European Governments Exposed to Russian-Linked Security Software
The Hague, Saturday 29 August 2026
European public institutions and green energy firms are using a password manager supervised by Russia’s FSB, posing severe national security risks despite marketing itself as a European product.
A Dual Identity Built for European Expansion
In April 2017, a 32-year-old software developer named Ilya Garakh and his co-founder won an innovation award for ‘Passwork’ at a Skolkovo Foundation ‘Startup Tour’ in Arkhangelsk, Russia [1]. Passwork was initially pitched as ‘Dropbox, but then for company passwords’ [1]. To expand into European markets, the founders admitted on a Russian tech platform in 2017 that they needed to establish an official company in a ‘normal’ country because international customers did not trust products originating directly from Russia [1]. Consequently, the company adopted a dual-website strategy: a Cyrillic version that markets the software as domestic Russian, and an English-language version claiming it is ‘Made in Europe’ and ‘Chosen by government agencies and highly regulated sectors across Europe’ [1].
Kremlin Connections and FSB Supervision
The reality behind Passwork’s European facade is deeply tied to the Russian state apparatus. The software operates under the supervision of the FSB (the Russian security service) and is listed in an official registry of domestic Russian software [1]. Under Russian legislation, the company is legally required to cooperate with requests from security services [1]. Furthermore, Passwork supplies its services to major Russian state-owned enterprises, including energy giants Gazprom and Transneft, as well as sanctioned defence firms such as Avangard, Almaz-Antey, and the United Aircraft Corporation [1].
Penetrating European Critical Infrastructure
A collaborative investigation by the OCCRP and various European media outlets—including Investico, De Groene Amsterdammer, NU.nl, Le Monde, and De Tijd—revealed that several European entities have adopted or tested Passwork in recent years [1]. Alarmingly, this includes Dutch companies operating within the sustainable energy sector, such as Novar (formerly Solarfields), which manages major projects like the largest solar park in the Netherlands located in the Groningen Eekerpolder [1]. This exposure raises acute security concerns, particularly given that in late December 2025, Russian-aligned hackers disrupted dozens of wind and solar parks in Poland, nearly leaving half a million people without electricity [1].
Shell Offices and Technical Support Links
The physical and technical infrastructure of Passwork further highlights these risks. While Passwork claims a European presence through a Spanish branch, investigations show that its office in Barcelona does not house software developers; instead, the address is occupied by ‘Russian lawyers’ who deal with residence permits and company setups [1]. Additionally, up until August 2026, the Spanish branch of Passwork received technical support and updates directly from Dubai [1]. Although the Spanish owner, Alexander Muntyan, claims that the ‘umbilical cord’ to the Russian branch is being cut after August 2026, cybersecurity experts remain highly sceptical [1]. Ronald Prins, a prominent cybersecurity expert, warned that it is ‘a bit naive to think that the use of the software is thereby safe’ [1].
The Growing Threat of Silent Digital Warfare
The potential for exploitation has triggered urgent warnings from security officials. Chris van ‘t Hof, director of the Dutch Institute for Vulnerability Disclosure (DIVD), emphasised the asymmetric nature of modern cyber warfare, stating that a threat actor can cause immense damage remotely in a very short time, making attribution incredibly difficult [1]. Van ‘t Hof remarked, ‘It is a great miracle that it has not happened yet. This will go wrong at some point’ [1]. The Dutch government has already taken steps to mitigate such risks; since 2023, it has advised civil servants not to install apps from countries with an offensive cyber programme, including Russia, following a 2018 decision to stop using Kaspersky software [1]. This latest investigation is expected to trigger urgent procurement reviews and stricter digital sovereignty regulations for SaaS vendors operating within the Benelux public sector [1].