An Idaho CEO was arrested for allegedly helping Russians hide ownership of a firm whose software reached the Secret Service, prosecutors say the cover-up followed Russia’s Ukraine invasion.
Lee Reiber, 55, was taken into custody in Idaho on Sunday and charged with conspiracy to commit wire fraud after federal prosecutors said he served as the American face of a digital forensics company still controlled by Russian nationals. Oleg Davydov, 52, a Russian national described as Reiber’s boss, was arrested the same day at London’s Heathrow Airport, and the United States is seeking his extradition.
Both men face up to 20 years in prison if convicted. Prosecutors allege they concealed from U.S. officials that Alexandria, Virginia-based Oxygen Forensics Inc. was owned by five Russian nationals and that its software, used by the U.S. Secret Service, was developed and managed in Russia.
The case lands hard on a simple security question: how software tied to Russian owners and Russian development teams reached contracts with the Secret Service and other sensitive federal agencies while ownership was scrubbed from public view.
Prosecutors say the cover-up began after Ukraine
The U.S. Attorney’s Office for the Central District of California laid out the alleged motive in plain terms. Officials said the concealment deal tracked the fallout from Moscow’s war.
In a statement tied to the charges, the office said: prosecutors stated,
"In response to Russia’s invasion of Ukraine, Davydov, Reiber, and the Russian co-conspirators agreed to conceal Oxygen Forensics’ true ownership and the development of its software in Russia,"
Court filings describe the corporate reshuffle that followed. Reiber was installed as CEO, president, and chairman of the board in March 2022. The Russian owners were then removed from the company’s public corporate filings.
Filings put it directly:
"Reiber was installed as the company’s CEO, president, and chairman of the board in March 2022. The Russian owners were then removed from the company’s public corporate filings,"
Prosecutors say the names of the Russian owners were scrubbed in recent years around the same time the American executive was put in charge. The firm itself remained a vehicle for software first developed by Davydov in Russia in 2000.
Federal contracts came with ownership certifications
In September 2024, Oxygen Forensics signed a five-year deal with the U.S. Secret Service and the National Computer Forensics Institute. The NCFI trains law enforcement and judicial officials on cybercrime. Reiber certified that the company had no immediate or highest-level owner who would raise alarm, language aimed at keeping foreign adversaries off sensitive contracts.
The New York Post reported that the company secured more than $2 million in federal contracts while Russians controlled the firm through a Cyprus holding company, and that Reiber falsely represented to government agencies that Oxygen had no foreign ownership or control and that its software was developed in the United States.
That certification sits at the center of the wire-fraud conspiracy charge. If ownership and development location were hidden, the government was sold a false picture of who controlled tools touching federal systems.
An affidavit in the case identifies multiple U.S. agencies affected by the Russian-linked firm, including the Department of War, the Department of Homeland Security, and the DHS Inspector General’s office. The Secret Service was not the only door the software reached.
Security lapses around protective agencies already draw hard scrutiny, including cases where a Secret Service agent was placed on leave amid a probe into leaked travel details.
Reiber’s own email showed the stakes
Prosecutors point to messages that undercut any claim of innocent paperwork errors. In an alleged email to Davydov, Reiber warned that the firm’s links to Russia must not be discovered because they could “destroy this entire opportunity.” He also wrote that the company “hangs in the balance,” language tied to a pending federal contract.
Those phrases are short. They are also clear. A CEO discussing a U.S. government opportunity while fretting about Russian links being exposed is not routine compliance talk.
Prosecutors further allege that in March 2026 Reiber told government officials Russians were not involved in building the software and that no one in the country had access to it. They say that was false, and that a Russian team still managed the product.
Oxygen’s software recovers, preserves, and analyzes electronic data from digital devices, the kind of tool agencies use when phones, laptops, and cloud accounts become evidence. Giving that capability a clean American front while development stayed overseas is exactly the risk federal ownership rules exist to block.
Russian security services were earlier customers
The government’s account does not stop at ownership on paper. Prosecutors allege the software was previously sold to the Russian federal security service, the Russian investigative committee, and the Russian ministry of internal affairs. In other words, the same product line had already served Moscow’s own security apparatus before it appeared in U.S. contracting channels.
That history matters for any conservative reader who has watched years of warnings about supply-chain risk, foreign software in federal networks, and the ease with which shell structures can blur true control. The charge here is wire-fraud conspiracy, not a completed espionage count. But the alleged method, install an American CEO, scrub Russian names from public filings, certify clean ownership, keep development in Russia, is a blueprint for defeating the screening process.
Protective and national-security work already contends with other breaches of perimeter and information control, from an armed man arrested at a Trump golf course with sketches and Secret Service details to pressure on agencies that handle the country’s most sensitive movements.
Secret Service cut ties after the risk surfaced
The Secret Service later confirmed it had used Oxygen Forensics software and said it “immediately discontinued” that use in February after the agency identified security risks. The White House referred a press inquiry on the case to the Secret Service, which did not immediately respond when the charges became public.
Discontinuing a product after the fact is damage control. It is not the same as blocking a tainted vendor before a five-year deal is signed. Taxpayers and agents who rely on clean tools deserve the screening to work on the front end, not after indictments.
Reiber’s background as a former police officer, reported in coverage of the arrest, only sharpens the contrast. An American ex-cop was allegedly installed as the public leader of a firm prosecutors say remained under Russian ownership and Russian technical control. Figurehead leadership is a classic way to make a foreign-controlled vendor look domestic enough to clear a checklist.
Other recent episodes show how fast security assumptions can collapse when protection details slip, including police response to a trespasser at a high-profile residence after Secret Service protection ended.
Wire fraud charges target the lies that opened the door
Federal prosecutors framed the conduct as conspiracy to commit wire fraud: a scheme to deceive U.S. officials about ownership and development so the company could win and keep government business. The alleged false statements, the ownership certification on the September 2024 Secret Service and NCFI deal, and the scrubbing of Russian names from corporate filings are the acts the government says made the fraud work.
Davydov’s arrest at Heathrow and the extradition request show the Justice Department is not treating this as a paperwork spat. Reiber’s Idaho arrest puts an American executive in the dock for allegedly fronting the arrangement. Both men, prosecutors say, joined Russian co-conspirators in the concealment plan after the Ukraine invasion raised the political and security cost of open Russian ownership.
Open questions remain. The public package does not list all five Russian owners by name, does not publish a full docket number, and does not reproduce every line of the affidavit. What it does show is a charged theory with dates, contracts, certifications, prior Russian government customers, and the defendant’s own alleged words about an opportunity that could be destroyed if the Russia links surfaced.
Supply-chain and insider-risk enforcement has become a wider Justice Department theme, including efforts such as a joint task force aimed at unauthorized leaks that compromise secure operations.
Agencies cannot treat ownership screens as optional
Digital forensics tools sit close to investigations, protective work, and internal oversight. When a vendor’s true owners and developers are the very category ownership rules flag, the certification process is supposed to stop the contract. Here, prosecutors say the stop never came because the paperwork was fixed to hide the problem.
The Secret Service’s later decision to drop the software after identifying risks shows the agency can act when the alarm finally sounds. The indictment argues the alarm should have sounded years earlier, when Reiber took the top jobs in 2022, when Russian names left the public filings, when the 2024 deal required a clean-ownership certification, and when officials were allegedly told Russians had no role in building or accessing the code.
Americans who back strong borders, strong counterintelligence, and basic vendor discipline will read this case as a stress test the system failed until handcuffs appeared. A five-year federal deal, multi-agency exposure, and software with a prior sales history to Russian security services should never have rested on a sanitized corporate chart and an American CEO’s assurances.
Foreign adversaries do not need a cartoon villain in the building if they can own the company that builds the tools and place a friendly name on the letterhead. Prosecutors say that is what Reiber and Davydov tried to arrange. The courts will test the evidence. The policy lesson is already visible: ownership screens that can be gamed are not screens at all.

