Leaked docs show Cellebrite has sold tech that can let NYC police “unlock and extract data from all iOS and high-end Android devices” on their own since 2018
Previously, if law enforcement wanted to get into newer devices, they had to send the phones to one of Cellebrite's …
Context & Ripple Effects
Cellebrite's law-enforcement business has been moving up the stack for years: the 2016 documents showed it working with police across 20 US states, and by early 2018 it was telling clients it could crack iOS 11 devices. What this leak adds is the distribution shift — NYC police didn't just buy a service, they bought the capability itself, running extractions in-house since 2018 instead of mailing phones to a Cellebrite lab.
The later arc confirms both the spread and the ceiling: FOIA records show agencies in over 11 states, including CA, FL, and NY, spent $4M+ over a decade on phone-cracking software and devices, while 2024 leaked docs show Apple eventually closed the gap, with Cellebrite unable to forcibly unlock iPhones on iOS 17.4 or newer. The in-house model also concentrates risk: a 2017 breach exposed 900GB of data from Cellebrite's own systems.
First-order effects
- NYPD investigators can now unlock and extract data from iOS and high-end Android devices on their own, removing the turnaround time and per-phone cost of Cellebrite's send-away lab service.
- Cellebrite's revenue model shifts from per-device forensic services to selling the tooling outright, deepening its entrenchment as the default vendor in US policing.
Second-order effects
- Other large departments face pressure to buy the same in-house kits to keep pace, extending the multi-state, multi-million-dollar procurement pattern the FOIA spending records document.
- Apple and Google's device hardening becomes the binding constraint on the business: once an OS version resists extraction, every deployed kit loses coverage until Cellebrite ships a workaround.
Third-order effects
- Phone forensics is structurally splitting into an arms race between OS vendors' security updates and vendor-supplied extraction tools, with police capability determined by whichever side of that cycle they bought into.
- Distributing unlock capability to thousands of in-house operators widens the attack surface for leaks and misuse — the Cellebrite breach and later misuse-related customer suspensions point to accountability becoming the industry's unresolved problem.
The trend: Mobile forensics is shifting from centralized lab services to in-house police toolkits, with Apple and Google's security hardening — not procurement budgets — setting the ceiling on what agencies can unlock.