European password manager Passwork appears to be Russian

Researchers found a password manager that was promoted as European, but in reality has ties with the Russian intelligence agency FSB. This makes European businesses and organizations vulnerable to malicious hacks, cybersecurity experts say.
This became evident after a study by Investico, a Dutch platform for investigative journalism.
Several Dutch news outlets, including NU.nl and De Groene Amsterdammer, participated in this project, as well as Belgian newspaper De Tijd, French newspaper Le Monde, and the Organized Crime and Corruption Reporting Project (OCCRP).
Passwork claims to be made and developed in Europe, thereby fully complying with Europe’s privacy and data protection laws, such as the GDPR and NIS2 Directive.
Originally, the company was founded in 2014 in Russia. A few years later, a subsidiary was opened in Finland. However, due to the Russian invasion of Ukraine, the subsidiary was closed. Since then, Passwork has been sold to European customers via a shell company in Barcelona.
What the owners kept secret from the public is that the company is also active in Russia and is used, among others, by state-owned enterprises like Gazprom, the Russian intelligence service FSB, and the Ministry of Defense.
To serve European companies, Passwork holds licenses from the Kremlin. Before handing out these licenses, the Russian government demands detailed information about Passwork’s clients.
What cybersecurity experts fear the most is that Russia could exploit software vulnerabilities to target European companies.
“I don’t think it’s wise to hand over the digital keys to your home to a party like that. That’s far too dangerous,” Bart van den Berg, Head of the Security Unit at The Clingendael Institute, tells Investico.
Nevertheless, Passwork was used by numerous European businesses and organizations, including French ports, German and Irish government organizations, universities, and Novar, one of the largest builders and operators of solar farms in the Netherlands.
According to experts, companies like Novar are an attractive target for foreign powers such as Russia. Anyone who manages to gain control of enough solar panels can cause a large-scale power outage.
“This is much more effective than an airplane or a bomb,” Chris van ‘t Hof, Founder and Managing Director of the Dutch Institute for Vulnerability Disclosure (DIVD), says in an interview with Investico.
After hearing the news, Novar immediately took Passwork offline and changed its passwords. The company also filed a report with the National Cyber Security Centre (NCSC-NL) and the industry association Holland Solar.
There are no indications that Passwork has been compromised or that Russia has access to passwords or other data. However, experts recommend that we should at least be aware of the risks. Even if passwords are stored locally or if customers host the service themselves, a connection still needs to be made to a central server to verify whether customers have a subscription and to install updates.