An investigation by OCCRP and its media partners raises questions about the transparency of Passwork Europe, a Spanish company offering a password manager as a ‘Made in the EU’ solution. The software is used by European public institutions, universities and companies. However, journalists have established that the product was developed in Russia, and its European version still bears significant similarities to the solution sold by the Russian company Passwork LLC.
A technical analysis revealed 517 almost identical lines of code in the installation script. The release schedule for updates is also similar. Version 7.6 was released in Russia on 6 April 2026 and in Europe the following day, with virtually the same changelog. Updates for the European company are reportedly to come from a firm in the United Arab Emirates, managed by one of Passwork’s Russian co-founders.
Further concerns relate to the Russian company Passwork LLC. The company lists clients linked to the defence industry and subject to Western sanctions. It also states that it holds certification from FSTEC, an agency under the Russian Ministry of Defence, and authorisation from the FSB. According to experts, the FSTEC certification process usually requires the source code to be submitted to a state-accredited laboratory for analysis. Given that the code base is shared, this could reveal vulnerabilities that also exist in the European version.
However, there is no evidence that the European software contains malicious code, has been modified by the Russian security services, or has led to a data breach. Alexander Muntyan, head of Passwork Europe, assures that the companies do not share customers, servers, support or administrative access. He also emphasises that encryption takes place locally on customers’ servers, so the provider does not have access to their passwords.
Customer reactions have been mixed. An Irish government laboratory has launched a risk review, whilst the Brussels-based IT service provider Paradigm sees no functional impact on security arising from historical links. Eight companies presented as clients, including Enel and Deutsche Post, have, however, denied using the product. The case demonstrates that when selecting cybersecurity tools, it is not only the product’s architecture that matters, but also ownership transparency and control over updates.

