Citizen Lab Finds Evidence of Mobile Data Extraction from Detained Kenyan Activist
Citizen Lab has identified forensic evidence indicating the use of Cellebrite's mobile extraction technology on a Samsung Android phone. The device, belonging to detained Kenyan activist and politician Boniface Mwangi, was in police custody in July 2025.
Citizen Lab has identified forensic evidence indicating the use of Cellebrite's mobile extraction technology on a Samsung Android phone. The device, belonging to detained Kenyan activist and politician Boniface Mwangi, was in police custody in July 2025.
This case underscores the potential for high-powered forensic tools to access sensitive personal and political data during arrests and device seizures.
Mwangi, a notable dissenting voice in Kenya, plans to run for president in the 2027 elections. On July 19, 2025, officers from Kenya's Directorate of Criminal Investigations (DCI) arrested Mwangi at his residence. Authorities conducted raids at both his home and office in Nairobi, seizing multiple devices.
Following the arrest, Mwangi was presented before a special court dealing with terrorism and transnational crime and faced charges under a firearms law. Initially, authorities considered pursuing terrorism and money-laundering-related charges linked to protests in June 2025. The terror-related charges were subsequently dropped, and Mwangi was released on bail, though his criminal case remains active.
Citizen Lab has identified forensic evidence indicating the use of Cellebrite's mobile extraction technology on a Samsung Android phone.
The seized devices were returned to Mwangi on September 4, 2025. He observed that the password protection on his Samsung phone had been removed, despite not providing the password. Citizen Lab's examination of the returned devices revealed signs that Cellebrite was used during the period the phone was held by Kenyan police, specifically around July 20–21, 2025.
A technical indicator in the report identifies an application named com.client.appA , which Citizen Lab associates with Cellebrite's forensic extraction tools. Such tools facilitate the extensive extraction of device contents, including messages, private files, financial information, and stored passwords. Citizen Lab's analysis of other seized devices in the case is ongoing.
The incident contributes to a pattern where Cellebrite-linked capabilities are reportedly associated with alleged abuses by government clients. This raises questions regarding vendor human-rights due diligence and oversight in high-risk environments.
Based on reporting by GBHackers.



