
Alleged Core Qilin Ransomware Member Arrested in Japan, Extradited to Germany
Japanese authorities arrested a 28-year-old Russian national alleged to be a core member of the Qilin ransomware group in Osaka and extradited him to Germany over a ransomware attack on a German company.
Arrest and Extradition
Japanese authorities have arrested a 28-year-old Russian national alleged to be a core member of the Qilin ransomware group in Osaka and extradited him to Germany. The suspect was apprehended last May in the western Japanese city, according to The Japan Times.
Germany had been searching for the man in connection with a ransomware attack that caused serious damage to a German company. The extradition is considered surprising because Japan and Germany do not have an extradition treaty. In addition, Japanese extradition law prohibits the extradition of suspects who are to be prosecuted in Japan or who have not yet served their sentence.
Qilin's Ransomware-as-a-Service Model
Qilin is a ransomware-as-a-service operation that first appeared in 2022 and is believed to be based in Russia, although the physical locations and identities of its core operators have not been officially confirmed. The group is considered one of the most active ransomware operations.
Under its double extortion scheme, Qilin operators develop and provide ransomware and digital infrastructure to affiliates. The affiliates use these tools to break into victim networks, steal sensitive data, and encrypt systems and files. Attackers then demand a ransom in exchange for a decryption key and threaten to release the stolen data on the dark web if the victim refuses to pay. Once the extortion money is received, the proceeds are split between the affiliates and the operators.
Scale of Qilin's Operations
Cybersecurity firm NCC Group recorded 1,022 cyberattacks carried out by Qilin in 2025. North America was the most targeted region, accounting for 56% of all attacks, followed by Europe at 22% and Asia at 12%. Check Point recorded 279 victims in the second quarter of 2026 alone, making Qilin the most prolific ransomware operation for four consecutive quarters. Rapid7 researchers estimated that Qilin made approximately $193 million between July 2025 and March 2026.
Over the years, Qilin has attacked many companies worldwide, including Asahi Holdings, Volkswagen, Nissan, MedImpact, Tulsa International Airport, Malaysia Airlines, and Scientology.
Sources: Cybernews
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.