U.S. Forensics Firm Under Investigation

Department of Justice building with American flag
Photo: CHRISTOPHER E ZIMMER / Shutterstock

Federal prosecutors say a trusted U.S. digital forensics vendor hid control by five Russian nationals to win government business, raising urgent questions about who watches the watchdogs.

Story Snapshot

  • Justice Department alleges Oxygen Forensics concealed Russian ownership to secure U.S. contracts.
  • CEO Lee Reiber and Russian national Oleg Davydov were arrested on September 23, 2026.
  • Reports link the company’s tools to past sales to federal agencies, including law enforcement.
  • The case is at the complaint stage; key ownership details remain alleged, not proven.

What Prosecutors Allege About Ownership And Control

Federal prosecutors said the Virginia firm Oxygen Forensics was actually owned and controlled by five Russian nationals, including Oleg Davydov. They alleged the company hid this from U.S. agencies and claimed its software was built in the United States, when it was developed in Russia. The government framed the conduct as a scheme to win federal business under false pretenses. The complaint charges conspiracy to commit wire fraud, which targets deceit used to obtain money or property.

Court summaries describe a holding chain that ran through a company in Cyprus. Prosecutors say the Cyprus layer masked the real owners and their ability to influence the U.S. entity. The filings cited by reporters do not publish a full ownership cap table, and the identities of all five alleged owners are not laid out in one public document in the gathered record. Those gaps reflect complaint-stage limits, not a court finding on the merits yet.

Arrests, Charges, And The Active Case Timeline

On September 23, 2026, authorities arrested Oxygen’s chief executive officer, Lee Reiber, in Idaho. British authorities detained Davydov at London Heathrow Airport the same day. Both face conspiracy to commit wire fraud charges tied to alleged misrepresentations to U.S. agencies. These arrests indicate a live case with named defendants and an active cross-border component. An arrest is not a conviction, and the defendants are presumed innocent unless proven guilty in court.

Prosecutors link the alleged concealment to procurement fraud risk. Reporters cite references to federal customers, including a National Computer Forensics Institute award. While the public record here does not attach specific contract certifications, it states the theory: the company won business after saying there was no foreign control and that development was domestic. The complaint’s focus on control and development origin aims at disclosures that help agencies assess national security risk.

Why This Matters For Police Tech And Public Trust

Public records and past reporting have tied Oxygen’s tools to U.S. law enforcement over several years. A 2017 Forbes report said the company sold to federal departments, including the Federal Bureau of Investigation and Customs and Border Protection, and noted Immigration and Customs Enforcement and Secret Service deals. That history makes the new claims about hidden control and software origin more serious, because many agencies relied on the vendor’s tools in sensitive cases.

Foreign ownership alone does not automatically bar a contractor. Federal rules focus on who can direct decisions and how risks are mitigated. But when a vendor allegedly hides beneficial owners or development locations, agencies cannot judge risk. That is what many readers on both left and right fear: powerful insiders buy influence, vendors get paid, and the public gets excuses. Transparent disclosures are the minimum price of trust in tools that can reach into a person’s phone and life.

What We Know, What We Do Not, And What Comes Next

The record assembled here confirms arrests, charges, and the government’s theory of five-person Russian control routed through Cyprus. It also confirms the allegation that the software was built in Russia, not the United States. The material does not include the full complaint text, corporate registry extracts, or code provenance. It also lacks a direct, on-record denial from Oxygen’s leaders in this packet. Those missing items limit outside verification at this stage.

Readers should watch for four things. First, the unsealed complaint and any affidavit that list the five owners and their rights. Second, the exact contract files showing what Oxygen certified about ownership and development. Third, any facility-security or foreign-control disclosures made to agencies. Fourth, technical evidence that shows where code was authored. These documents will show whether this was fraud, sloppy disclosure, or something in between that still broke the rules.

Sources:

pjmedia.com, courthousenews.com, forbes.com, thewire.in

© newsworthy.news 2026. All rights reserved.