PolicyMedium

Alleged Qilin ransomware member arrested in Japan, extradited to Germany

A 28-year-old Russian national described as a core Qilin member was detained in Osaka in May and handed over to German authorities on October 2.

Alleged Qilin ransomware member arrested in Japan, extradited to Germany

At a glance

  • The 28-year-old Russian suspect was detained in Osaka, Japan, in May and transferred to Germany on October 2.
  • Germany wants him over a September 2024 attack on a logistics company that was encrypted and extorted for more than $160,000 in cryptocurrency.
  • Qilin, also known as Agenda, has operated since 2022 and is linked to attacks such as Synnovis and Asahi.
  • No official statement from German or Japanese authorities is cited in the report.

A 28-year-old Russian national described as a core member of the Qilin ransomware operation has been extradited from Japan to Germany to face hacking charges, SecurityWeek reported on October 7, citing a report by Cypro. The suspect was detained in Osaka in May and handed over to German authorities on October 2.

What happened

According to SecurityWeek, Germany is seeking the suspect over a September 2024 intrusion at a logistics company in which data on the firm's systems was encrypted and more than $160,000 in cryptocurrency was extorted. The publication did not name the German authorities handling the case, list the formal charges or give the exact date of the arrest in Japan. The report does not include statements from officials, investigators or the suspect's representatives, and the details have not been independently confirmed by other outlets at the time of writing.

Who is Qilin

Qilin, also tracked as Agenda, has been active since August 2022 and is described by SecurityWeek as one of the most prolific ransomware-as-a-service (RaaS) operations, with hundreds of victims worldwide. The group was blamed for the 2024 attack on pathology provider Synnovis that disrupted several London NHS hospitals, and in 2025 it claimed the attack on Japanese brewer Asahi Group, which the publication says compromised the personal information of roughly 2 million people.

SecurityWeek also notes that Qilin listed around 400 victims on its leak site in 2025, exploited a critical authentication bypass in Check Point VPN and firewall products (CVE-2026-50751) in June 2026, and was named on its leak site in connection with a cyberattack on the US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF), which the agency confirmed in August 2026.

Why it matters

Arrests of ransomware operators are rare because many suspects live in countries that do not extradite their citizens. A detention in a third country followed by extradition shows how international travel can expose members of Russian-speaking cybercrime groups to prosecution. As a RaaS operation, Qilin relies on affiliates, so a single arrest is unlikely to halt its activity, but it may give investigators insight into the group's infrastructure and members.

Organizations should continue to treat Qilin as an active threat: patch internet-facing VPN and firewall appliances quickly, enforce multi-factor authentication on remote access, keep offline and tested backups, and monitor for data exfiltration ahead of encryption.

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.