Tech News

NFI Unlocks a Google Pixel in Dutch Triple-Homicide Case

The Nederlands Forensisch Instituut (NFI) managed to access the contents of a Google Pixel belonging to one of the suspects in a triple-homicide case in Oosterhout, the Netherlands. Photos of weapons, stacks of cash, and, most importantly, conversations that can now be read. Prosecutors are hoping the two other seized Google Pixels will also be unlocked.

Results, but no technical details

The announcement was made on Thursday, August 20, 2026 by a Dutch prosecutor during a fifth pretrial hearing at Schiphol court. The Nederlands Forensisch Instituut (NFI) managed to unlock a suspect’s smartphone: a Google Pixel. The case is serious, as this is the device of one of the three people prosecuted in a triple-homicide case that took place in Oosterhout. The events date back to March 28, 2025 and are covered in more detail in the article by Omroep Brabant, the local media outlet on site.

The content, described in court by the prosecutor: "A very large number of images of weapons and stacks of cash were found on his phone. There are also many conversations that can now be read." - The two other Google Pixels are expected to be unlocked next.

What is frustrating is that there are no technical details. We do not know:

  • The exact model. Pixel generations are not all equally resistant to the various data extraction tools.
  • The Android version and its patch level at the time of seizure. It could even be a model running GrapheneOS, although I find that less likely.
  • The device state when it fell into investigators’ hands (we will come back to that).

So there is nothing to suggest that the NFI exploited a vulnerability or bypassed device authentication. On the one hand, that is understandable: disclosing an access method does the work for anyone who might want to protect themselves against it.

The NFI knows Google Pixel devices well

The institute, which reports to the Dutch Ministry of Justice and Security, is no stranger to this kind of work. In fact, the NFI took part in EXFILES, a European project funded under Horizon 2020, bringing together law enforcement agencies and private companies around access to encrypted phones.

In a post summarizing its findings from the project, the NFI said EXFILES helped provide access to hundreds of devices, mainly in organized-crime investigations. And the NFI does not work on just any smartphones: the models are carefully selected, notably based on trends in criminal circles.

BFU or AFU: the device state is crucial

In mobile forensics, one variable is decisive: the device’s state at the time of seizure. There are two main states:

  • BFU (Before First Unlock): the device has not been unlocked since its last reboot. Encryption keys are not loaded into memory, biometrics are disabled, and most user data remains inaccessible.
  • AFU (After First Unlock): the device has been unlocked at least once since boot. Some keys remain in RAM, opening the door to extraction techniques that BFU prevents.

In practice, a seized or stolen phone is almost always in AFU: the screen is locked, but the keys are in memory. If a device stays locked for too long while inactive, note that the smartphone may restart by itself. This is a new feature that Google began mentioning as early as April 2025 (Google Play services version 25.14). The idea: automatically restart the smartphone after 72 consecutive hours of being locked, if the device remains inactive. It should be noted that the user cannot change this delay. It is a protection already offered by GrapheneOS, with a trigger after 18 hours.

Looking at my Samsung Galaxy smartphone, I was able to confirm the presence of this option: Settings > Security and privacy > Other security settings > Auto restart when inactive.

As for Google Pixel resistance, it is difficult to draw conclusions without knowing exactly which models were used by the defendants. In October 2025, a user known as rogueFed posted screenshots on the GrapheneOS forum of an internal Cellebrite support matrix, obtained by joining a private meeting (however, Cellebrite never authenticated those documents).

According to 404 Media, the Israeli vendor’s tools would be able to extract data from Pixel 6 through Pixel 9 devices running stock Google firmware in all three states (BFU, AFU, and unlocked). By contrast, the same devices running GrapheneOS would resist from late-2022 releases onward.

Even if this proves nothing about this case, it does show that some organizations have the means to crack the locks...

author avatar
Florian Burnel Co-founder of IT-Connect
Systems and network engineer, co-founder of IT-Connect and Microsoft MVP "Cloud and Datacenter Management". I'd like to share my experience and discoveries through my articles. I'm a generalist with a particular interest in Microsoft solutions and scripting. Enjoy your reading.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.