U.S. Federal Agencies Targeted: Russian-Controlled Forensics Vendor’s Covert Operations Unveiled

10

U.S. Federal Agencies Duped by Russian-Controlled Forensics Vendor in Software Supply Chain Fraud

Federal prosecutors have charged two executives at a Virginia-based digital forensics company with conspiracy to commit wire fraud after allegedly concealing Russian ownership and development of software sold to multiple U.S. government agencies.

The arrests expose a chilling gap in how Washington vets the technology it trusts with its most sensitive investigative work. For security leaders across government and private industry, the case is less a cybersecurity incident than a procurement reckoning — one that raises uncomfortable questions about whether vendor paperwork is protection or theater. Cases like this one sit at the intersection of geopolitics and technology procurement, and they underscore why understanding the data security risks embedded in software supply chains has become a board-level concern rather than an IT department checkbox.

The Arrests, the Allegations, and What Was at Stake

On September 23, 2026, the U.S. Attorney's Office for the Central District of California announced the arrests of Lee Reiber, 55, — CEO of Alexandria, Virginia-based Oxygen Forensics Inc. — and Oleg Sergeyevich Davydov, 52, the company's Russian co-founder and chief technology officer. Reiber was arrested in Boise, Idaho and released on bond. Davydov was detained at London Heathrow Airport while attempting to board a flight to Istanbul; the U.S. intends to seek his extradition.

Prosecutors allege that Oxygen Forensics presented itself to federal buyers as an independent U.S.-based company. In reality, they say five Russian nationals — including Davydov — owned and controlled the company through a Cyprus-based holding company, while software development continued in Moscow under Davydov's direction.

Those same five individuals also owned a Russian company originally called Oxygen Software LLC, renamed MKO Systems LLC in September 2022. That Russian entity reportedly sold its tools domestically to customers including Russia's Federal Security Service (FSB), the Russian Investigative Committee, and the Russian Ministry of Internal Affairs.

Federal agencies named in the affidavit as affected U.S. customers include:

  • The Department of War
  • The U.S. Secret Service and its National Computer Forensics Institute
  • Homeland Security Investigations
  • The DHS Office of Inspector General

Crucially, prosecutors are careful to note the complaint does not allege that Oxygen's software contained malicious code or was used to access any customer's systems or data. Each defendant faces a statutory maximum of 20 years if convicted, and both are presumed innocent unless proven otherwise in court.

Why Digital Forensics Tools Represent an Elevated Risk Category

The sensitivity of this case is amplified by the nature of the product itself. Digital forensics software is not generic enterprise software — it is purpose-built to extract, analyze, and reconstruct data from seized devices, often in the context of criminal investigations. A compromised or adversary-controlled tool in this environment does not merely represent a licensing irregularity. It sits at the center of law enforcement workflows, with potential visibility into case evidence, investigative targets, and operational methodology. Even absent malicious code, the question of who controls the development environment is a question of who could theoretically shape what the tool sees, surfaces, or obscures.

A Timeline Engineered Around Sanctions

The alleged scheme tracks closely with the geopolitical calendar following Russia's 2022 invasion of Ukraine.

Weeks after expanded U.S. sanctions took effect in March 2022, Reiber was installed as CEO, president, and board chairman, while Russian owners disappeared from public corporate filings. Prosecutors say those owners continued making significant decisions regardless — setting Reiber's compensation, overruling him on payments, and holding signatory authority over company bank accounts.

In December 2022 and again in October 2023, Reiber certified to the government that Oxygen Forensics had no immediate or highest-level foreign owner. When a reporter asked about the company's Russian connection in November 2023, Reiber wrote to Davydov and two other owners that public reporting "could destroy this entire opportunity" — referencing a pending National Computer Forensics Institute contract — and that the "current existence of this company hangs in the balance."

By July 2024, prosecutors say one of the Russian owners had been appointed to the board under a Turkish identity. In September 2024, NCFI awarded Oxygen a five-year software contract with a reported $12 million ceiling. As recently as March 2026, Reiber told DHS personnel that no Russian was involved in developing the software and that no one in Russia had access to its build environment. According to the complaint, that statement was false.

The Build Server Sleight of Hand

The most technically instructive detail is what investigative journalist Kim Zetter described as a "build server sleight of hand." Davydov allegedly moved the company's software build infrastructure to U.S.-based cloud computers, allowing Reiber to tell customers the code was built in the United States — while development continued in Russia.

An attestation can prove a binary came out of a pipeline in a specific region. It says nothing about who authored the commits flowing into that pipeline, or who holds the admin credentials to the environment. This distinction is not a technicality. It is the precise gap the alleged scheme was engineered to exploit, and it is one that standard procurement workflows are poorly equipped to detect.

Beneficial Ownership as a Concealment Layer

The corporate structure alleged here — a U.S.-facing operating company, a Cyprus-based holding entity, and Russian ultimate beneficiaries — is a well-documented pattern in financial crime and sanctions evasion. What makes this case notable is its application to a government technology vendor operating in a cleared procurement environment. The structure did not need to defeat sophisticated financial intelligence analysis; it only needed to satisfy the self-certification fields on a procurement form. Effective information security risk management requires organizations to look beyond paperwork and interrogate the actual control structures behind the vendors they trust.

What Security and Procurement Leaders Must Do Now

The case echoes the 2024 Kaspersky ban — the first-ever prohibition issued by the Commerce Department's Bureau of Industry and Security under Executive Order 13873 — which specifically flagged white-labeling and third-party integration as risk multipliers, because users become less likely to know the true source of code. BIS is leading the Oxygen investigation alongside the Defense Criminal Investigative Service.

As The Register's Carly Page framed it, the government's allegation is that U.S. agencies were buying tools from the same Russian development operation supplying a fundamentally different set of government customers back home. The deception allegedly operated in plain sight for years, while procurement workflows treated self-certification as the end of due diligence rather than its starting point.

Immediate Steps for Affected Organizations

For security and procurement leaders, the case offers several actionable considerations.

Check your own environment. Oxygen's customer base extended beyond federal agencies into law enforcement and private digital forensics practices. With roughly 57 domains seized, licensing and update channels may now be disrupted, creating operational gaps that need immediate assessment.

Treat ownership attestations as claims, not conclusions. Beneficial ownership can be layered through holding companies across multiple jurisdictions — as allegedly happened here via Cyprus. A form that asks whether a foreign entity holds ownership is only as reliable as the honesty of the entity completing it. Independent verification, where achievable, is a more defensible posture.

Ask where code is written, not merely where it is built. Build attestations do not answer questions of developer location, repository administration, or who holds merge authority over production branches. Robust supply chain security practices demand scrutiny of the human layer behind the pipeline, not just the pipeline's geographic output.

The Broader Procurement Reckoning

This case is a reminder that supply chain risk lives not only in the code, but in who controls the people writing it — and whether anyone checks beyond the form that says "no foreign ownership." The Kaspersky precedent established that national-security concerns about software provenance can justify outright prohibition. The Oxygen case suggests the next frontier is not software with known malicious capability, but software whose ownership and development chain is itself the undisclosed risk.

For organizations that have not yet conducted a structured audit of their forensics and investigative tooling vendors, this case makes the argument that waiting for a criminal complaint to surface the problem is not a risk management strategy — it is an abdication of one.

In this case, prosecutors allege the most important answer in the procurement file was the one that was never true.

You might also like