Germany has arrested a 28-year-old Russian suspected of being a core Qilin ransomware member after Japanese authorities detained and extradited him.

Germany Arrests Alleged Qilin Ransomware Leader After Extradition From Japan

The420 Web Correspondent
6 Min Read

German authorities have arrested a 28-year-old Russian national suspected of being a leading member of the Qilin ransomware group after he was detained in Japan and extradited to Germany.

Japan’s National Police Agency confirmed that German authorities had obtained an arrest warrant in connection with a ransomware attack in Germany.

After learning that the suspect was travelling to Japan as a tourist, Japanese police located and detained him before facilitating his extradition under the country’s fugitive-transfer law.

FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals

Suspect Allegedly Linked to German Logistics Attack

German authorities suspect the man of involvement in a September 2024 ransomware attack against a German logistics company.

The company’s systems were allegedly encrypted and its stolen data used as leverage in an extortion demand.

SecurityWeek reported that the victim ultimately paid more than $160,000 in cryptocurrency.

The suspect’s name has not been publicly released.

He has not been convicted, and the allegations remain subject to German criminal proceedings.

Japan Detained Him During Tourist Visit

Japanese authorities were alerted after investigators learned that the suspect planned to enter the country.

He was detained at a hotel in Osaka in May.

Japan’s Ministry of Justice, the Tokyo High Public Prosecutors Office and German authorities then coordinated the extradition process.

The National Police Agency said the operation relied on a provisional detention warrant under Japan’s extradition law.

Japanese reporting says he was handed over to German authorities in early October.

Authorities Describe Him as a Core Qilin Member

The suspect is believed to have held a significant position within Qilin rather than simply operating as an outside affiliate.

North Rhine-Westphalia officials described the arrest as an important result of an investigation in which German authorities had infiltrated and monitored the group for months.

Qilin operates as a ransomware-as-a-service network.

Under that model, core operators maintain ransomware infrastructure while affiliates conduct intrusions and attacks.

Profits from successful ransom payments are then divided between the affiliates and the core group.

Japanese police said the detained man was believed to have been one of the figures leading the operation.

Qilin Has Become One of the Most Active Ransomware Groups

Qilin first emerged in 2022 under the name Agenda and later became one of the world’s most active ransomware operations.

The group typically steals data before encrypting a victim’s systems.

Victims are then pressured to pay both to recover encrypted files and to prevent stolen information from being published.

BleepingComputer says Qilin has targeted more than 2,350 known organisations across 62 countries, while Japanese reporting puts the broader number of affected organisations at around 4,000. Differences in these figures reflect different datasets and counting methods.

Major victims linked to Qilin have included Asahi Group, Nissan, Lee Enterprises and Court Services Victoria.

Group Remained Active After the Arrest

The suspect’s detention did not shut Qilin down.

BleepingComputer reported that the gang continued listing hundreds of victims after his May arrest, including more than 450 victims since June.

That reflects the structure of ransomware-as-a-service groups.

Removing one operator can disrupt technical knowledge, infrastructure or management, but affiliates and other administrators may continue attacks.

Qilin has also recently been linked to exploitation of vulnerabilities in Check Point and Palo Alto Networks products.

In August, the US Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed a cyber incident after Qilin claimed responsibility.

Japan Has Also Faced Qilin Attacks

Qilin has been particularly active against Japanese organisations.

Japanese authorities say the group has attacked dozens of companies, hospitals and schools in the country.

It also claimed responsibility for the 2025 attack on Asahi Group Holdings, which caused significant operational disruption.

That history made Japan’s role in the arrest particularly notable.

Instead of prosecuting the suspect domestically, Japanese authorities detained him at Germany’s request and transferred him to face charges connected with the German attack.

International Cooperation Is Becoming Central to Ransomware Enforcement

Ransomware operations frequently involve infrastructure, attackers, victims and money flows spread across several countries.

That makes prosecution difficult unless law-enforcement agencies cooperate across borders.

In this case, German investigators obtained the arrest warrant, Japanese police located and detained the suspect, and judicial authorities coordinated his extradition.

The operation shows how international travel can create opportunities to arrest ransomware suspects who may otherwise remain outside the reach of investigators.

What this means for you

The arrest is significant because investigators say they reached beyond Qilin’s affiliates and targeted someone believed to be part of the group’s core structure. But Qilin remains active, showing why arresting individual operators can weaken ransomware networks without immediately stopping their attacks.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected