/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Leaked docs show Cellebrite has sold tech that can let NYC police “unlock and extract data from all iOS and high-end Android devices” on their own since 2018

Previously, if law enforcement wanted to get into newer devices, they had to send the phones to one of Cellebrite's

OneZero Michael Hayes

Context & Ripple Effects

Cellebrite's law-enforcement business has been moving up the stack for years: the 2016 documents showed it working with police across 20 US states, and by early 2018 it was telling clients it could crack iOS 11 devices. What this leak adds is the distribution shift — NYC police didn't just buy a service, they bought the capability itself, running extractions in-house since 2018 instead of mailing phones to a Cellebrite lab.

The later arc confirms both the spread and the ceiling: FOIA records show agencies in over 11 states, including CA, FL, and NY, spent $4M+ over a decade on phone-cracking software and devices, while 2024 leaked docs show Apple eventually closed the gap, with Cellebrite unable to forcibly unlock iPhones on iOS 17.4 or newer. The in-house model also concentrates risk: a 2017 breach exposed 900GB of data from Cellebrite's own systems.

First-order effects

  • NYPD investigators can now unlock and extract data from iOS and high-end Android devices on their own, removing the turnaround time and per-phone cost of Cellebrite's send-away lab service.
  • Cellebrite's revenue model shifts from per-device forensic services to selling the tooling outright, deepening its entrenchment as the default vendor in US policing.

Second-order effects

  • Other large departments face pressure to buy the same in-house kits to keep pace, extending the multi-state, multi-million-dollar procurement pattern the FOIA spending records document.
  • Apple and Google's device hardening becomes the binding constraint on the business: once an OS version resists extraction, every deployed kit loses coverage until Cellebrite ships a workaround.

Third-order effects

  • Phone forensics is structurally splitting into an arms race between OS vendors' security updates and vendor-supplied extraction tools, with police capability determined by whichever side of that cycle they bought into.
  • Distributing unlock capability to thousands of in-house operators widens the attack surface for leaks and misuse — the Cellebrite breach and later misuse-related customer suspensions point to accountability becoming the industry's unresolved problem.

The trend: Mobile forensics is shifting from centralized lab services to in-house police toolkits, with Apple and Google's security hardening — not procurement budgets — setting the ceiling on what agencies can unlock.

Discussion

  • @kennwhite Kenn White on x
    “$200K covered s/w licensing & installation, training for select personnel, an agreed-upon # of phone cracks, [and] references ~$1M in add-ons [...] The DA's office must designate a “secure room” where the s/w is housed, which cannot contain any audiovisual recording devices.” ht…
  • @hshaban Hamza Shaban on x
    Documents obtained by OneZero reveal that Cellebrite has been selling a product that can “unlock and extract data from all iOS and high-end Android devices” to New York City law enforcement since 2018. https://onezero.medium.com/...
  • @willoremus Will Oremus on x
    Remember when the FBI demanded Apple open the San Bernardino shooter's iPhone, Apple said no, and the FBI hired a secretive Israeli form to crack it? That firm has been contracting w/ the Manhattan DA to crack iPhones for the past year. @ozm scoop: https://onezero.medium.com/...
  • @amdanquart Dan Quart on x
    Once again, the @ManhattanDA has proven he cannot be trusted to protect privacy rights. Purchasing the ability to unlock and extract data from cellphones raises grave concerns over abuses of power. We must resist attempts by law enforcement to expand the surveillance state. https…