Germany Arrests Suspected Qilin Ransomware Leader After Japan Detention

Pierluigi Paganini October 09, 2026

Japan helped extradite a Russian suspect linked to Qilin ransomware to Germany, but the gang continued attacking victims after his arrest.

Germany has arrested a Russian national believed to be a leading figure in the Qilin ransomware group, and Japan’s National Police Agency just put its own role in that arrest on the record. The suspect was detained in Japan back in May, at a hotel in Osaka, while traveling as a tourist.

“In connection with a ransomware incident in Germany, German authorities had obtained an arrest warrant for a Russian national suspected of involvement in the attack. When the suspect arrived in Japan, the Japanese authorities worked with the Ministry of Justice, the Tokyo High Public Prosecutors Office, and German authorities to detain him under a provisional detention warrant, in accordance with Japan’s Act of Extradition.” reads a full NPA statement in Japanese. “The Japanese authorities subsequently handed the suspect over to Germany in accordance with the procedures established by that law. These actions contributed to the case.”

Germany already had an arrest warrant out for the man over a ransomware incident on German soil. When he showed up in Japan, Japanese authorities moved fast. Per the NPA’s own account, Japan’s Ministry of Justice, the Tokyo High Public Prosecutors Office, and German authorities worked together to detain him under Japan’s extradition law, using a provisional detention warrant, before handing him over to Germany through the proper legal process.

The NPA statement does more than confirm the arrest. It specifically recognizes the work of the Kanto Regional Police Bureau’s Cyber Special Investigation Unit and other local police forces. They had been investigating Qilin ransomware attacks in Japan and working with German investigators on the wider case. The agency stressed that international cooperation is essential to investigating cybercrime, including ransomware attacks that affect countries around the world.

Japan has good reason to focus on Qilin. The group has attacked Japanese organizations, including carmaker Nissan and brewing company  Asahi. The attack on Asahi disrupted its operations for an extended period and exposed data belonging to 1.5 million people. Japan has been directly affected by the group, so its role in the investigation and the suspect’s extradition is significant.

Qilin ransomware operation has been active since 2022, it has become one of the most active RaaS groups in 2025, claiming over 40 victims monthly and peaking at 100 in June.

The group enables affiliates to deploy customized ransomware payloads against targeted organizations. Qilin uses double-extortion tactics, encrypting data while threatening to leak it via Tor-based portals. The group has targeted multiple sectors worldwide, including healthcare, manufacturing, and finance, leveraging phishing and known vulnerabilities.

In October 2025, Resecurity’s researchers detailed how the Qilin RaaS group relies on global bulletproof hosting networks to support its extortion operations.

In early October, DragonForce, LockBit, and Qilin formed a ransomware alliance to boost attack effectiveness, marking a major shift in the cyber threat landscape. Ransomware groups DragonForce, LockBit, and Qilin formed a strategic alliance to enhance their attack capabilities, signaling an evolving cyber threat landscape. The alliance aims at sharing tools and infrastructure to enhance attack effectiveness. 

At the end of March, Qilin Ransomware group allegedly breached the chemical manufacturing giant Dow Inc. 

Despite the suspect’s detention in May, the cybercrime group has listed hundreds of new victims on its Tor leak site since June alone.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



you might also like

leave a comment