Cellebrite Phone Extraction and the Serbia Abuse Case

What the evidence shows

Cellebrite sells tools that access, extract, and analyse data from phones. Amnesty International found forensic evidence that Serbian authorities used those tools against members of civil society. The evidence supports a documented Serbia case, not a claim that every Cellebrite customer uses the products unlawfully.

Extraction product
UFED
Caution
Cellebrite
Analysis product
Physical Analyzer
Caution
Cellebrite
Documented abuse case
Serbia
Warning
Amnesty

A phone can hold years of messages, photos, contacts, browser activity, account tokens, and location records. Cellebrite builds tools for investigators to collect and organise that data after they obtain a device or a separate data return.

The company describes UFED as a mobile forensic data extraction tool. Its current product page advertises full-file-system and physical extraction methods, access to protected data on supported Android and iOS devices, and techniques for devices in an after-first-unlock state. Its Physical Analyzer product ingests extractions, decodes application data, builds timelines, and exports reports.

Those descriptions matter because they come from the vendor. They establish the capability Cellebrite markets. They do not establish that every phone can be opened, that every extraction recovers the same data, or that possession of a device guarantees success.

What Amnesty Found in Serbia

Amnesty International's Security Lab published a detailed Serbia investigation in December 2024. The researchers interviewed people targeted by surveillance and examined devices from activists and journalists. They reported forensic traces showing use of Cellebrite products on devices held by Serbian authorities.

One case involved independent journalist Slaviša Milanov. Police took his Android phone during a stop. Amnesty reported that he did not provide the passcode and was not told that officers intended to search the device. Its analysis found traces showing that a Cellebrite product had been used to unlock it.

Amnesty also found NoviSpy, an Android spyware system, on examined devices. The report said Serbian police and the Security Information Agency used NoviSpy alongside Cellebrite tools against independent journalists, activists, peaceful protesters, and people working with civil society groups. In the documented cases, physical access and phone extraction could expose stored data and create a path for spyware installation.

This is stronger than a general allegation about surveillance vendors. It is a named investigation with interviews, device examinations, and published forensic findings. It still needs careful wording. Amnesty documented cases in Serbia. That does not prove identical use by every agency or in every country where Cellebrite products are sold.

Extraction Is Not Remote Interception

Cellebrite extraction and remote spyware are different threats. In a 2021 technical post, Signal described UFED as software that creates a device backup and Physical Analyzer as software that parses the extracted files. Signal stressed that the workflow begins with someone else physically holding the phone.

That distinction changes the risk model. Cellebrite's products do not need to break Signal's transport encryption to read Signal data that is already available on an unlocked endpoint. End-to-end encryption protects the route between devices. It does not erase readable records from the devices at either end.

Signal also demonstrated security flaws in the Cellebrite software it examined. The post showed that a specially formed file on a scanned phone could execute code on the forensic workstation. That finding challenged the integrity of the analysis software in 2021. It did not make phones immune to extraction, and it should not be treated as a current bypass.

Reduce What a Seized Phone Can Reveal

A strong passcode is useful, but no fixed passcode length guarantees safety against current forensic tools. Device model, operating-system version, lock state, and the extraction method all affect the result. Keep the operating system and sensitive apps current. Security updates close known flaws that forensic vendors may rely on.

Minimise the data carried into a higher-risk situation. A travel phone should not contain a complete message archive, password vault, cloud session, identity file, and financial access unless each item is needed. Removing an app shortly before travel may leave recoverable records or synced copies elsewhere. Build the device with less data from the start.

Powering a phone down before a predictable seizure or border inspection can return it to a before-first-unlock state. That may restrict some extraction methods. It is not a guarantee. Avoid presenting biometrics at a checkpoint when the local legal and operational risk makes compelled unlocking a concern. Rules and consequences differ by jurisdiction.

Compartmentation limits damage when extraction works. Separate public communications from sensitive contacts. Keep long-term archives off the device used at protests, crossings, or meetings where seizure is plausible. Make account recovery independent of that phone so losing it does not also remove access to every account. The legal authority to compel access is separate from the extraction product; reported police use and the statutory position are compared in Cellebrite in Australia: NSW and Victoria phone-access powers.

Sources

Frequently Asked Questions

What does Cellebrite UFED do?

Cellebrite says UFED accesses and collects data from mobile devices. Its product page describes full-file-system and physical extraction methods, including access to protected and encrypted data on supported devices.

What is Cellebrite Physical Analyzer?

Physical Analyzer ingests phone extractions and other records, decodes application data, builds timelines, and produces reports.

Was Cellebrite used against journalists and activists in Serbia?

Amnesty International reported forensic evidence that Serbian authorities used Cellebrite tools on devices belonging to an independent journalist, activists, and peaceful protesters. Amnesty also found NoviSpy spyware on some examined devices.

Does Signal encryption stop phone extraction?

Signal protects messages in transit. It cannot protect readable data on an unlocked endpoint from someone who has physical possession of that device. Whether extraction succeeds depends on the device, operating system, lock state, and available technique.