Back to Feed
RansomwareOct 7, 2026

Qilin Ransomware Suspect Arrested in Japan, Extradited to Germany

Qilin ransomware suspect arrested in Japan and extradited to Germany.

Summary

A 28-year-old Russian national, believed to be a core member of the Qilin ransomware group, has been arrested in Japan and extradited to Germany. The suspect faces charges for a ransomware attack on a logistics company that resulted in over $160,000 in cryptocurrency extortion. Qilin, also known as Agenda, has been active since August 2022 and is responsible for numerous attacks worldwide, including incidents affecting Synnovis, London hospitals, and Asahi Group.

Full text

An alleged member of the Qilin ransomware group was arrested in Japan and subsequently extradited to Germany. The suspect, a 28-year-old Russian national, was detained in Osaka in May and was reportedly handed over to the German authorities on October 2. Believed to be a core member of the ransomware gang, the individual was wanted in Germany for hacking into a logistics company in September 2024, encrypting data on its systems, and extorting it of over $160,000 in cryptocurrency. Also known as Agenda, Qilin has been active since August 2022 and has become one of the most prolific ransomware-as-a-service (RaaS) operations, hitting hundreds of organizations worldwide and causing millions of dollars in damages. In 2024, the group was blamed for hacking into pathology lab services provider Synnovis and causing disruptions at multiple London hospitals run by the National Health Service. Last year, Qilin claimed responsibility for hacking beer giant Asahi Group. The incident caused operational disruptions and resulted in the personal information of roughly 2 million people being compromised.Advertisement. Scroll to continue reading. Throughout 2025, the group listed 400 victims on its Tor-based leak site, including Lee Enterprises and pharma company Inotiv. In June this year, Qilin was exploiting a critical authentication bypass vulnerability in Check Point VPN and firewall products, tracked as CVE-2026-50751. In August, the US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed it had fallen victim to a cyberattack after Qilin added it to its leak site. Related: FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware Related: Alleged ShinyHunters Leader Arrested in Jordan Related: In Rare Move, Alleged Iranian State Hacker Extradited to US Related: Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM MalwareApple to Tighten Full Disk Access Controls in macOS Amid AI RisksLong-Running NPM Malware Campaign Accumulates 40,000 Downloads8.8 Million Impacted by Data Breach at Denmark’s Central Person RegisterLinux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare FirmsExploitation Hits Rejetto HFS Vulnerability Discovered by AI Alleged ShinyHunters Leader Arrested in Jordan Latest News Hadrian Raises $40 Million to Expand Autonomous Offensive Security PlatformAdvantest Discloses Data Breach Months After Ransomware AttackChrome 155 Update Patches 247 VulnerabilitiesAnthropic Introduces 3-Tier Cyber Verification Program for AI AccessASOS Confirms Cyberattack, Data BreachWikimedia Says Rogue OpenAI Agents Tried to Turn Its Tools Into ProxiesAndroid’s October 2026 Updates Patch 25 VulnerabilitiesAtlassian Patches Critical Vulnerability Affecting 8 Products Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveChip Wentz has been appointed as SVP & CISO at Keurig Dr Pepper Inc.Lumen Technologies has named Kim Keever as CSO.Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.More People On The MoveExpert Insights AI Has Changed Attack Speed, Not Security Fundamentals As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. (Joshua Goldfarb) Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • malware — Qilin
  • malware — Agenda
  • cve — CVE-2026-50751

Entities

Qilin (threat_actor)Agenda (threat_actor)Check Point VPN (product)