Germany arrests alleged core Qilin ransomware member after extradition

A leading member of the notorious Qilin ransomware group has been arrested in Germany following extradition from Japan, marking a significant blow to the cybercrime operation. The suspect, a Russian national, was detained in May by Japanese authorities at a hotel in Osaka, but had managed to evade capture until now.

The arrest comes after months of activity by Qilin, which has become one of the most prolific ransomware-as-a-service (RaaS) operations worldwide. Since its emergence under the name Agenda in August 2022, the group has launched devastating double-extortion attacks on over 2,350 known organizations across 62 countries. Its victims include high-profile targets such as Nissan, Asahi Brewery, and Court Services Victoria.

Qilin’s modus operandi is to steal sensitive data from its victims before encrypting it with ransomware. This approach allows the group to extort not only a ransom payment but also threatens to release stolen information if the victim refuses to pay. The attack on Asahi, Japan’s largest beer producer, was particularly damaging, disrupting operations for an extended period and exposing sensitive details about 1.5 million people.

The suspect’s extradition from Japan is a result of international cooperation between law enforcement agencies in both countries. Germany had obtained an arrest warrant for the suspect in connection with a ransomware incident in the country, and Japanese authorities worked together to detain him under the Extradition Law for Fugitives. The suspect arrived in Germany as a tourist before being detained.

Qilin’s activities have been linked to other high-profile attacks, including on the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) and the exploitation of zero-day vulnerabilities in VPN software from Check Point and Palo Alto Networks. Despite its recent setbacks, Qilin remains a significant threat to organizations worldwide.

The arrest is a welcome development for cybersecurity experts and law enforcement agencies fighting against ransomware threats. However, it serves as a reminder that these groups can be highly organized and persistent. As such, organizations must remain vigilant in their cybersecurity measures and continue to invest in robust security protocols to protect themselves from these types of attacks.


Source: Bleeping Computer — 2026-10-09