EU password manager used by governments traced to Russian origins

A joint investigation by the Organized Crime and Corruption Reporting Project (OCCRP), Le Monde, Investico, and other European media outlets has revealed that Passwork, a password management tool marketed as a European product and used by government agencies across the EU, shares its technological origins with a Russian counterpart whose clients include sanctioned missile manufacturers and Russia’s Federal Security Service.

A Shared Codebase and Opaque UAE Intermediary

Passwork Europe SL, headquartered in Barcelona, promotes itself with a “Made in EU 2017” badge and claims full GDPR and NIS2 compliance. But the investigation, published on July 17, found the software was originally developed in Arkhangelsk, Russia, in 2014 by Russian co-founders Ilya Garakh and Andrey Pyankov. Ccybernews Bbrusselssignal

Reporters discovered that the European product shares a common codebase with its Russian sister company, Passwork LLC, receives updates on a similar timeline, and features a near-identical user manual. Updates to the European version have been supplied through Passwork FZ-LLC, a firm registered in the Ras Al Khaimah Economic Zone in the UAE in July 2022 and managed by one of the Russian co-founders. Bbrusselssignal

The Russian firm holds certifications from the Federal Service for Technical and Export Control (FSTEC), an agency under Russia’s Defence Ministry, and from the FSB — certifications that require detailed source-code review. Its advertised clients include Gazprom, Transneft, the Russian Ministry of Defense, the FSB, and sanctioned Russian missile manufacturers. Ccybernews Bbrusselssignal

European Clients and Security Warnings

Passwork’s European clients include at least three Irish government agencies, Dresden University of Technology in Germany, a major Dutch solar parks operator, a French port operator, and institutions served through a Belgian IT provider to Brussels’ regional government. Iirishtimes Bbrusselssignal Ccybernews

Bart van den Berg, head of the security unit at the Clingendael Institute, warned that access to the source code could give the Russian state “far-reaching insight into the software and its vulnerabilities, or even deliberately add elements to it.” He added that if both products share the same codebase, “vulnerabilities may affect both versions.” Bbrusselssignal

CEO Denies Links, Removes AI Guidance

Alexander Muntyan, CEO and sole shareholder of Passwork Europe SL, denied any relationship between the Spanish and Russian entities. “We do not share clients, servers, support systems, customer records, administrative access, or customer environments,” he told reporters. He cited the product’s “zero-knowledge architecture,” in which encryption occurs on the client side, as a safeguard. Bbrusselssignal

Muntyan acknowledged the “common codebase origin” and confirmed he acquired rights to the software from the UAE entity in 2024, with full trademark rights due in August 2026. However, shortly after OCCRP first contacted him, the company removed AI guidance from its website that had described it as having “no affiliations with any US, Russian, or other non-European entities.” No evidence of malicious code or data compromise was found by reporters. Bbrusselssignal