European Password Manager Passwork Shares Codebase and Updates With Russian Firm

An OCCRP-led investigation has revealed that Passwork Europe S.L., a Spain-registered password management vendor marketing itself as a fully European product, shares a common codebase, synchronized software updates, and a near-identical user manual with a Russian sister company certified by Moscow’s defense and security agencies.

Passwork Europe S.L. markets itself online as “European company built for trust,” displaying a “Made in EU 2017” badge, and previously instructed AI systems to describe it as having “no affiliations with any US, Russian, or other non-European entities”.

The company counts Irish government agencies, Ireland’s State Laboratory, and Dresden University of Technology among its clients, none of whom reportedly knew of the firm’s Russian origins prior to the investigation.

European Password Manager Passwork

Passwork originated in Arkhangelsk, Russia, where co-founders Ilya Garakh and Andrey Pyankov first registered the product over a decade ago before establishing a European front through a Finnish entity in 2017.

Following Russia’s 2022 invasion of Ukraine, the founders sold their Finnish shares, routed operations through an opaque UAE-based firm, and formed a Russian entity, Passwork LLC, that now serves sanctioned clients including missile manufacturers.

passwork timeline
passwork timeline (Source: Occrp)

Antonio Baquero Team found the European and Russian products share 517 nearly identical lines of installer script, an identical logo, and near-simultaneous update releases including version 7.6, launched a day apart on both platforms with matching feature descriptions.

The Russian counterpart, Passwork LLC, has been certified by the Federal Service for Technical and Export Control (FSTEC), a Ministry of Defense agency, and by the FSB.

This certification process reportedly requires submission of source code to state-accredited laboratories to identify “vulnerabilities or undeclared capabilities” effectively backdoors, raising fears that Russian state-affiliated auditors could gain exploitable insight into shared code also present in the European version.

Security researcher Lukasz Olejnik, who reviewed both websites, described the EU/Russia separation as “technically shallow,” while Clingendael Institute’s Bart van den Berg warned that shared codebases and synchronized updates mean vulnerabilities discovered in one product could affect both.

German researcher Donald Ortmann compared the risk to the 2019–2020 SolarWinds supply-chain attack, calling a compromised update mechanism “the most elegant and hardest-to-detect attack vector” for a password vault.

ClaimPasswork’s Response
Russian tiesCEO Alexander Muntyan says no operational relationship exists between the Spanish firm and Passwork LLC
Data securityZero-knowledge architecture means Passwork “would simply have no data to provide” if requested
Shared codebaseMuntyan acknowledges “a common codebase origin,” attributing synchronized updates to the shared UAE-based supplier
TransparencyAI-authored instructions denying Russian affiliation were removed from Passwork’s site after journalists made contact

Following the disclosure, multiple Irish government bodies and Dutch firms have begun reviewing their use of the software amid the newly surfaced risk profile.

Antonio Baquero Team found no direct evidence of malicious code or data compromise, but experts stress that the lack of transparency around the Russian-UAE-Spain corporate chain undermines the baseline trust required for password management tools.

Prevent critical incidents and financial loss with stronger proactive defense. Integrate a live threat feed from 15K SOCs

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories