Back
Alleged Core Qilin Ransomware Member Arrested in Japan, Extradited to Germany
SiTech AI Team2 min read

Alleged Core Qilin Ransomware Member Arrested in Japan, Extradited to Germany

Japanese authorities arrested a 28-year-old Russian national alleged to be a core member of the Qilin ransomware group in Osaka and extradited him to Germany over a ransomware attack on a German company.

Arrest and Extradition

Japanese authorities have arrested a 28-year-old Russian national alleged to be a core member of the Qilin ransomware group in Osaka and extradited him to Germany. The suspect was apprehended last May in the western Japanese city, according to The Japan Times.

Germany had been searching for the man in connection with a ransomware attack that caused serious damage to a German company. The extradition is considered surprising because Japan and Germany do not have an extradition treaty. In addition, Japanese extradition law prohibits the extradition of suspects who are to be prosecuted in Japan or who have not yet served their sentence.

Qilin's Ransomware-as-a-Service Model

Qilin is a ransomware-as-a-service operation that first appeared in 2022 and is believed to be based in Russia, although the physical locations and identities of its core operators have not been officially confirmed. The group is considered one of the most active ransomware operations.

Under its double extortion scheme, Qilin operators develop and provide ransomware and digital infrastructure to affiliates. The affiliates use these tools to break into victim networks, steal sensitive data, and encrypt systems and files. Attackers then demand a ransom in exchange for a decryption key and threaten to release the stolen data on the dark web if the victim refuses to pay. Once the extortion money is received, the proceeds are split between the affiliates and the operators.

Scale of Qilin's Operations

Cybersecurity firm NCC Group recorded 1,022 cyberattacks carried out by Qilin in 2025. North America was the most targeted region, accounting for 56% of all attacks, followed by Europe at 22% and Asia at 12%. Check Point recorded 279 victims in the second quarter of 2026 alone, making Qilin the most prolific ransomware operation for four consecutive quarters. Rapid7 researchers estimated that Qilin made approximately $193 million between July 2025 and March 2026.

Over the years, Qilin has attacked many companies worldwide, including Asahi Holdings, Volkswagen, Nissan, MedImpact, Tulsa International Airport, Malaysia Airlines, and Scientology.

Sources: Cybernews

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.