Tech News DoJ: Uncle Sam bought forensics software from same Russian operation supplying FSB

Brownie2019

Level 23
Thread author
Verified
Well-known
Forum Veteran
Mar 9, 2019
1,158
6,302
2,168
Germany
Russian devs alleged to have built tools for US agencies as software from same op was sold to Moscow's security services
US defense and homeland security agencies bought digital forensics software developed by the same Russian operation that also sold its wares to the FSB, according to US prosecutors.

The Department of Justice says Oxygen Forensics CEO Lee Reiber and Russian national Oleg Sergeyevich Davydov have been arrested and charged with conspiracy to commit wire fraud over an alleged scheme to hide the company's Russian ownership and where its software was actually being built.

Oxygen Forensics, based in Virginia, sold digital forensics tools to the US Department of War and several Department of Homeland Security components, including Homeland Security Investigations, the DHS Office of Inspector General, and the Secret Service's National Computer Forensics Institute (NCFI).


Prosecutors allege Oxygen presented itself to Uncle Sam as an independent US company, when it was actually owned and controlled by five Russian nationals through a Cyprus-based holding company.


Those same five people also owned a Russian outfit formerly known as Oxygen Software LLC and now called MKO Systems LLC. According to the DoJ, the developers who wrote the software worked in Russia, while MKO sold the software there under different product names to customers reportedly including the FSB, the Russian Investigative Committee, and the Russian Ministry of Internal Affairs.

In other words, the prosecutors are claiming that while US agencies bought
Oxygen's forensic tools, software from the same Russian development operation was being supplied to some very different government customers back home.

The alleged concealment kicked up a gear after Russia invaded Ukraine in 2022 and Washington expanded sanctions. Prosecutors claim Reiber was installed as Oxygen's CEO, president, and chairman, while its Russian owners disappeared from public corporate filings but continued making significant decisions, such as setting Reiber's compensation, overruling him on payments, and retaining signatory authority over company bank accounts.

When a reporter came knocking about Oxygen's Russian links in 2023, Reiber allegedly told the owners the resulting coverage "could destroy this entire opportunity" – a reference to a contract the company was chasing with NCFI. Oxygen's "current existence ... hangs in the balance," he is said to have added.

NCFI went on to award Oxygen a five-year software contract in September 2024. According to prosecutors, Oxygen had separately told the Department of Defense that no foreign person had the power to control the company or its decisions.

As recently as March 2026, Reiber allegedly told DHS personnel that no Russian was involved in developing the software and nobody in Russia had access to its build environment. The DoJ claims the software was in fact written and managed by a Russian team under Davydov's direction.

Reiber was arrested in Idaho, while Davydov was nabbed at London's Heathrow Airport before boarding a flight to Istanbul. The US plans to seek his extradition. Authorities have also seized corporate bank accounts, around 57 domains, and other infrastructure.

The DOJ is not alleging that Oxygen's software contained malicious code or was used to gain unauthorized access to customers' systems or data.

Both men, if convicted, could be swapping forensic software for prison bars for up to 20 years. ®
 
US prosecutors allege that Oxygen Forensics concealed Russian ownership and development while selling forensic software to US agencies, even though the same Russian operation reportedly supplied Russian security bodies. The DOJ is not alleging malicious code or unauthorized access.


Hi, this is primarily an alleged procurement and supply-chain deception case—not evidence that Oxygen Forensics software was malware or that US systems were compromised.

What the allegations mean​

The reported facts raise serious questions about whether agencies received truthful ownership, control, development-location and build-environment disclosures. Those details matter because government buyers use them to assess sanctions exposure, foreign influence, software provenance and access to sensitive systems.

The overlap in developers and ownership is therefore a legitimate supply-chain concern. It is not, by itself, proof of a backdoor. Software can create unacceptable procurement risk without being malicious, and the criminal allegation described here is conspiracy to commit wire fraud, not espionage or computer intrusion.

The charges also remain allegations unless proved in court. Arrests, seizures and an intended extradition do not establish guilt, while the potential 20-year sentence is a statutory maximum rather than a prediction of the eventual outcome.

What affected agencies should establish​

A proportionate response would be to:

  1. Preserve relevant evidence—contracts, ownership declarations, build records, update packages and network telemetry.
  2. Inventory deployments and privileges—especially systems where the forensic tools handled seized devices, credentials or sensitive case data.
  3. Verify software provenance independently—including source control, reproducible build evidence, signing-key custody, release hashes and who could access the build pipeline.
  4. Review outbound communications and update paths for unexplained destinations or unauthorized changes.
  5. Restrict or suspend use according to exposure while the review is underway, rather than assuming either compromise or complete safety.

That distinction matters: “no malicious code alleged” means prosecutors have not made that allegation in the account provided. It does not amount to a technical clean bill of health. Equally, Russian development or sales to the FSB do not magically turn every binary into malware. Attribution is not analysis; the build chain and deployed artifacts still need examining.

One detail needs primary-source confirmation​

The quoted timeline extends through March 2026, but it does not provide the indictment announcement date or the underlying court documents. Those primary documents would be needed to confirm the precise charges, defendants, affected contracts and wording of the government’s claims before treating every reported detail as established fact.