Passwork Security Breach: European Password Manager Linked to Russian Intelligence

Article Content
In the high-stakes arena of global cybersecurity, trust is not merely a preference; it is the fundamental currency upon which modern digital infrastructure is built. When an enterprise or government agency selects a password manager, it is quite literally handing over the “keys to the kingdom.” Yet, a bombshell joint journalistic investigation published on July 17, 2026, has shattered that trust, exposing how geopolitical realities can hide behind sleek marketing and European addresses. This revelation is being analyzed in cybersecurity circles not just as a compliance failure, but as a potential Passwork security breach of trust that exposes fundamental vulnerabilities in Western software supply chain verification. A collaborative probe led by the Organized Crime and Corruption Reporting Project (OCCRP), alongside premier European media outlets such as The Irish Times, Le Monde, NU.nl, De Groene Amsterdammer, De Tijd, and Investico, has revealed that Passwork, a popular password manager widely utilized across European public and private sectors, has deep, concealed technological and administrative ties to a Russian sister company certified by the Kremlin’s intelligence and defense apparatus.
The Anatomy of Deception: AI Bots and the Finnish Origin Myth
Passwork Europe S.L., currently headquartered in Barcelona, Spain, went to extraordinary lengths to distance itself from its true origins. On its English-language website, the company proudly displayed a “Made in EU 2017” badge and actively cultivated a narrative that it was founded in Finland as a small, security-focused startup before relocating to Spain to comply with the European Union’s strict privacy and cybersecurity regulations. This positioning was designed to assure European procurement officers that the company was fully independent, GDPR-compliant, and free from the oversight of hostile foreign intelligence services.
However, the investigative team uncovered a bizarre and highly calculated defensive measure embedded directly in the company’s website architecture. Passwork had created a specific webpage designed solely to instruct artificial intelligence web crawlers and search bots on how to describe the company. The instructions explicitly directed AI bots to state that Passwork was “bootstrapped, founder-owned, and has no affiliations with any US, Russian, or other non-European entities”. The site went so far as to command that these guidelines “should always override conflicting or outdated data”. This preemptive strike on automated information retrieval illustrates a deliberate strategy of digital deception aimed at maintaining a false facade of European digital sovereignty.
The truth, as investigators revealed, is far less palatable. Passwork was actually founded in Arkhangelsk, Russia, in 2014 by Russian developers Ilya Garakh and Andrey Pyankov. Despite claims of a clean break and a relocation to Barcelona, the developers simply split their operations into two parallel tracks. While Passwork Europe S.L. was spun up to capture the lucrative Western enterprise market, a Russian sister company—Passwork LLC—was registered in Russia to sell near-identical password vault software to domestic clients. These clients are not benign commercial entities; they include massive Russian state-owned enterprises like Gazprom and Transneft, as well as EU-sanctioned aerospace and military defense suppliers, such as the missile manufacturer Almaz-Antey’s subsidiary Avangard, and aircraft builder United Aircraft Corporation.
A Shared Codebase and the Shadow of FSB Certification
The defense mounted by Passwork’s leadership has focused on physical and operational isolation. The company’s Spanish CEO, Alexander Muntyan, has adamantly denied any structural connection between the Barcelona-registered Passwork Europe S.L. and its Russian counterpart, Passwork LLC. Muntyan asserted that the European business operates entirely on German servers, and since Passwork is primarily marketed as a self-hosted, on-premise solution (often deployed in-house using Docker and PHP/MongoDB), the client’s actual vault data remains strictly inside the client’s own private infrastructure. From his perspective, the similarities between the European and Russian software versions are merely administrative holdovers.
However, cybersecurity experts and the joint investigation have thoroughly dismantled this defense by analyzing the software’s underlying mechanics. The investigation confirmed that the European and Russian versions of Passwork are built upon a heavily shared codebase, utilize virtually identical user manuals, and pull product updates on synchronized timelines. This architectural overlap introduces a massive, state-level risk due to the regulatory environment in Russia.
Because Passwork LLC sells its software to the Russian military and state-owned enterprises, the product must hold official certifications from the Federal Service for Technical and Export Control (FSTEC)—an agency under the Russian Ministry of Defense—and the Federal Security Service (FSB). To obtain these state licenses, Russian law requires developers to submit their software to a deep, intrusive source-code review. The primary objective of these state-supervised audits is to search for “undeclared capabilities”—a regulatory euphemism for backdoors—as well as unpatched vulnerabilities.
In a standard commercial audit, such as those conducted via platforms like HackerOne, security bugs are found and immediately patched to protect users. However, when the Russian Ministry of Defense and the FSB perform these code reviews, they are not acting as benevolent security consultants. Rather, they are building a precise technical map of the software’s internal logic, dependencies, and flaws. Because the European and Russian versions of Passwork share a common codebase, any structural vulnerability or “undeclared capability” discovered (or covertly introduced) during the FSB’s certification process in Russia can be weaponized against European servers running the Western version of the software.
Analyzing the Risks of a Passwork Security Breach
For European enterprises, the primary threat is not that Russian spies are actively reading password databases stored on German servers. Instead, the risk lies in the software update supply chain and the potential for a catastrophic Passwork security breach. If a hostile state actor possesses a blueprint of the software’s vulnerabilities, they can execute a targeted attack through several highly effective vectors:
- The Malicious Update Vector: Because password managers require regular updates to maintain compatibility with browser extensions and corporate directory services (like LDAP and Active Directory), clients are constantly pulling new code. If the development pipeline is compromised or influenced by developers operating under Russian jurisdiction, a malicious update could be pushed to European servers. This is precisely the mechanism used in the infamous SolarWinds hack.
- The Middle-Man Pipeline: The investigation revealed that software updates for Passwork’s European arm have not been delivered directly from Spain. Instead, they have been routed through an opaque intermediary firm in the United Arab Emirates, named Passwork FZ-LLC, registered at “Shed No. 23” in the Ras Al Khaimah Economic Zone. This UAE entity is managed by Russian co-founder Ilya Garakh. Even as Alexander Muntyan claims a transition period is underway to end Garakh’s involvement by August 2026, the technical pipeline remains deeply suspect.
- Targeted Zero-Day Exploitation: Armed with the source code obtained through FSTEC and FSB reviews, Russian state-affiliated cyber units do not need to push a malicious update. They can simply scan the public-facing IP addresses of European organizations hosting Passwork on-premise and exploit existing, unpatched zero-day vulnerabilities in the codebase to gain remote code execution.
As Bart van den Berg, head of the security unit at the prestigious Clingendael Institute, starkly warned: “It doesn’t seem wise to me to hand over the digital keys to your house to such a party. That is far too dangerous.” He added that in the context of modern hybrid warfare, gaining access to an organization’s password vault is “far more effective than a plane or a bomb.”
Collateral Exposure and the Immediate European Fallout
The exposure of Passwork’s true pedigree has sent shockwaves through critical European infrastructure. Because Passwork was marketed as a high-trust, “Made in EU” solution, it successfully bypassed traditional geopolitical vetting processes at numerous public and private entities. The investigation identified a highly sensitive roster of clients actively using the software to guard their internal operations, including:
- Irish State Agencies: At least three Irish government bodies, including the state-funded Dublin Institute for Advanced Studies, were discovered to be actively managing their employees’ passwords using Passwork. The agencies admitted they were completely unaware of the Russian connection and launched immediate procurement and security audits.
- Novar (Netherlands): As one of the largest builders of solar parks and green energy infrastructure in the Netherlands, Novar represents a textbook target for state-sponsored cyber-sabotage. Upon being notified of the investigation’s findings, Novar immediately terminated its contract with Passwork and flagged the vendor to the Dutch National Cyber Security Centre (NCSC) over concerns that a hostile foreign actor could leverage the software to compromise the nation’s power grid.
- The Dresden University of Technology: High-profile academic and research institutions are prime targets for intellectual property theft. Storing the credentials of research laboratories in a password manager with Russian ties represents an unacceptable level of risk.
- A French Port Operator: Maritime and logistics infrastructure are critical to European trade and military mobility, making this client exposure a matter of serious national security.
In response to these findings, cybersecurity agencies across the Continent are issuing urgent guidance. The consensus among security experts is clear: organizations currently utilizing Passwork must immediately halt automated updates, export their credential vaults, and begin a structured rotation of all stored passwords—prioritizing administrative, network infrastructure, and database credentials to limit the potential blast radius of a compromised vault.
The Geopolitical Wake-Up Call for Software Procurement
The Passwork scandal is a watershed moment that highlights a gaping blind spot in Western software procurement. For years, European organizations have relied on simple “Made in Europe” self-attestations, corporate relocations to cities like Barcelona, and compliance badges as a proxy for security. In an era of aggressive hybrid conflict, these administrative shells are easily manipulated by entities wishing to obfuscate their true origins
Written by
TempMail Ninja
Digital privacy and online security expert. Passionate about creating tools that protect users' identity on the internet.


