The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

In December 2024, the U.S. Department of Justice arrested two leaders of Oxygen Forensics, a phone-hacking company that allegedly concealed its Russian ownership to secure over $2 million in contracts with U.S. government agencies including the Secret Service, Department of Homeland Security, and Department of Defense. CEO Lee Reiber and Russian national Oleg Davydov face conspiracy charges for wire fraud after prosecutors revealed that five Russian shareholders, including those with ties to the FSB, maintained actual control of the company despite sanctions imposed following Russia's invasion of Ukraine in 2022.

This case highlights the growing sophistication of supply chain deception tactics and the critical need for enhanced vendor vetting processes as nation-state actors increasingly exploit commercial relationships to penetrate sensitive government operations and critical infrastructure.

Why This Matters Now

This incident exposes critical vulnerabilities in government procurement processes as geopolitical tensions escalate and supply chain attacks become a primary vector for nation-state espionage, demanding immediate strengthening of vendor verification and ongoing monitoring capabilities.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The company installed Lee Reiber as CEO in 2022 after sanctions, removed Russian owners from public filings, and repeatedly asserted U.S. ownership to procurement officials while Russian shareholders maintained actual control.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have constrained this supply chain compromise by limiting forensics software network access and reducing the scope of data exfiltration through segmented cloud workloads. The attack's lateral movement across government agencies would likely have been restricted through east-west traffic controls.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Zero trust fabric controls would likely have limited the forensics software's network connectivity and reduced its ability to establish unauthorized communications with external systems beyond defined policy boundaries.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Microsegmentation policies would likely have constrained the forensics software's ability to access sensitive investigative databases and limited privilege escalation by restricting workload-to-workload communications based on identity verification.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic controls would likely have limited the forensics software's ability to move between agency systems and constrained its reach across different government cloud environments through inter-workload communication restrictions.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Centralized visibility controls would likely have detected unusual communication patterns from forensics software and constrained unauthorized command channels by monitoring traffic flows across government cloud deployments.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress controls would likely have constrained large-scale data transfers from forensics systems and limited the software's ability to exfiltrate sensitive investigative data through unauthorized outbound connections.

Impact (Mitigations)

Even with network and data access constraints, the fundamental supply chain compromise would likely have maintained some residual risk to ongoing investigations and evidence integrity within the reduced blast radius.

Impact at a Glance

Affected Business Functions

  • Digital Forensics and Investigation Services
  • Law Enforcement Technology Procurement
  • National Security Operations
  • Cybersecurity Training Programs
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: $2,000,000

Data Exposure

Potential compromise of sensitive law enforcement investigation data and forensic evidence processed through Oxygen Forensics software used by U.S. Secret Service, DHS Investigations, DOD, and other federal agencies. Risk of unauthorized access to forensic data by Russian-controlled entity with ties to FSB intelligence services.

Recommended Actions

  • • Implement Zero Trust Segmentation for all vendor software deployments to prevent unauthorized lateral movement across government systems and agencies
  • • Deploy Egress Security & Policy Enforcement to monitor and control all outbound data flows from forensics tools and prevent unauthorized exfiltration of sensitive investigative data
  • • Establish Multicloud Visibility & Control to detect anomalous interactions between vendor software and government systems, including suspicious automation patterns
  • • Implement Encrypted Traffic (HPE) protection to secure all data in transit from forensics operations and prevent interception by unauthorized parties
  • • Deploy Cloud Native Security Fabric (CNSF) with real-time inspection capabilities to autonomously detect and block supply chain compromise attempts and hidden ownership deception

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image