaho and CTO Oleg Davydov in London; seizure of over 50 company domains and corporate bank accounts.
## Attack Methodology
- **Initial Access:** Fraudulent misrepresentation of software origin and ownership.
- **Persistence:** Appointment of a U.S. citizen (Reiber) as CEO in March 2022 to act as a front for Russian stakeholders.
- **Defense Evasion:** Removal of Russian names from official corporate records and use of Cyprus-registered holding companies to mask Russian ownership.
- **Collection:** The software ("Mobile Forensic Expert") is designed for deep data gathering from mobile devices, including bypassing encryption on iPhone 14 models.
- **Impact:** Dual-use capability where tools developed for the U.S. government were also used by the FSB to suppress political dissent.
## Impact Assessment
- **Financial:** Seizure of company accounts; potential loss of millions in federal contracts.
- **Data Breach:** High risk that sensitive U.S. forensic methodologies were exposed to Russian intelligence.
- **Operational:** Disruption of forensic capabilities for ICE and Pentagon as software integrity is now questioned.
- **Reputational:** Severe blow to the "Oxygen Forensics" brand and U.S. government supply chain vetting processes.
## Indicators of Compromise
- **Network indicators:** Domains associated with the company (e.g., oxygen-forensic[.]com - *defanged*)
- **File indicators:** Mobile Forensic Expert / Mobilny Kriminalist software binaries.
- **Behavioral indicators:** Inconsistent corporate filings regarding Beneficial Ownership; presence of Moscow-based development teams for "U.S.-made" products.
## Response Actions
- **Containment measures:** U.S. court-ordered seizure of 50+ domains to prevent further distribution or remote communication.
- **Eradication steps:** Legal proceedings initiated for extradition and prosecution of key executives.
- **Recovery actions:** Ongoing federal audit of all agencies utilizing Oxygen Forensics software to assess potential backdoors.
## Lessons Learned
- **Due Diligence Gaps:** Standard procurement background checks failed to identify the Russian citizens controlling the Cyprus holding company.
- **Software Origin Verification:** Trusting "self-certified" claims of software origin (Made in USA) poses a critical national security risk.
- **Dual-Use Risk:** Forensic tools sold to Western democracies can be simultaneously utilized by authoritarian regimes if the vendor has split loyalties.
## Recommendations
- **Beneficial Ownership Transparency:** Require exhaustive disclosure of all stakeholders for software vendors serving federal agencies.
- **Code Audits:** Mandate independent source code reviews for forensic tools to ensure no "phone-home" capabilities to foreign servers.
- **Supply Chain Vetting:** Implement stricter verification of the physical location of software development teams, not just the company's headquarters location.