# DOJ Says a US Government Forensics Vendor Hid Russian Ownership for Years. What Reiber and Davydov Are Accused Of > Federal prosecutors arrested Oxygen Forensics CEO Lee Reiber and Russian national Oleg Davydov, alleging the Virginia-based digital-forensics vendor concealed Russian ownership and Russian-developed software while selling to the Secret Service, HSI, DHS OIG and other agencies. What the complaint alleges, what it explicitly does not, and what it means for vendor-risk programs everywhere. Source: https://playciso.com/blog/doj-oxygen-forensics-russian-ownership-arrests · Published: 2026-09-24 · Publisher: PlayCISO (https://playciso.com) Primary source: https://www.justice.gov/usao-cdca/pr/tech-ceo-russian-national-arrested-complaint-alleging-they-hid-russian-ownership-and --- On September 21, 2026, federal agents arrested Lee Reiber, the CEO of Virginia-based digital-forensics vendor Oxygen Forensics, at his home in Idaho. On the same day, agents arrested Oleg Sergeyevich Davydov — the Moscow-based businessman prosecutors say actually owns and controls the company — at London Heathrow Airport, before he could board a connecting flight to Istanbul. Both men are charged with conspiracy to commit wire fraud. The allegation at the center of the complaint: a company that sold mobile-forensics software to the U.S. Secret Service and other federal agencies for over a decade was not, as represented, an independent American business — it was owned by Russian nationals and its software kept being developed in Russia, through years of U.S. sanctions on Russia and U.S. government contracts that depended on knowing exactly the opposite. ## What the complaint alleges Oxygen Forensics was established in Virginia in 2013 by Davydov, who had run a Russian predecessor company — originally called Oxygen Software LLC, founded in 2000 — for over a decade before that. Reiber joined the U.S. entity in 2015 and became its public face as CEO. Prosecutors allege that despite that, Davydov and four other Russian nationals owned and controlled the company throughout, and that its software continued to be written and maintained by developers based in Russia. After the United States imposed expanded sanctions on Russia in early 2022 following the invasion of Ukraine, the complaint alleges Davydov, Reiber and their co-conspirators agreed to actively conceal the company's true ownership rather than disclose it. Reiber is alleged to have then falsely certified to the U.S. government — in December 2022 and again in October 2023 — that Oxygen Forensics had no immediate or highest-level owner. One investigator's statement cited in reporting on the complaint says Reiber knew as early as 2018 that the U.S. government had specific security concerns about Russian-developed software, which is part of what makes the alleged multi-year certifications notable: this wasn't reported as an oversight discovered later, but as a standing concern the complaint says he had already been made aware of. ## What DOJ does not allege — and why that distinction matters Read the complaint's own language carefully, because it draws a specific line: prosecutors explicitly state they are **not** alleging the software contained malicious code, or that it was used to gain unauthorized access to any customer's systems or data. The charge is about concealed ownership and false certifications — a fraud on the procurement and disclosure process, not (as charged) a technical compromise of the product itself. That distinction is worth sitting with rather than skipping past. It doesn't make the allegations less serious; it changes what kind of failure this is. A backdoor is a technical problem with a technical fix. A years-long, undetected misrepresentation about who actually owns and directs a vendor selling forensic tools to federal law enforcement is a governance and verification problem — and those don't get caught by the same controls that catch malware. ## Who the affected customers were Reporting on the complaint and related coverage name several federal customers: the U.S. Secret Service and its National Computer Forensics Institute (NCFI) — which reportedly awarded Oxygen Forensics a five-year, $12 million contract in September 2024 — Homeland Security Investigations, the DHS Office of Inspector General, and a unit referenced as the Department of War. Separate reporting puts total documented U.S. government spending on the company's products at more than $5.6 million since 2011, spread across the Department of Homeland Security (about $2.7 million), Treasury, and the Department of Justice itself. These are agencies whose core function depends on the integrity and independence of their forensic tooling — digital-forensics software extracts and handles evidence that ends up in criminal prosecutions, which is precisely the kind of use case where "who actually controls the vendor" isn't an abstract compliance question. ## The Russian-market side of the story Davydov's original company — Oxygen Software LLC, later renamed MKO-Systems LLC in 2022, the same year the sanctions pressure intensified — reportedly continued selling forensic software into the Russian market, including to Russian security services, according to multiple outlets covering the complaint and related reporting (the specific list of Russian government purchasers circulating in social coverage of this story, including named agencies, goes beyond what independent reporting has directly confirmed as of this writing — treat that specific enumeration as unverified). Separately, a February investigation identified an individual connected to Oxygen's operations, Eduard Benderskiy, whom British authorities have described as a former high-ranking FSB official. None of this is presented in the complaint as evidence the U.S.-deployed software itself was compromised — see the section above — but it is the backdrop prosecutors say made the ownership concealment worth actively hiding rather than simply disclosing. ## The infrastructure seizure Separately from the criminal charges, federal authorities seized approximately 57 domains, related cyberinfrastructure, and corporate bank accounts on September 20, under a warrant issued the day before. This is a civil/administrative seizure action running in parallel with the criminal complaint, not part of the wire-fraud charge itself — but it's the part of this story with the most direct operational consequence for anyone who had Oxygen Forensics infrastructure in their environment or update chain: seized domains stop resolving, and anything depending on them (license checks, update servers, telemetry endpoints) can break without warning. ## Where things stand Reiber made his initial appearance in U.S. District Court in Idaho and was released on bond. Davydov's path to a U.S. courtroom depends on extradition from the United Kingdom following his arrest at Heathrow. **These are allegations in a federal criminal complaint. Both defendants are presumed innocent unless and until proven guilty.** Nothing here should be read as a finding of fact by a court. ## The actual security lesson Set aside the specific defendants and treat this as a case study, because the mechanism is the reusable part. A federal vendor certified its ownership structure to the U.S. government twice, in writing, over a period of years, while allegedly being both foreign-owned and foreign-developed the entire time — and the misrepresentation held until a federal investigation surfaced it, not until a routine compliance review caught it. That is not a story about Russia specifically; it is a story about what "vendor risk assessment" actually means in practice at most organizations, government or not: a self-attested form, collected once at onboarding, rarely revisited, and trusted by default. Beneficial-ownership structures, corporate registrations, and where code actually gets written are all things that can and do change — sanctions events, acquisitions, and corporate restructurings all create exactly the kind of moment where a vendor's story about itself stops matching reality, and those moments are also exactly when self-certification is least likely to be voluntarily corrected. The practical takeaway for any security or procurement program, not just federal ones: ownership and development-location attestations need a re-verification trigger tied to real-world events — a sanctions regime change, a vendor's corporate name change, a shift in where support tickets or code commits actually originate — not just a renewal-cycle checkbox. A form a vendor fills out about itself is a starting point for diligence, not a substitute for it. [Start a vendor risk review — free →](/tools/vendor-risk) ## Frequently asked questions **What is Oxygen Forensics accused of?** Prosecutors allege that Oxygen Forensics, a Virginia-registered digital-forensics company that sells mobile-data-extraction software to U.S. government agencies, concealed that it was actually owned and controlled by Russian nationals — not by its American CEO, as represented — and that its software continued to be developed by engineers in Russia. CEO Lee Reiber allegedly certified to the U.S. government in December 2022 and again in October 2023 that the company had no immediate or highest-level owner, which prosecutors say was false. **Who are Lee Reiber and Oleg Davydov?** Lee Reiber, 55, of Boise, Idaho, is Oxygen Forensics' CEO; he joined the company in 2015 and was arrested in Idaho, then released on bond. Oleg Sergeyevich Davydov, 52, of Moscow, is described in the complaint as the company's real controlling owner; he originally founded a Russian predecessor company (Oxygen Software LLC, later renamed MKO-Systems LLC) in 2000 and helped establish the Virginia entity in 2013. He was arrested at London Heathrow Airport before a connecting flight and the U.S. is expected to seek his extradition. **Did DOJ allege the software was malicious or backdoored?** No. The complaint explicitly states it does not allege the software contained malicious code or was used to gain unauthorized access to any customer's computer systems or data. The charge is conspiracy to commit wire fraud over concealed ownership and origin — a misrepresentation to procurement and export-control processes, not an allegation of a technical compromise. **What government agencies used Oxygen Forensics software?** Named customers in reporting on the complaint include the U.S. Secret Service and its National Computer Forensics Institute (which reportedly awarded a five-year, $12 million contract in September 2024), Homeland Security Investigations, the DHS Office of Inspector General, and a unit referred to in the complaint as the Department of War. Other reporting puts total U.S. government spending on the company's products since 2011 at more than $5.6 million across DHS, Treasury and DOJ. **What happens next in the case?** Both defendants are charged with conspiracy to commit wire fraud and are presumed innocent unless proven guilty in court. Reiber was released on bond after his initial appearance in U.S. District Court in Idaho. Davydov's case depends on extradition from the U.K. Separately, federal authorities seized roughly 57 domains, related cyberinfrastructure and corporate bank accounts on September 20 under a warrant issued the day before — a civil/administrative seizure action distinct from the criminal charges.