A Spanish password manager used by European government agencies shares deep technical links with a Russian company. This arrangement has raised serious security concerns among experts.
The company, Passwork Europe S.L., markets itself as a fully European firm. However, an investigation uncovered significant connections to a Russian counterpart.
Passwork sells software that helps organizations store and manage their passwords. Its clients include Irish government agencies and the Dresden University of Technology. The company strongly emphasizes its European identity.
Its website displays a badge reflecting its creation in Europe and the firm also released guidelines stating it has no ties to Russian or American entities. But the investigation found this public image does not match reality.
The hidden ties to Russia
Two Russian co-founders, Andrey Pyankov and Ilya Garakh, originally developed the password manager. They remain involved through an opaque company based in the United Arab Emirates.
This UAE firm supplies software updates to the Spanish company. However, the owners of the UAE company received no public disclosure. Therefore, it is unclear who controls the update pipeline.
Furthermore, the Russian co-founders also own a separate company called Passwork LLC in Russia. This Russian firm uses the same logo as the Spanish version. It advertises clients that include sanctioned Russian missile manufacturers.
The Russian company holds certifications from state agencies. These include the Federal Service for Technical and Export Control, or FSTEC and this agency falls under the Defense Ministry of Russia. The company also has certification from the FSB, Russia’s main counterintelligence agency.
Obtaining these certifications requires a deep review of the source code. The goal is to search for vulnerabilities or undeclared capabilities; in simple terms, they look for weaknesses or hidden backdoors. Experts warn this process could give Moscow valuable insights. If the Russian and European software share the same code, the risks are clear.
Bart van den Berg is a security expert at the Clingendael Institute. He described these scenarios as ‘serious risks.’ He said access to the source code could give the Russian state deep knowledge of vulnerabilities. It could even allow them to deliberately add harmful elements. While reporters found no evidence of malicious code, the situation remains concerning.
Expert concerns and transparency issues
Cybersecurity experts say transparency is essential in this field. Password managers hold the keys to the digital systems of an organization. Therefore, trust is not just a marketing claim.
Alessandra Chirico is an expert in EU regulation and cybersecurity policy. She said the stronger the trust narrative, the greater the duty of transparency; moreover, the lack of openness from the company raises red flags.
None of the European clients contacted by reporters knew about the Russian connection. Only one client knew about the former Russian owner of the product. This shows a clear gap in communication.
Meanwhile, the CEO of the company, Alexander Muntyan, denied any relationship with the Russian firm. He said they do not share clients, servers, or support systems. He also stated that customer data stays safely on private servers.
The investigation established that there were similarities between the two products. It noted that both products are derived from the same core codebase. The products also received updates via the software at similar intervals.
Such similarities suggest that the products may have connections with each other. Van den Berg said that if two products have the same code, the absence of flaws in one of the products does not guarantee protection against flaws in the other product. This means they could pose some issues that may be more dangerous for users in Europe.
A short while after the reporters approached Muntyan, the company withdrew its Artificial Intelligence guidelines. The guidelines had mentioned that there was no connection with Russia, but the removal puts the transparency of the company in doubt.
Muntyan also said he acquired the software rights from the UAE company two years ago. However, he was unable to comment on the ownership of the firm. He noted that he would completely acquire the trademark after August this year.
The origins and shift to Europe
Passwork began as a startup in Arkhangelsk, a Russian port city near the Arctic. Co-founder Pyankov registered the Russian website in June 2014. The very next day, he registered the European domain to the same address. This shows the European operation grew directly from the Russian roots.
The company initially faced skepticism in Russia. Some questioned whether it was independent. In a blog post, the administrator joked about its popular name as a ‘Putin’s password-stealing project.’ Many people also called it a Freelance FSB Department. This shows the trust issues they faced in Russia itself.
The fortunes of the company changed in 2017, this was when it won a startup competition which was run by the Skolkovo Foundation, a state-backed Russian organization.
However, this foundation was later sanctioned by the United States. Through this competition, the co-founders met a Finnish entrepreneur named Pekka Viljakainen, he helped them set up a European company.
The reason for the move was practical. Russian regulations did not allow the simultaneous handling of Russian and European client data. Therefore, the operators have to move Western clients out of Russia.
The company’s administrator admitted this in a blog post. He said people do not really trust Russian products. So, they needed an official company in a ‘normal’ country.
The challenge of achieving true European digital sovereignty is also evident in the EU Digital Identity Wallet’s reliance on Apple and Google.
In May 2017, Passwork Oy completed its registration in Finland. The co-founders each held a 35% share and Viljakainen’s firm held the remaining 30%. Viljakainen said he was not involved in operations.
He also had no knowledge of the product after the Finnish firm closed two years ago. However, he described the founders as having made a high-quality service.