A security breach occurred at Cellebrite, a company that provides digital forensics tools to law enforcement agencies worldwide. Reports indicate that a hacker has gained access to Cellebrite’s systems and has leaked the company’s software, along with a significant amount of sensitive customer data, online.
Cellebrite is a well-known provider of digital forensics tools, which law enforcement agencies and other organizations use to extract data from mobile devices and other digital devices. Police and other agencies widely use the company’s tools to investigate crimes, including terrorism, drug trafficking, and human trafficking.
The hacker, who goes by the name “Hash_Brazil”, claimed to have stolen 900GB of data from Cellebrite, including the company’s software, customer data, and other proprietary information. The stolen data was then leaked online on a popular hacking forum. The hacker also stated they had access to Cellebrite’s internal systems for at least two months.
Reading an older article? Use the brief to stay current.
This Article Is Background. The Brief Keeps You Current.
This article is a useful reference. The brief covers the CISA actions, regulations, guidance, and risk shifts that changed the practical picture after it was published.
Free. Weekday mornings. 5 minutes or less.
Built from 100+ trusted cybersecurity sources.
The company has confirmed that the data breach did occur but stated that the extent of the damage is still under investigation. Cellebrite also stated that it is taking the necessary steps to secure its systems and protect its customers’ data.
Cellebrite’s products have been used to access data from mobile devices. In the past, the company’s tools have been used to extract data from the phones of suspects in high-profile criminal cases, including the investigation into the terrorist attacks in Paris in 2015.
The data breach at Cellebrite highlights the importance of companies securing their systems and protecting their customers’ data. It also raises concerns about the security of the data that is being extracted by law enforcement agencies using Cellebrite’s tools. As the use of digital forensics tools in criminal investigations becomes more widespread, it’s crucial for companies to ensure that their products are secure and that their customers’ data is protected.
Reading an older article? Use the brief to stay current.
What Changed Since This Was Published, in 5 Minutes or Less
Get the weekday brief that covers the new developments, policy shifts, and risk signals this article could not.
Free. Weekday mornings. 5 minutes or less.
Built from 100+ trusted cybersecurity sources.
In addition, this incident also shows the power of hackers and the potential impact of a cyber-attack on a company which is providing security services. It also serves as a reminder for companies to stay vigilant and have proper security measures in place to detect and respond to potential breaches.
Overall, this data breach at Cellebrite is a reminder of the ongoing need for companies to prioritize cybersecurity, especially when dealing with sensitive data, and the importance of organizations to have incident response plan in place to mitigate the damage and secure data in the event of a breach.
Newer CyberExperts coverage on this topic
This article still works as background. If you want the current picture, start with the freshest related coverage below and today's brief.
E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands
This campaign is worth attention because it moves dead-drop logic into an FTP welcome banner, which is unusual enough to break some...
The safety penalty: Reclaiming operational sovereignty in the age of AI
Cisco Talos is making a strategic point that security leaders should not dismiss as thought-leadership filler. If defensive workflows depend on cloud...
AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes
AnonyMousKIT is more than another phishing-kit story because it connects stolen-device monetization to identity abuse. The useful operator detail is how the...
The 5-Minute Cyber Brief: August 26, 2026
The fastest way to catch up on what changed after this article was published.