The indictment started in a conference room that still had the vendor’s logo on the slide. Two executives at a digital forensics company that sold phone-extraction software to U.S. agencies were arrested this week, accused of covering up Russian ties and lying about where the technology is made. You buy tools like that because a case, a seizure, or a personnel investigation cannot wait. If you work cybersecurity, you also buy them because the brochure promised a clean chain of custody. The Department of Justice now says that chain had a factory you were never shown.

Your cybersecurity vendor just became chain of custody
Forensics platforms sit in a privileged corner of cyber security. They touch seized phones, employee laptops, cloud tokens, and the messy middle of an investigation where you have already decided the operator is trusted. A firewall never sees that decision. Your threat-protection stack never scores it. The purchase order did.
According to reporting from Recorded Future’s Record, the company sold several U.S. agencies its extraction software while its leaders allegedly hid the fact that the technology is made in Russia. That is a classification problem, an evidence problem, and a continuity problem at the same time. If a tool that images devices was built, staffed, or updated from a jurisdiction your contracts forbid, every case that used it now has a footnote you did not budget for.
You already know how this failure mode feels in smaller form. A contractor keeps a shared admin login. A VAR ships a support jumphost you never inventoried. A “U.S. company” turns out to mean a Delaware filing and a Slack channel that wakes up eight hours ahead of you. The DOJ case is that pattern with handcuffs. Origin is a control. Treat it like one, or you will explain in writing why you did not.
Hubris still answers the LinkedIn pitch
Cisco Talos spent this week on a quieter version of the same bet. Martin in the Threat Source newsletter walked through a social-media elicitation dressed up as a consultancy offer, then landed on a point the industry hates hearing: trust is the asset, and hubris is the hole. Someone wanted access to judgment, not a port. They asked nicely. They flattered. They implied you were the kind of expert who gets private work.
That pitch works because security people are trained to hunt packets and under-trained to hunt compliments. You will block a brute-force spray against VPN with a grin. You will still take a coffee meeting with a stranger who already knows your conference talks. Defense in depth dies at the moment you decide the person across the table is “one of us.”
Keep those two stories in the same folder. A federal buyer trusted a forensics brand. A practitioner was invited to trust a stranger with a plausible bio. Both failures start before exploit code. Both leave you doing incident response on relationships, which most playbooks still pretend is a legal problem for later.

Four ransom notes, one pair of hands
Microsoft’s threat detection write-up on Storm-2570 makes the labeling problem rude. The affiliate ran a consistent post-compromise kit across deployments tied to Qilin, DragonForce, Anubis, and BERT. The sticker on the extortion note changed. The tools after the foothold did not. If your hunting is organized by ransomware family, you are filing the same actor under four drawers and wondering why the dwell time looks familiar.
That is the twin of the Oxygen story. Marketing names are cheap. Tradecraft is expensive to change, whether you are an affiliate or a vendor with a factory you would rather not put on the bid. Stop asking “which brand hit us.” Ask “which hands, which tools, which update path.” You will catch more, and you will write fewer silly after-action reports.
Run an origin failure like a host compromise
Do this this week, not after counsel schedules a briefing. Pull every forensics, e-discovery, MDM, and “trusted investigative” product into one list with legal entity, manufacturing location, subprocessor list, update-server destinations, and remote-support path. If a cell is empty, the control is already failed. Empty is a finding.
Then lock the path the vendor actually uses. Restrict their callbacks on the firewall to named destinations. Put support accounts, jumphosts, and VPN identities under the same lockout and security hardening you already apply to staff. Brute-force against a vendor login is still brute-force. An ipban-style block on repeated failures belongs on that edge; if you already run something like IPBan Pro there, confirm the vendor’s source ranges sit in the same policy as everyone else, with no courtesy allowlist because “they’re the forensics people.”
If origin, ownership, or staffing comes into dispute, open an incident. Rotate every credential that product could have seen. Revoke persistent remote access. Quarantine update channels until you can prove the bits. Preserve the installer, the license server logs, and the case list that used the tool. That is incident response for a supply-integrity event, and it is slower if you wait for a press release to tell you the factory address.
Keep it going after the news cycle. Make manufacturing location and personnel-access rights a renewal gate, not a slide in the original RFP. Re-check parent companies when funding rounds land. Hunt affiliates by tool reuse, the way Microsoft did with Storm-2570, instead of by the name on the note. Your threat-protection catalog should track hands. Your procurement file should track factories. Those are the same discipline with different stationery.
Sources
- Digital forensics firm with US federal contracts covered up ties to Russia, DOJ alleges
- Trust and the enticing consultancy offer
- Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
