European Union institutions used a password manager advertised as a home-grown European cybersecurity product, even as it remained technically tied to software in Russia through a shared development history, synchronised updates and infrastructure linked to its original founders, an international investigation has found.
The investigation, published by the Organised Crime and Corruption Reporting Project (OCCRP) and its media partners, examined Passwork, a password management platform used by businesses, universities and public institutions across Europe.