What happened
The US Department of Justice announced charges against two leaders of Oxygen Forensics, a maker of mobile forensics software used by law enforcement. Lee Reiber of Boise, Idaho, the company's CEO, was arrested in his home state. Oleg Davydov, described as one of five Russian nationals who controlled the company, was arrested in London, where the department plans to seek extradition. Both face charges of conspiracy to commit wire fraud.
According to the criminal complaint, the company presented Reiber publicly as its true leader and told US government customers it was American owned, while Russian officials at the company repeatedly overruled him. The complaint cites correspondence saying that fateful decisions would be made by five shareholders, including Davydov.
The timing matters. After the United States expanded sanctions against Russia following the 2022 invasion of Ukraine, the company installed Reiber as CEO and removed the owners from public corporate filings. From March 2022 onward, Oxygen sold its forensics software to the US Secret Service, Homeland Security Investigations, the DHS inspector general and the Department of Defense, winning more than USD 2 million in contracts and purchases from the Secret Service and its National Computer Forensics Institute. Reiber is alleged to have asserted US ownership as recently as February of this year.
The complaint states that procurement officials said they would not have awarded or renewed contracts for the software had they known the company was Russian owned. The DOJ also specified that the complaint does not allege the software contained malicious code or was used to gain unauthorised access to any customer's systems or data. Oxygen has previously faced accusations that its US and Russian entities sold the same software, developed by the same team, with Russian government customers.
Why this is a GRC story
Ownership is a due diligence fact, not a formality. The allegation here is not about a product defect. It is about a supplier control question that buyers did not verify, and that omission is exactly what procurement integrity and sanctions compliance exist to catch.
Sanctions exposure runs through the supply chain. A vendor can be incorporated locally, staffed locally and invoiced locally, and still be controlled from a sanctioned jurisdiction. Beneficial ownership checks, not entity names on a filing, are what answer that question.
Government buyers set the standard others copy. If contracts were awarded on an unverified ownership claim, the same gap most likely exists in commercial procurement. Third party risk programmes that rely on supplier self attestation alone are testing paperwork rather than control.
What to watch
Watch the extradition proceedings and whether the case prompts contract reviews at the agencies named, plus any knock on scrutiny for other forensics vendors with offshore ownership. Access Now has called on governments using the technology to review their ties to the company.
The practical takeaway: for any supplier with access to sensitive data or systems, be able to show how you confirmed who ultimately controls it, when you last checked, and how you would find out if that changed.
Attribution: Analysis based on CyberScoop and related public reporting. This article is original commentary, not a repost of the source material.
