For years, the U.S. government asked one of its digital forensics vendors a simple question: Who owns you, and where is your code written? According to federal prosecutors, the answers it got back were false—and the software it bought was being developed in Moscow by the same operation that sold its tools to Russia's Federal Security Service (FSB).
On September 23, the U.S. Attorney's Office for the Central District of California announced the arrests of Lee Reiber, CEO of Alexandria, Virginia-based Oxygen Forensics Inc., and Oleg Sergeyevich Davydov, the company's Russian co-founder and chief technology officer. Both are charged with conspiracy to commit wire fraud. Reiber, 55, of Boise, was arrested in Idaho and released on bond; Davydov, 52, of Moscow, was detained at London Heathrow Airport before boarding a flight to Istanbul, and the U.S. intends to seek his extradition.
The case is not, prosecutors are careful to say, a malware story. The complaint does not allege that Oxygen's software contained malicious code or was used to access any customer's systems or data. It is something arguably more uncomfortable for security leaders: a story about how easily the paperwork that underpins vendor trust can be gamed.
According to the affidavit filed with the complaint, Oxygen Forensics presented itself to federal buyers as an independent, U.S.-based company. In reality, prosecutors say, five Russian nationals, including Davydov, owned and controlled it through a Cyprus-based holding company.
Those same five individuals also owned a Russian company, known as Oxygen Software LLC until September 2022 and now called MKO Systems LLC, which Davydov co-founded in 2000. The developers who wrote the software worked in Russia. MKO sold the software domestically under different product names to customers that reportedly included the FSB, the Russian Investigative Committee, and the Russian Ministry of Internal Affairs.
The affected U.S. customers named in the affidavit are the Department of War and three components of the Department of Homeland Security: the U.S. Secret Service and its National Computer Forensics Institute (NCFI), Homeland Security Investigations, and the DHS Office of Inspector General. Oxygen's own website—inaccessible since earlier this week—had also listed the IRS, U.S. Army, and Justice Department among its federal customers, according to reporting by Kim Zetter at Zero Day.
The alleged scheme maps neatly onto the geopolitical calendar.
2013–2015: Davydov helps establish Oxygen Forensics in Virginia. Reiber joins in August 2015.
March 2022: Weeks after Russia's invasion of Ukraine and the expanded U.S. sanctions that followed, Reiber is installed as CEO, president, and board chairman. The Russian owners disappear from public corporate filings. Prosecutors say they continued to make significant decisions anyway—setting Reiber's compensation, overruling him on payments, and holding signatory authority over the company's bank accounts.
September 2022: The Russian parent drops the "Oxygen" name and becomes MKO Systems. Zetter reports the rename was intended to put distance between the Russian entity and its U.S. counterpart.
December 2022 and October 2023: Reiber certifies to the government that Oxygen Forensics has no immediate or highest-level owner.
November 2023: A reporter asks Reiber about the company's ownership and Russian connection. He then writes to Davydov and two other owners that public reporting "could destroy this entire opportunity"—a reference to a pending NCFI contract—and that the "current existence of this company hangs in the balance."
July 2024: At Reiber's direction, Oxygen certifies to the Department of War that no foreign person can control the appointment of its directors or direct its decisions. By then, prosecutors say, one of the Russian owners had recently been appointed to the board under a Turkish identity.
September 2024: NCFI awards Oxygen a five-year software contract, which Courthouse News Service reports carried a $12 million ceiling. The award file included Reiber's October 2023 no-owner certification.
March 2026: Reiber tells DHS personnel that no Russian was involved in developing the software and that no one in Russia had access to its build environment. Days later, he publishes a statement on the company website declaring no development presence in any restricted jurisdiction. According to the complaint, the software was written and managed by a team in Russia under Davydov's direction, in a cloud environment administered by one of the Russian owners.
September 19–20, 2026: A federal magistrate judge authorizes seizure of corporate bank accounts, roughly 57 domains, and other infrastructure. Agents execute the seizures the next day.
The most instructive detail for practitioners is a technical one. Zetter reports that Davydov moved the company's software build infrastructure to U.S.-based cloud computers, allowing Reiber to tell customers the code was built in the United States while development continued in Russia.
That distinction deserves a moment. "Where is it built?" and "Who writes it?" are different questions, and much of the modern software provenance conversation—signed builds, reproducible pipelines, build attestations—is focused on the first. An attestation can faithfully prove that a binary came out of a particular pipeline in a particular region. It says nothing about who authored the commits flowing into that pipeline, or who holds the admin credentials to the environment. If the complaint's account holds up, Oxygen's build location was effectively a compliance artifact, engineered to produce a true-sounding answer to the wrong question.
Here is the part that should sting. Oxygen's Russian roots were not hidden in the industry. Zetter, who covers the digital forensics space, notes that its Russian ownership had long been known and that she referenced it in a piece for The Intercept back in 2016. The digital forensics market is small—Zetter lists Cellebrite, Magnet Forensics, Susteen, Paraben, BlackBag Technologies, and Oxygen among its handful of players—and practitioners talk.
Yet, per the complaint, federal contracting decisions rested on self-certifications. The NCFI award file contained the very certification prosecutors now call false. That is not a failure of any one contracting officer so much as a structural gap: procurement workflows that treat a vendor's attestation as the end of due diligence rather than the start.
Digital forensics software exists to recover, preserve, and analyze data from seized devices without altering the originals. That puts it in an unusually sensitive position. It sits inside investigative workflows, handles evidence from criminal and counterintelligence cases, and is operated by exactly the agencies a foreign intelligence service would most like to understand.
To be clear, prosecutors have alleged none of the following. But the questions a security leader should ask are obvious: What did the vendor learn about its customers through licensing, support tickets, update channels, or telemetry? Which agencies were buying which capabilities, and for which device types? Could a vendor controlled from a jurisdiction subject to FSB influence have been compelled to share any of that? And, from a legal standpoint, will defense attorneys in cases that relied on Oxygen-processed evidence now probe the tool's provenance and integrity? None of these require malicious code to matter.
As The Register's Carly Page put it, the government's allegation is that U.S. agencies were buying tools from the same Russian development operation that was supplying very different government customers back home.
The investigating agency is telling. The Commerce Department's Bureau of Industry and Security (BIS) is leading the probe, assisted by the Department of War OIG's Defense Criminal Investigative Service. BIS is the same bureau whose Office of Information and Communications Technology and Services issued its first-ever prohibition under Executive Order 13873 in June 2024—banning Kaspersky from selling antivirus and cybersecurity products to U.S. persons, with a wind-down deadline of September 29, 2024.
That determination, as summarized by Covington & Burling, singled out white-labeling and third-party integration as risk multipliers precisely because users become less likely to know the true source of the code. Oxygen, as alleged, is that concern in a different costume: not a rebranded product but a rebranded company.
Check your own estate. Oxygen's customer base extended beyond federal agencies into law enforcement and, likely, private DFIR practices, law firms, and corporate investigations teams. Inventory where Oxygen tools are deployed and what data they've touched. With roughly 57 domains seized, also assess whether licensing, activation, or updates are now disrupted.
Treat ownership attestations as claims, not conclusions. Beneficial ownership can be layered through holding companies in third countries, as prosecutors say happened here via Cyprus. For high-sensitivity tools, verify independently: corporate registries in multiple jurisdictions, board composition, who holds bank signatory authority, and who sets executive compensation.
Ask where code is written, not just where it's built. Extend provenance questions to developer location, repository administration, and who controls cloud and CI/CD environments. Build attestations are necessary, but they don't answer authorship.
Watch for sanctions-era tells. A sudden leadership change, disappearing names in corporate filings, or a foreign affiliate renaming itself shortly after a sanctions escalation are signals worth a second look—not proof, but reason for further due diligence.
Listen to your practitioners. If something is common knowledge among the analysts who use a tool, it should be discoverable by the people who buy it. Build a channel for that knowledge to reach procurement and third-party risk teams.
A criminal complaint is only an allegation. Reiber and Davydov are presumed innocent, and prosecutors will have to prove their case in court, where each faces a statutory maximum of 20 years if convicted.
But whatever the outcome, the case exposes a lesson the security community keeps relearning: supply chain risk is not only about what's in the code; it's about who controls the people writing it—and whether anyone checks beyond the form that says "no foreign ownership." In this case, according to prosecutors, the most important answer in the procurement file was the one that wasn't true.