Media reports on 28 September 2026, citing the US Department of Justice, said that Oxygen Forensics, a US-registered company specialising in digital forensics and data extraction from electronic devices, was effectively controlled by Russian citizens and that its software was developed in Russia.
The company’s products were reportedly supplied to law-enforcement bodies in the United States, Germany and other Western countries. They were also used in European Union-funded projects and sold to Russian security agencies, including the Federal Security Service (FSB), according to the reports.
US authorities allege that the company’s management concealed Russian control of the business and the location of its software development after sanctions were introduced in 2022. The Justice Department has separately said that the current allegations do not claim the software contained malicious code or that it enabled unauthorised access to clients’ systems.
The account describes the company’s links to developers operating under Russian jurisdiction as an information-security risk for Western law-enforcement agencies. It says such circumstances could create opportunities for pressure from Russian security services, sanctions evasion or the introduction of concealed functions. These possibilities are presented as risks, not as established findings.
Among the potential concerns identified are access to extracted data from mobile devices, including evidence, contact details, geolocation information and investigative methods. The source material also raises the possibility that access to software algorithms, system logs, server infrastructure or update mechanisms could expose investigative techniques or create a channel for future cyber interference.
It further suggests that compromised systems could affect the integrity of digital evidence and potentially expose sensitive information about judges, investigators and forensic experts. However, the supplied material does not provide evidence that such access, interception, manipulation of evidence or malicious use occurred.
The case may prompt a broader review of foreign software used by law-enforcement agencies and of supplier-screening procedures in NATO countries, according to the source material. The reports and allegations can be read in full at Deutsche Welle.