Imagine this: somewhere in Moscow in September 2025, a group of people in suits gathered. They were drinking coffee, flipping through presentations, and having a very serious discussion about how to hack into your phone (yes, the very phone of the person reading this right now). The conference was called Moscow Forensics Day—an annual gathering of digital forensic experts, attended by specialists from commercial companies and, importantly, from the Investigative Committee of Russia.
The organizers thought no one else was watching. But the Memorial Human Rights Center found the recording publicly available. Nearly ten hours of candid reports. The media have analyzed it. We’re summarizing for you what’s important to know right now.
Table of Contents
Top Story: No Breakthrough
Let’s start with the good news. Russian law enforcement agencies don’t have any magical device that can unlock any iPhone in a second. The myth of an all-powerful state that sees everything all the time is just that—a myth. But that doesn’t mean we can let our guard down. Because the methods discussed at the conference are real and are already being used.
Cellebrite isn't available to them—but they still have some old stock left
The world’s leading tool for hacking smartphones is the Israeli company Cellebrite. It was Cellebrite’s equipment that the FBI used to unlock the phone of the man who shot at Trump in just 40 minutes. Olga Tushkanova, head of a department at the Russian Investigative Committee’s Research Institute of Criminalistics, admitted outright at a conference that they cannot purchase the new versions—Cellebrite withdrew from the Russian market back in 2021.
But it’s too early to let our guard down: they still have their old equipment. And the FSB has already used it against an anti-war activist, the author of the Telegram channel “Protest MSU.” So this isn’t a complete victory—rather, it’s a temporary advantage.
Your face is the key. And they can use it.
Now that’s really unpleasant. In 2025, the Investigative Committee developed a new procedure for handling detainees’ phones. One of the procedures sounds mundane, but it’s a nightmare in practice: a forensic investigator can ask you to come over so they can hold your phone up to your face and unlock it using Face ID.
It's not hacking. It's just that your face is being used as a key—without your consent.
What to do: Switch to a digital passcode instead of biometrics. This is especially important if you’re heading to a protest, crossing the border, or simply feel that the situation might get out of hand. Refusing to disclose your passcode is your constitutional right, which even the Supreme Court of the Russian Federation has recognized as lawful.
Hashcat: One Tool for All
To crack encrypted archives, documents, and files, Russian experts almost without exception use the same program—hashcat. It is open-source, free, and highly effective: it cycles through millions of password combinations per second, leveraging the processing power of graphics cards.
It will crack a weak password in no time. “Cat2004” isn’t a password—it’s the obituary of your privacy.
What to do: Long passwords for archives (20 characters or more—that’s a whole other story), a password manager for everything else. And wherever possible, switch to passkeys. They weren’t mentioned at all at the conference because forensic experts don’t yet know how to handle them.

macOS isn't a fortress, but it's almost one
One of the speakers promised to “debunk the myth that Apple is impenetrable.” Spoiler: it didn’t really work out. Yes, in theory, you can extract a password hash from macOS system files and try to crack it using hashcat. But that requires root access. And if you have disk encryption (FileVault) enabled and a modern Mac with an Apple Silicon chip—the whole plan falls apart. The speaker admitted as much himself when he was pressed with questions.
Android 8 characters = 10,000 years of hacking
This isn't clickbait. An expert from ACELab candidly explained that modern Android devices use the scrypt algorithm, which requires so much RAM that even an eight-character password would take about ten thousand years to crack using a brute-force attack. No graphics card can handle that.
That’s why the main goal of law enforcement is not to break into your phone through technical means, but to force you to unlock it yourself. That’s why they resort to pressure, interrogations, and forced biometric data collection.
Whatever they find on the phone will be handed over to the investigator
If, after unlocking a phone, a forensic investigator discovers saved passwords for Gmail, iCloud, or Google Drive, they must not access those accounts themselves. Under the new rules, they are required to report this to the investigator, who will then decide what to do with this discovery.
That's not protecting your data. It's just shifting the responsibility onto someone else in uniform.
What to do: Don't store passwords in notes, text files, or email correspondence. A password manager isn't paranoia—it's basic security practice. Proton Pass, Bitwarden, 1Password—choose whichever one you like.
Belarus is about you, too
The conference emphasized that Belarusian and Russian law enforcement agencies are working closely together and exchanging methods and tools. What is used in Moscow today appears in Minsk tomorrow.
In a Nutshell: What to Do Right Now
- Replace Face ID with a passcode — especially before any potentially risky situation
- Install a password manager — Proton Pass, Bitwarden, 1Password
- Don't store passwords in notes or messaging apps
- Turn on encryption — It's turned on by default on the iPhone; on Android, check the settings
- Use long passwords for archives and important files
- Switch to passkeys where possible (Google, Apple ID)
- Remember: You are not required to disclose your password. That is your right—even under the Russian Constitution.
The government wants your data. But there are limits to what it can do. Knowing those limits means knowing how to protect yourself.
Take care of yourself and your phone.
This material was prepared based on an analysis of the recording of the Moscow Forensics Day 2025 conference, published by the publication "Medusa."
0 comments
Enter your email — we’ll send you a one-time code. No passwords or accounts.
Code sent to
If the email doesn't appear in your inbox within a few minutes, check your spam, junk, or promotions folder, as some email services may mistakenly place automated messages there