A Shared Codebase and Opaque UAE Intermediary
Passwork Europe SL, headquartered in Barcelona, promotes itself with a “Made in EU 2017” badge and claims full GDPR and NIS2 compliance. But the investigation, published on July 17, found the software was originally developed in Arkhangelsk, Russia, in 2014 by Russian co-founders Ilya Garakh and Andrey Pyankov. cybernews brusselssignal
Reporters discovered that the European product shares a common codebase with its Russian sister company, Passwork LLC, receives updates on a similar timeline, and features a near-identical user manual. Updates to the European version have been supplied through Passwork FZ-LLC, a firm registered in the Ras Al Khaimah Economic Zone in the UAE in July 2022 and managed by one of the Russian co-founders. brusselssignal
The Russian firm holds certifications from the Federal Service for Technical and Export Control (FSTEC), an agency under Russia’s Defence Ministry, and from the FSB — certifications that require detailed source-code review. Its advertised clients include Gazprom, Transneft, the Russian Ministry of Defense, the FSB, and sanctioned Russian missile manufacturers. cybernews brusselssignal
European Clients and Security Warnings
Passwork’s European clients include at least three Irish government agencies, Dresden University of Technology in Germany, a major Dutch solar parks operator, a French port operator, and institutions served through a Belgian IT provider to Brussels’ regional government. irishtimes brusselssignal cybernews
Bart van den Berg, head of the security unit at the Clingendael Institute, warned that access to the source code could give the Russian state “far-reaching insight into the software and its vulnerabilities, or even deliberately add elements to it.” He added that if both products share the same codebase, “vulnerabilities may affect both versions.” brusselssignal
CEO Denies Links, Removes AI Guidance
Alexander Muntyan, CEO and sole shareholder of Passwork Europe SL, denied any relationship between the Spanish and Russian entities. “We do not share clients, servers, support systems, customer records, administrative access, or customer environments,” he told reporters. He cited the product’s “zero-knowledge architecture,” in which encryption occurs on the client side, as a safeguard. brusselssignal
Muntyan acknowledged the “common codebase origin” and confirmed he acquired rights to the software from the UAE entity in 2024, with full trademark rights due in August 2026. However, shortly after OCCRP first contacted him, the company removed AI guidance from its website that had described it as having “no affiliations with any US, Russian, or other non-European entities.” No evidence of malicious code or data compromise was found by reporters. brusselssignal