Qilin ransomware suspect arrested in Japan, sent to Germany
A man believed to be part of the Qilin ransomware operation has been arrested in Japan and extradited to Germany, where prosecutors want him for an attack on a logistics firm.
The suspect is a 28-year-old Russian national. Japanese authorities detained him in Osaka in May. According to reports, he was transferred to German custody on October 2.
German investigators consider him a core member of the gang, not a peripheral affiliate. The arrest is one of the more notable law enforcement actions against a major ransomware-as-a-service (RaaS) brand this year.
The German case
The extradition request relates to an intrusion at a logistics company in September 2024. The attackers broke into the firm's network, encrypted data on its systems and then demanded payment. The company was extorted out of more than $160,000, paid in cryptocurrency.
Neither the name of the logistics company nor the suspect's identity has been made public.
Who is Qilin?
Qilin, also tracked as Agenda, first appeared in August 2022. It runs as a RaaS operation, which means the core group develops and maintains the ransomware and leak infrastructure while affiliates carry out attacks in exchange for a share of the ransom.
The model has worked well for the group. Qilin has hit hundreds of organizations around the world and caused damages in the millions of dollars.
Some of its attacks have had effects far beyond the victim's own network:
- Synnovis (2024): Qilin was blamed for the attack on the pathology lab services provider, which disrupted several London hospitals run by the National Health Service (NHS), the UK's publicly funded healthcare system.
- Asahi Group (2025): The group claimed the attack on the Japanese beer maker. The incident disrupted operations and exposed personal information of roughly 2 million people.
- Leak site activity (2025): Over the year, Qilin posted 400 victims on its Tor-based leak site, among them media company Lee Enterprises and pharmaceutical firm Inotiv.
The gang has stayed active in 2026. In June, it was exploiting CVE-2026-50751, a critical authentication bypass flaw in Check Point VPN and firewall products. In August, the US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF), a federal law enforcement agency, confirmed it had suffered a cyberattack after Qilin listed it on its leak site.
Part of a wider crackdown
The Qilin arrest comes during a busy stretch for police work against cybercriminals. In recent weeks, the alleged developer of the Ploutus ATM malware appeared in a US court, and authorities took action against the KillSec ransomware operation, identifying a 16-year-old suspected leader.
The route this case took is worth noting. The suspect was not picked up in Germany or in his home country, but in Japan, and then handed over across borders.
Our Take
This case suggests that travel remains one of the biggest risks for ransomware operators based in Russia. Many of them are hard to reach at home, but once they enter a country willing to cooperate with European or US investigators, an outstanding warrant can turn into an arrest. A similar pattern played out recently when an Iranian hacker was extradited from Montenegro.
For defenders, one arrest is unlikely to shut Qilin down. RaaS groups spread work across many affiliates, and the gang was still exploiting fresh Check Point flaws this summer. Organizations running Check Point VPN and firewall products should make sure CVE-2026-50751 is patched.
It is worth watching whether German prosecutors link the suspect to other Qilin attacks, and whether information from the case leads to further arrests or disruption of the group's infrastructure.
