Hacker steals 900GB of data from Cellebrite, the Israeli company that makes products for breaking into mobile phones
This is part of an ongoing Motherboard series on the proliferation of phone cracking technology, the people behind it, and who is buying it. Follow along here.
Context & Ripple Effects
This breach lands three weeks after Motherboard's documents showing Cellebrite works with US law enforcement across 20 states to extract data from locked phones — coverage that established exactly why the company's servers are a high-value target: they hold both customer records and the technical machinery of phone cracking itself.
The story also fits a pattern inside Israel's surveillance sector: months later, an Israeli indictment alleged an employee stole NSO Group's hacking-tool source code to sell it, showing that insiders and intruders alike treat these firms' proprietary capabilities as loot.
First-order effects
- Cellebrite's law-enforcement customers — the agencies documented across 20 US states — now face exposure of their own forensic casework if the stolen 900GB includes client data, and the company must defend its security credentials while selling intrusion products.
- The theft puts Cellebrite's unlock techniques at risk of leaking, directly threatening the exclusivity that underpins its government contracts.
Second-order effects
- When parts of the stolen material surfaced weeks later as publicly released iOS cracking tools resembling jailbreaking software, capabilities once restricted to paying police agencies became available to anyone — collapsing the vendor's moat and widening who can break into phones.
- Rivals and buyers in the phone-forensics market now have to price in vendor compromise: an agency relying on Cellebrite inherits the breach risk of its supplier.
Third-order effects
- If the pattern holds alongside the NSO insider-theft case, the structural lesson is that companies stockpiling exploit capability become single points of failure — their vaults concentrate the very vulnerabilities that make everyone else's phones insecure.
- That dynamic pushes the industry toward scrutiny it did not face when it operated quietly: procurement decisions by police and governments will increasingly weigh a vendor's own security posture, not just its unlock success rate.
The trend: Phone-cracking vendors are becoming targets themselves, converting their stockpiled intrusion capabilities from market assets into systemic liabilities.