Passwork Europe, a Spain-based password manager used by European public sector bodies, universities, and private organizations, is facing scrutiny after an investigation led by OCCRP uncovered technical and historical connections to a Russian counterpart certified by Russian state agencies.
The investigation found that Passwork Europe S.L. and Russia’s Passwork LLC share a common codebase origin, closely aligned release schedules, similar documentation, and nearly identical deployment scripts.
Although no evidence suggests malicious code, data compromise, or unlawful conduct, researchers expressed concern about the combination of software overlap, opaque ownership structures, and the update supply chain, which raises significant risk questions for customers managing highly sensitive credentials.
Passwork Updates With FSTEC-Certified Russian Firm
Passwork Europe promotes itself as a European company, describing its product as “Made in EU 2017” and highlighting its private-server deployments.
The company’s chief executive and sole shareholder, Alexander Muntyan, stated that there is no operational relationship between the Spanish company and its Russian counterpart.
He emphasized that they do not share clients, servers, support systems, customer data, administrative access, or customer environments. Additionally, Muntyan noted that the platform’s zero-knowledge design means that encryption and decryption occur on customers’ own infrastructures, limiting Passwork Europe’s access to vault contents.
However, OCCRP discovered that the product originated in Arkhangelsk, Russia, where co-founders Ilya Garakh and Andrey Pyankov registered both the Russian Passwork.ru and the European-facing Passwork.pro domains in 2014.
The business later established a Finnish entity, Passwork Oy, which the Russian founders exited in ownership in 2022. A UAE-based firm, Passwork FZ-LLC, was subsequently registered in Ras Al Khaimah, with Pyankov listed as the manager. Public domain records reportedly indicate that Garakh is the owner and contact for the firm’s UAE domain.
The Spanish company was registered in 2024, shortly after the Finnish operation entered liquidation. Muntyan informed OCCRP that he acquired the rights to the Passwork software from the UAE entity in 2024, with a transition period expected to conclude in August 2026.
He mentioned that the UAE-based firm has provided limited product knowledge-transfer assistance. At the same time, Passwork Europe reviews updates before integrating them into its product.
Researchers identified the update pipeline as a significant concern. The Russian and European websites reportedly announced six recent releases on nearly the same timeline, often using very similar descriptions.
For instance, Russia’s Passwork LLC announced version 7.67.67.6 on April 6, 2026, followed by Passwork Europe’s announcement of version 7.67.67.6 the next day.
Security researcher Lukasz Olejnik noted that the separation between the two products is “technically shallow,” citing hundreds of substantially identical lines in installer scripts.
The Russian Passwork LLC is certified by Russia’s Federal Service for Technical and Export Control (FSTEC) and the Federal Security Service (FSB). FSTEC certification involves a detailed evaluation of software architecture, cryptographic controls, access mechanisms, logging, and potential “undeclared capabilities.”

Experts told OCCRP that if the Russian and European offerings retain shared code or components, source-code access granted during Russian compliance assessments could potentially reveal weaknesses relevant to both products.
Bart van den Berg of the Clingendael Institute warned that synchronized codebases may expose both variants to the same vulnerabilities. Donald Ortmann, a German security researcher, pointed out that software updates are a high-value supply chain attack vector, drawing comparisons to the SolarWinds compromise, in which attackers inserted a backdoor into a trusted update process.
Such incidents highlight the importance of assessing not only encryption design but also who controls source code, build systems, signing keys, update infrastructure, and third-party development access.
European customers contacted by OCCRP, including government-related bodies, reportedly stated they were unaware of the Russian product and its state certifications. Some organizations have begun to reassess their exposure.
For customers, these findings underscore the need for supplier due diligence, independent code review, software bill of materials validation, reproducible builds, cryptographic update signing, and clear disclosure of ownership, development, and support relationships.
Despite these concerns, Passwork Europe maintains that its customers’ data remains isolated on customer-controlled servers and rejects the suggestion that Russian code review creates an automatic backdoor risk.
However, the investigation illustrates a broader cybersecurity principle: for password management platforms, transparency across the entire software supply chain is critical for establishing trust.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

