Security Concerns

Russian Connections: European Password Manager Passwork Under Scrutiny

Passwort, password manager, Passwork password manager Russia, Passwork password manager Russia connections investigation, Passwork, Security
Facebook
X
LinkedIn
Reddit
WhatsApp

An investigation reveals close technological ties between the European password manager Passwork and a Russian counterpart certified by state authorities.

A joint investigation by the Organized Crime and Corruption Reporting Project (OCCRP) and partner media outlets indicates that European password manager Passwork maintains close technological links with a Russian partner company. Passwork Europe S.L., headquartered in Spain, markets its products online as a European solution carrying the “Made in EU” label. The software is used by numerous European public authorities, research institutions such as the Technical University of Dresden in Germany, and Irish government organizations.

Ad

The investigation found that the software was originally developed by two Russian founders in Arkhangelsk. Updates for the European version are distributed through an opaque company in the United Arab Emirates, which is managed by one of the Russian co-founders. The founders also own the Russian company Passwork LLC, which uses an identical logo and lists sanctioned Russian defense companies among its customers.

Independent security researchers found that the source code of the installation scripts for both products is nearly identical across more than 500 lines. In addition, software updates, including version 7.6 released in April 2026, were published on the Russian and European platforms only one day apart and included matching feature descriptions.

Russian State Certifications Raise Security Concerns

The Russian counterpart Passwork LLC holds certifications from FSTEC, a Russian defense ministry agency, as well as from the Federal Security Service (FSB). Experts in sanctions law and cybersecurity point out that obtaining such certifications in Russia typically requires companies to submit the complete source code to state accredited laboratories. The purpose of these reviews is to identify vulnerabilities or undisclosed functionality.

Ad

Bart van den Berg, a security expert at the Clingendael Institute, warned that access to source code could provide the Russian government with “extensive insight into the software and its vulnerabilities or even allow it to deliberately add components.” He described such scenarios as serious risks.

However, there is currently no evidence that the European version’s source code has been manipulated or that user data has been compromised. Regulatory expert Alessandra Chirico commented more broadly on transparency obligations within the cybersecurity industry:

“In cybersecurity, trust is not simply a commercial claim. The stronger the narrative of trust, the greater the corresponding transparency obligation required to maintain it.”

Alessandra Chirico, Regulatory Expert

Management Response and Customer Reactions

Alexander Muntyan, CEO and sole shareholder of Passwork Europe S.L., rejected claims of an active business relationship between the European and Russian entities. He emphasized that the Spanish and Russian companies do not share customers, servers, support systems, or administrative access.

According to Muntyan, the similarities between the products and the synchronized update schedule are the result of their shared source code origins. He also stated that the software architecture is based on a zero knowledge principle, with encryption and decryption performed exclusively locally on customers’ private servers. As a result, the provider itself has no access to users’ data.

Explicit statements on the company website claiming that there were no connections to Russian entities were removed after initial media inquiries.

Most European customers contacted during the investigation were reportedly unaware of the product’s Russian background. After the allegations became public, Ireland’s state laboratory launched an internal review of the software and associated risks. Other customers, including Brussels based IT authority Paradigm, said they did not see any functional impact on their security.

Several major companies listed as references on Passwork’s website, including Italian energy provider Enel and Deutsche Post, denied to journalists that they use the software at all.

(ll)

Ad

Artikel zu diesem Thema

Weitere Artikel