Germany arrests alleged core Qilin ransomware member after extradition
Germany arrests alleged Qilin ransomware member extradited from Japan.
Summary
Germany has arrested a Russian national suspected of being a core member of the Qilin ransomware group. The suspect was extradited from Japan, where they were initially detained upon arrival as a tourist. Qilin, formerly known as Agenda, is a notorious ransomware-as-a-service operation that has targeted over 2,350 organizations globally.
Full text
Germany arrests alleged core Qilin ransomware member after extradition By Bill Toulas October 9, 2026 11:38 AM 0 Germany has arrested a Russian national suspected of being a leading member of the Qilin ransomware group following extradition from Japan earlier this month. Japan has confirmed the extradition to Germany, with the National Police Agency saying that the suspect was detained after arriving in the country as a tourist. “When a Russian national for whom Germany had obtained an arrest warrant in connection with a ransomware incident in Germany arrived in Japan, the Japanese Ministry of Justice, the Tokyo High Public Prosecutors Office, and Germany worked together to detain the suspect under the Extradition Law for Fugitives by obtaining a provisional detention warrant, and then facilitated the extradition,” [machine translated] reads the press release. Earlier this week, Japanese media reported the arrest based on internal sources, but authorities in the country have now officially confirmed the action. Qilin is a notorious ransomware-as-a-service (RaaS) operation that emerged in August 2022 under the name Agenda, and deployed typical double-extortion attacks, where data is stolen before being encrypted. The operation became one of the most active ransomware threats worldwide. By more recent statistics, the group targeted more than 2,350 known organizations across 62 countries. Among the victims are Japanese automaker Nissan, Japanese brewery Asahi, U.S. newspaper publisher Lee Enterprises, and Australia’s Court Services Victoria. The attack on Asahi, Japan’s largest beer producer, was particularly damaging, disrupting operations for an extended period and exposing sensitive details about 1.5 million people. More recently, the threat group hit the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) and was also linked to the exploitation of Check Point VPN zero-days and Palo Alto VPN n-day flaws. According to media publications, Japan detained the alleged Qilin leading member in May at a hotel in Osaka. Despite this, the gang continued to be a major player on the ransomware stage. Since June, the group has listed more than 450 victims on its data leak site. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: Hackers arrested over €30M bank fraud exploiting service provider flawRansomware attack disrupts Japan's IDCF Cloud used by govt clientsJapan's Keio confirms ransomware attack disrupted business systemsBerlin confirms data theft after Rhysida ransomware attack claimsATF confirms “major incident” after recent Qilin breach claims
Indicators of Compromise
- malware — Qilin
- malware — Agenda