Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Ransomware » Japan Extradites Alleged Qilin Ransomware Leader to Germany

Japan Extradites Alleged Qilin Ransomware Leader to Germany

By:
Last updated:October 8, 2026
Human Written
  • Japan held a 28-year-old Russian man in Osaka. Police suspect he is a key member of the Qilin ransomware group.

  • Germany blames him for a 2024 attack on a logistics firm. The attackers demanded about $165,000 in Bitcoin.

  • Japan sent him to Germany on October 2. The Tokyo High Court approved his transfer first.

Japan Extradites Russian Man to Germany Over Alleged Qilin Ransomware Role

Japanese police detained a 28-year-old Russian man in Osaka in late May 2026. Investigators suspect he is a core member of the Qilin ransomware group. German officials had asked Japan to hold him and send him to Germany.

They link him to a ransomware attack on a German logistics company from September 2024. The Tokyo High Court reviewed the case and approved the extradition. Japan then handed the man over to German authorities on October 2, as reported by TV Asahi.

German and Japanese authorities believe the suspect broke into computer terminals at the logistics firm. They say he stole data and then locked it with encryption. The attackers then demanded roughly $165,000 in Bitcoin. They threatened to leak the stolen files if the company refused to pay.

Investigators also suspect the man helped build tools for Qilin’s ransomware system. They believe he received a share of the money from other Qilin attacks too. This suggests he held more than a small role in the group.

Two Japanese outlets independently confirmed parts of this story. TV Asahi reported the arrest and the later handover to Germany. ITmedia, citing the Sankei Shimbun newspaper, also reported the October transfer. Both reports agree on his age, his nationality, and his arrest location. They also agree that German investigators are now leading the case.

Qilin Pays Partners to Run Its Attacks

Qilin does not work alone. It runs on a model called ransomware-as-a-service. Under this setup, the core group builds the malicious software and the systems behind it. Other attackers, often called affiliates, then use these tools to break into victims’ networks. When a victim pays a ransom, the affiliate and the core Qilin team split the money.

This setup has helped Qilin grow fast. According to Japan Cyber Watch, reporting from The Asahi Shimbun cited data from the security firm Mitsui Bussan Secure Directions. That data reportedly showed Qilin listed 161 victims on its leak website in August 2026 alone.

This number was the highest among roughly 370 ransomware groups the firm tracks. It shows Qilin was more active than almost any other ransomware gang that month.

Experts warn that one arrest does not stop a whole network like this. Many affiliates can keep attacking even without the core team. Researchers also caution against assuming too much about the suspect. His alleged role inside Qilin does not prove he personally carried out every attack linked to the group, Japan Cyber Watch noted.

Qilin Also Struck Japan’s Asahi Group Last Year

This case has drawn extra attention inside Japan for another reason. Qilin claimed responsibility for a major cyberattack on Asahi Group Holdings in September 2025. The attack later became one of the group’s major reported incidents in Japan, with the ransomware gang claiming responsibility for the attack on Japan’s Asahi Group; the breach impacts 1.5 million covering the reported impact in greater detail. Asahi is one of Japan’s biggest beverage and food companies.

That attack disrupted Asahi’s order systems, its shipments, and other daily operations. Reuters reported that Qilin later claimed it had stolen about 27 gigabytes of company data. However, independent outlets said these claims could not be confirmed right away. Asahi’s recovery took time, and the company later postponed a financial results announcement because of the attack, according to Reuters.

The Japan Times also covered the fallout from the Asahi incident at the time. These reports show how disruptive a single Qilin attack can be for a large company.

What Happens Next

This extradition marks a real step forward for law enforcement against Qilin. Still, the suspect has not yet been proven guilty in a courtroom. Germany now holds the case and will lead the next stages of the investigation.

The case also shows how spread out ransomware crime has become. The alleged attack happened in Germany. Japan found and held the suspect. German officials will now handle his prosecution. Three countries’ systems had to work together to reach this point.

For now, these remain allegations only. More facts should come out as the German investigation and any court case move forward. People should watch for updates rather than assume guilt before a trial decides it.

Share this article

About the Author

Joahn G

Joahn G

Cyber Threat Journalist

Joahn is a cyber threat journalist dedicated to tracking the evolving landscape of digital risks. His reporting focuses on ransomware gangs, data breach incidents, and state-sponsored cyber operations. By analyzing threat actor motives and tactics, he provides timely intelligence that helps readers understand and anticipate the security challenges of tomorrow.

View all posts by Joahn G >
Comments (0)

No comments.