Federal aviation workers received an order last week. Install this app. No choice. The directive came from higher up. It involved software tied to a $1.4 million contract. And inside that code sat pieces built by a company founded in Russia.
The revelation has sent ripples through government tech circles. Security experts spotted the connection quickly. TechRadar first reported the details on July 19, 2026. Their story laid out how Elfsight, started in the Russian city of Tula, still operates an active entity there. This happened even as U.S. sanctions bite harder than ever.
Andrey Yusupov serves as chief executive. Vladimir Fedotov acts as chief technology officer. The pair launched Elfsight back in 2016. The firm now pitches itself as based in Andorra. Its European face looks clean. Yet the original Russian operation reported 126.5 million rubles in revenue for 2025. That’s about $1.6 million. A 71 percent jump from the year before. Staff numbers climbed to 61. Hiring ads for Moscow-based roles appeared as recently as this year.
One posting sought a support specialist. Salary ranged from 60,000 to 100,000 rubles monthly. Full time. In Russia. Under local law, such firms must store user data domestically. Authorities can demand access. An Elfsight support representative told investigators the company had “never received any request” from Russian officials. Comforting words. But trust remains thin in these matters.
Atomic Computer, a security outfit, ran network tests on the app. Their analysis showed Elfsight servers deciding which JavaScript files executed inside the White House tool. Cookies flowed freely. More than ten from Elfsight alone. Google DoubleClick domains joined the mix through the app’s YouTube features. Data trails multiplied. Federal phones suddenly carried extra baggage.
Olivia Wales speaks for the White House. She stated the app “does not request or collect any user locations.” All information stays “safe and secure,” she added. A second official went further. Elfsight’s script now handles only a tax calculator. It runs inside a sandboxed webview. No access to cookies or local files. The vendor cleared a full security review. Big names use it too. UFC. FIFA. The NBA. Cartier.
Those credentials carry weight in corporate boardrooms. On government devices carrying sensitive aviation data, they raise eyebrows. The founders kept accounts at banks hit by sanctions. They continued trips to Russia. One even mentioned a summons from tax authorities linked to another investment. Private messages captured these details. Exposure lingers.
Relations between Washington and Moscow hit new lows after 2022. Sanctions lists grew long. Tech ties faced extra scrutiny. Yet this app slipped through. No one from the White House or Elfsight has explained the approval process in clear terms. Questions pile up. How did a vendor with such roots pass muster for mandatory installation across federal fleets?
The app itself serves communication needs. It pushes updates from the administration. FAA staff handle critical infrastructure. Their devices process flight paths, safety alerts, regulatory filings. Introducing external code from a foreign-linked firm invites risk. Even sandboxed. Even reviewed. Potential for supply chain compromise stays real.
Elfsight isn’t alone in this gray zone. Many software makers maintain dual presences. Headquarters in the West. Talent and operations in lower-cost regions. Geopolitics complicates those arrangements. Russian developers contribute code. U.S. agencies consume it. The gap between policy and practice widens.
Industry watchers point to broader patterns. Government procurement often favors speed and cost. Vetting supply chains takes time. Third-party libraries hide in plain sight. JavaScript snippets load dynamically. Servers control behavior long after initial approval. Static reviews miss dynamic threats.
But. This case hits different. It’s not some obscure library. It’s a prominent app. On government phones. With direct ties to a nation under heavy sanctions. The revenue growth in Russia during wartime adds sting. Headcount expansion signals commitment. Not divestment.
White House assurances focus on current setup. The tax calculator stays isolated. No location data. Secure. Those statements satisfy some. Others demand code audits. Independent verification. Proof that no back channels remain. Sandbox or not, trust eroded once the Russian link surfaced.
Federal workers didn’t volunteer for this. The order was mandatory. Pushback surfaced quietly in internal channels. Some questioned the necessity. Others worried about personal data. Phones issued by agencies carry two lives. Official duties. Personal messages. Blurring lines creates headaches.
TechRadar drew its findings from The Newsground’s original reporting. That piece traced the ownership threads. It highlighted persistent Russian operations. No major outlets have published follow-ups with fresh disclosures since the July 19 article. Searches across the web and X, formerly Twitter, turned up mostly shares of the same story. No new statements from Elfsight. No congressional inquiries announced yet.
The silence speaks volumes. Agencies prefer to contain such stories. Admit the lapse. Then move on. Yet for cybersecurity professionals guarding federal systems, the incident offers a teaching moment. Vendor due diligence must extend beyond the surface. Ownership history. Legal jurisdictions. Data sovereignty laws. All factor in.
Consider the mechanics. Elfsight provides widgets. Embeddable tools. Popular for websites. The White House integrated one or more. Over time, dependencies grew. What began as a simple add-on became core. Dynamic loading from external servers followed. Control shifted. Atomic Computer’s discovery confirmed the extent.
Defenders note that many American firms use overseas talent. Irish headquarters. Indian engineers. Similar structures. The difference here is Russia. Active conflict. Espionage concerns at peak levels. Laws requiring cooperation with intelligence services. The risk profile changes.
So the app stays. Workers comply. Reviews continue. And questions hover. Can a $1.4 million investment justify the exposure? Did procurement skip key checks? Will this prompt tighter rules on foreign code in government tools?
Answers may come slowly. In the meantime, thousands of federal mobiles run the software. Russian-founded code sits inside. Sandboxed, reviewed, and declared safe. The episode underscores a stubborn truth. In software supply chains, origins matter. Connections persist. And oversight gaps invite exactly these surprises.


WebProNews is an iEntry Publication