An investigation by OCCRP reveals that several Dutch organizations unknowingly utilized a password manager with concealed Russian origins. The software, marketed as a secure solution for managing credentials, was developed by a company with deep ties to Russia’s security services. This hidden connection raises significant concerns about potential data breaches and espionage risks for the organizations involved, including government entities. Researchers discovered evidence linking the developers to individuals with past involvement in Russian intelligence. The password manager’s code may allow for backdoors or vulnerabilities exploitable by Russian actors. Dutch authorities have been alerted, and organizations are urged to assess their security posture and consider alternatives to the compromised software. The incident highlights the growing threat of foreign interference through seemingly legitimate technology products.