The Oxygen Forensics case: hidden Russian ownership, no alleged hidden code
The charge is narrow. The DOJ's release says the defendants are charged with conspiracy to commit wire fraud. According to the DOJ, Reiber told the federal government that the company had no foreign ownership or control and that its software was developed in the U.S. — when in fact five Russian nationals, including Davydov, owned and controlled the company and its software was developed in Russia.
The DOJ's limit on the case is as important as the charge itself. The complaint does not allege that the software was malicious or was used to gain unauthorized access to any systems or data. Several outlets carried the DOJ's announcement, including The Register, Courthouse News Service, Radio Free Europe/Radio Liberty and Patch. Most of these accounts come straight from the DOJ release, so they confirm that the charges were announced. They do not independently confirm the facts behind them.
One outlet describes the court filing differently. RFE/RL called it an indictment released on September 23. The DOJ release and other reports call it a criminal complaint. A criminal complaint is an allegation, not a conviction. A complaint usually comes before any grand-jury indictment, so this article follows the DOJ's own wording.
The DOJ describes digital-forensics software as tools that recover, preserve and analyze data from devices while leaving the original files unchanged. Investigators and auditors rely on these tools to pull evidence from phones and computers. That puts the vendor in an unusually trusted position: its software handles seized devices and sensitive case material inside government networks.
How Oxygen Forensics and MKO Systems allegedly shared five Russian owners
Prosecutors say the company presented an American face over a Russian ownership structure. The DOJ says Oxygen Forensics, established by Davydov in 2013, presented itself as being owned by Reiber, an American, when, in fact, it was owned and controlled by Davydov and four other Russian nationals through a holding company in Cyprus.
The same five people also owned a company in Russia. That company, co-founded by Davydov in 2000, was called Oxygen Software LLC until 2022, when it was renamed MKO Systems LLC. Davydov was the Russian company's chief technology officer and was responsible for the development of its software. Reiber joined the company in August 2015.
The link to the FSB, Russia's Federal Security Service, runs through MKO. Oxygen Software/MKO sold software developed in Russia to a variety of Russian customers, including the Russian Federal Security Service, the Russian Investigative Committee and the Russian Ministry of Internal Affairs, according to the DOJ release. The Register adds that the DOJ says MKO sold the software in Russia under different product names.
The DOJ has not said that American and Russian agencies received the same builds or configurations. What it alleges is one shared set of owners and one Russian development team serving both markets. In The Register's words, while US agencies bought Oxygen's tools, software from the same Russian development operation was going to very different government customers in Russia.
From the 2022 sanctions to March 2026: the certifications prosecutors call false
According to the complaint, the concealment began after Russia invaded Ukraine. After the United States imposed expanded sanctions on Russia in early 2022 in response to Russia's invasion of Ukraine, Davydov, Reiber, and the Russian co-conspirators agreed to conceal Oxygen Forensics' true ownership and the development of its software in Russia. Reiber was installed as the company's CEO, president, and chairman of the board in March 2022. The Russian owners were then removed from the company's public corporate filings.
Prosecutors say the Russian owners kept running the company after their names came off the filings. They allegedly set Reiber's pay, overruled him on payments and kept signing authority over the company's bank accounts. In practice, this is what separates real control from a nominee: anyone looking at the public registry would have seen an American-run company.
The DOJ's allegations, in order:
| Date | Alleged event |
|---|---|
| March 2022 | Reiber becomes CEO, president and chairman; the Russian owners disappear from public filings. |
| December 2022 and October 2023 | Reiber falsely certified to the U.S. government that Oxygen Forensics had no immediate or highest-level owner. |
| November 2023 | A reporter asks Reiber about the company's ownership and its Russian links; Reiber allegedly warns the owners. |
| July 2024 | At Reiber's direction, Oxygen Forensics certified to the Department of War that no foreign person had the power to control the appointment of the company's directors or managers or direct its other decisions. |
| September 2024 | NCFI awards Oxygen a five-year software contract. |
| March 2026 | Reiber allegedly tells DHS staff that no Russian works on the software and nobody in Russia can reach its build environment. |
The DOJ also says that by the time of the July 2024 certification, one of the Russian owners had recently joined the board under a Turkish identity. The March 2026 statement is the one most relevant to security engineers. It was not about ownership but about who could reach the build environment, the systems where source code is compiled into the software customers install. Prosecutors say the software was actually written and managed by a Russian team under Davydov, in a cloud environment run by one of the Russian owners.
The NCFI contract, and the reporter's question that allegedly alarmed Reiber
The clearest evidence of intent in the complaint comes from November 2023. According to the affidavit, a reporter asked Reiber about Oxygen Forensics' ownership and its connection to the Russian company. Reiber then wrote to Davydov and two other Russian owners that public reporting on the connection "could destroy this entire opportunity," referring to a pending contract with the National Computer Forensics Institute, and that the "current existence of this company hangs in the balance."
The National Computer Forensics Institute (NCFI) is part of the U.S. Secret Service. It got the contract anyway. In September 2024, the NCFI awarded a five-year contract for the software. The award file included Reiber's October 2023 certification that the company had no immediate or highest-level owner.
The allegation that the award file contained the disputed certification is central to the fraud theory. If the government relied on a false statement to award a federal contract, that is the kind of conduct wire-fraud charges are used for. It also means NCFI's due diligence depended, at least partly, on the vendor telling the truth about itself.
The named US customers go beyond NCFI. The alleged scheme affected the Department of War and three components of the Department of Homeland Security: the U.S. Secret Service and its National Computer Forensics Institute, Homeland Security Investigations and the DHS Office of Inspector General. The DOJ has not published contract values or the number of installations.
Arrests at Boise and Heathrow, 57 seized domains, and the road to arraignment
Both men were arrested on the same weekend. Lee Reiber, 55, of Boise, Idaho, was arrested in Idaho on Sunday, made his initial appearance on Tuesday in U.S. District Court in Idaho, and was ordered released on bond. He is expected to be arraigned in Los Angeles federal court in the coming weeks. Oleg Sergeyevich Davydov, 52, of Moscow, Russia, was arrested on Sunday at London Heathrow Airport in the United Kingdom prior to boarding a flight to Istanbul. The arrests were on September 20, 2026. The United States expects to seek Davydov's extradition.
In a separate proceeding, a federal magistrate judge in the Central District of California signed a seizure warrant on September 19. It covered corporate bank accounts and infrastructure, and the list covers approximately 57 domains, related infrastructure and corporate bank accounts. The DOJ has not published the domain names. It has also not said whether customer-facing services such as licensing or update servers were among them. Agencies and any private-sector customers still running Oxygen tools will need to know that. No outlet has reported what the seizure means for existing installations.
The Commerce Department's Bureau of Industry and Security is leading the investigation, with help from the Defense Criminal Investigative Service's Cyber Field Office, part of the Department of War Inspector General. The charge carries a maximum sentence of 20 years in prison. That is the legal maximum, not a likely sentence. As of RFE/RL's report, Reiber did not immediately respond to an e-mail seeking comment. Davydov could not be located for comment.
What this means for security teams that rely on forensic and security vendors
Organizations running Oxygen Forensics products should decide now how to treat the software, and not wait for a verdict. No government advisory has told anyone to remove it. The DOJ has also said plainly that it is not alleging malicious code. The question is one of trust: a customer that accepted the company's assurances about ownership and development location needs to decide whether those assurances still count for anything.
For everyone else, the practical lesson is about how vendor assurance works. Every alleged false statement in this case was a document that a buyer accepted: an ownership certification, a foreign-control declaration, a verbal promise about build-environment access and a statement on the company's website. None of these can be checked by scanning the software. Our inference is that code audits and malware scans would not have caught this. Checking ownership chains, beneficial owners and who actually administers the development infrastructure might have. The risk was in the paperwork.
Enterprise buyers are not bound by federal certification rules. Still, forensic and incident-response tools usually run with high privileges on sensitive evidence, and many vendor questionnaires ask the same questions this case turns on. The allegations show that one owner can be removed from public filings while keeping bank signing authority and the power to overrule the CEO. A vendor's public registry entry is a weak signal on its own.
- Oxygen Forensics customers should find out where the tools are installed, who has access to them and whether they depend on vendor-hosted services that may have been caught up in the September 20 seizure of about 57 domains.
- Procurement and security teams should treat a vendor's ownership and development-location statements as claims to verify, especially after a sanctions event or a sudden change of leadership, the pattern prosecutors describe here.
- Vendor questionnaires should ask who administers the build and cloud environments, not only where developers sit, because prosecutors say Oxygen's software was built in a cloud environment run by one of its Russian owners.
- Teams should not describe Oxygen's software as backdoored or compromised, because the DOJ says the complaint makes no such allegation.
- Anyone who depends on evidence processed with these tools should keep an eye on the Los Angeles arraignment and any agency guidance that follows, because contract decisions by the Secret Service, HSI and the Department of War will likely come before any trial.
The Oxygen Forensics case is a procurement-fraud prosecution, not a malware story. For IT and security buyers, that makes it harder to deal with. A clean code review would not have raised any flags, while an ownership structure that allegedly led from Alexandria through Cyprus to the developers behind the FSB's tools went unnoticed through certification after certification. The next concrete steps are Reiber's arraignment in Los Angeles and the extradition request for Davydov. Before either happens, every agency that signed an Oxygen contract has to decide whether a vendor accused of lying about who builds its software should stay in its evidence lab.