Executive Summary
In December 2024, the U.S. Department of Justice arrested two leaders of Oxygen Forensics, a phone-hacking company that allegedly concealed its Russian ownership to secure over $2 million in contracts with U.S. government agencies including the Secret Service, Department of Homeland Security, and Department of Defense. CEO Lee Reiber and Russian national Oleg Davydov face conspiracy charges for wire fraud after prosecutors revealed that five Russian shareholders, including those with ties to the FSB, maintained actual control of the company despite sanctions imposed following Russia's invasion of Ukraine in 2022.
This case highlights the growing sophistication of supply chain deception tactics and the critical need for enhanced vendor vetting processes as nation-state actors increasingly exploit commercial relationships to penetrate sensitive government operations and critical infrastructure.
Why This Matters Now
This incident exposes critical vulnerabilities in government procurement processes as geopolitical tensions escalate and supply chain attacks become a primary vector for nation-state espionage, demanding immediate strengthening of vendor verification and ongoing monitoring capabilities.
Attack Path Analysis
Russian-owned Oxygen Forensics engaged in a supply chain compromise by concealing foreign ownership to win U.S. government contracts, establishing persistent access to sensitive law enforcement operations through forensics software deployment. The company maintained command and control through dual management structures while potentially exfiltrating sensitive investigative data and digital evidence through their forensics tools, ultimately impacting national security and human rights investigations across multiple agencies.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Oxygen Forensics established initial compromise through supply chain deception by masking Russian ownership and installing a U.S. CEO facade to win contracts with DOD, DHS, Secret Service, and other agencies starting in March 2022.
MITRE ATT&CK® Techniques
Supply Chain Compromise: Compromise Software Supply Chain
Masquerading: Match Legitimate Name or Location
Acquire Infrastructure: Domains
Compromise Infrastructure: Domains
Data from Local System
Gather Victim Identity Information: Credentials
Trusted Relationship
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
CISA Zero Trust Maturity Model 2.0 – Supply Chain Risk Management
Control ID: ID.SC-5
NYDFS 23 NYCRR 500 – Third Party Service Provider Security Policy
Control ID: 500.11
Digital Operational Resilience Act (DORA) – ICT Third-Party Risk Management
Control ID: Article 28
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
PCI DSS 4.0 – Third Party Service Provider Monitoring
Control ID: 12.8.4
ISO 27001:2022 – Information Security Policy for Supplier Relationships
Control ID: A.15.1.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Direct supply chain compromise affecting DHS, DOD, Secret Service operations through Russian-owned forensics software concealing true ownership.
Law Enforcement
Critical exposure via compromised phone-hacking tools used by agencies, potentially enabling foreign intelligence access to sensitive investigations.
Computer/Network Security
Supply chain integrity undermined by Russian-controlled forensics vendor masquerading as US company, violating zero trust principles.
Defense/Space
National security breach through Defense Department contracts with foreign-controlled entity violating sanctions and procurement security requirements.
Sources
- Phone-hacking company that won U.S. security agency contracts hid Russian ownership, DOJ allegeshttps://cyberscoop.com/oxygen-forensics-ceo-arrested-russian-ownership-fraud/Verified
- Two Leaders of Russian-Owned Phone Hacking Company Arrested for Fraudulently Concealing Ownership to Win U.S. Government Contractshttps://www.justice.gov/opa/pr/two-leaders-russian-owned-phone-hacking-company-arrested-fraudulently-concealing-ownershipVerified
- Criminal Complaint USA v. Lee Reiber and Oleg Davydov - Eastern District of Virginiahttps://www.justice.gov/opa/media/1374971/dlVerified
- OFAC Sanctions Programs and Country Information - Russia-related Sanctionshttps://ofac.treasury.gov/country-summary/russiaVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have constrained this supply chain compromise by limiting forensics software network access and reducing the scope of data exfiltration through segmented cloud workloads. The attack's lateral movement across government agencies would likely have been restricted through east-west traffic controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Zero trust fabric controls would likely have limited the forensics software's network connectivity and reduced its ability to establish unauthorized communications with external systems beyond defined policy boundaries.
Control: Zero Trust Segmentation
Mitigation: Microsegmentation policies would likely have constrained the forensics software's ability to access sensitive investigative databases and limited privilege escalation by restricting workload-to-workload communications based on identity verification.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely have limited the forensics software's ability to move between agency systems and constrained its reach across different government cloud environments through inter-workload communication restrictions.
Control: Multicloud Visibility & Control
Mitigation: Centralized visibility controls would likely have detected unusual communication patterns from forensics software and constrained unauthorized command channels by monitoring traffic flows across government cloud deployments.
Control: Egress Security & Policy Enforcement
Mitigation: Egress controls would likely have constrained large-scale data transfers from forensics systems and limited the software's ability to exfiltrate sensitive investigative data through unauthorized outbound connections.
Even with network and data access constraints, the fundamental supply chain compromise would likely have maintained some residual risk to ongoing investigations and evidence integrity within the reduced blast radius.
Impact at a Glance
Affected Business Functions
- Digital Forensics and Investigation Services
- Law Enforcement Technology Procurement
- National Security Operations
- Cybersecurity Training Programs
Estimated downtime: N/A
Estimated loss: $2,000,000
Potential compromise of sensitive law enforcement investigation data and forensic evidence processed through Oxygen Forensics software used by U.S. Secret Service, DHS Investigations, DOD, and other federal agencies. Risk of unauthorized access to forensic data by Russian-controlled entity with ties to FSB intelligence services.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation for all vendor software deployments to prevent unauthorized lateral movement across government systems and agencies
- • Deploy Egress Security & Policy Enforcement to monitor and control all outbound data flows from forensics tools and prevent unauthorized exfiltration of sensitive investigative data
- • Establish Multicloud Visibility & Control to detect anomalous interactions between vendor software and government systems, including suspicious automation patterns
- • Implement Encrypted Traffic (HPE) protection to secure all data in transit from forensics operations and prevent interception by unauthorized parties
- • Deploy Cloud Native Security Fabric (CNSF) with real-time inspection capabilities to autonomously detect and block supply chain compromise attempts and hidden ownership deception



