At least three Irish State agencies have been using password software connected to a Russian technology company that is licensed by Moscow’s intelligence service, according to an investigation by The Irish Times. The report says the software was involved in the handling of sensitive information within parts of the public sector.

The findings focus on the software’s links to the Russian company rather than alleging a specific breach. Even so, the reported use of a password management tool with such connections is likely to raise fresh questions about security checks, procurement rules and the assessment of technology suppliers used by government bodies.

Password software is often central to managing access to internal systems and protected data, which is why the origin and ownership of these tools can draw close scrutiny. In this case, the investigation indicates that the software was in use across multiple agencies, extending the significance of the issue beyond a single department or office.

The report adds to wider concerns across Europe about cyber risk, supply-chain exposure and the use of software with links to states seen as security threats. In Ireland, attention is now likely to turn to how the software was approved, where it was deployed and whether any changes will be made to reduce potential risk.