A suspected key member of the Qilin ransomware group has been extradited from Japan to Germany following an international investigation into cyberattacks against businesses. The 28-year-old Russian national was detained while visiting Japan and is now in German custody facing allegations of cybercrime and extortion.
Japanese authorities arrested the suspect at a hotel in Osaka in May 2026 after receiving information from German investigators. Following legal proceedings, the Tokyo High Court authorized his extradition, and he was transferred to Germany on October 2.
Investigators believe the man played an important role in Qilin’s operations, particularly in developing and maintaining the infrastructure used to conduct ransomware attacks. Reports also suggest he received a share of the money collected from victims.
The German investigation centers on a September 2024 cyberattack against an unnamed logistics company. According to investigators, the attackers accessed the company’s computer systems, stole information, and encrypted files before demanding approximately $165,000 in cryptocurrency.
The criminals allegedly threatened to publish the stolen information unless their demands were met. This method, commonly called double extortion, puts additional pressure on victims by combining system disruption with the possibility of a data leak.
Qilin, also known as Agenda, has operated since 2022 and is considered one of the most active ransomware groups. It follows a ransomware-as-a-service model, providing malicious software and attack infrastructure to affiliates who carry out intrusions and share their proceeds with the operators.
The group has been linked to major incidents worldwide, including the 2024 attack on pathology services provider Synnovis, which disrupted healthcare services at London hospitals. Qilin also claimed responsibility for a 2025 cyberattack against Japanese beverage company Asahi Group Holdings.
Japanese police say Qilin has affected approximately 4,000 organizations worldwide since it began operating. Its targets have included businesses, hospitals, schools and government-related organizations.
The suspect’s detention followed cooperation between German authorities and several Japanese law enforcement agencies. Investigators identified his planned visit to Japan and coordinated efforts to locate him before carrying out the arrest.
The extradition represents a significant development in international efforts to pursue ransomware operators across national borders. However, authorities have not announced that Qilin’s wider infrastructure has been dismantled.
The suspect remains accused rather than convicted, and his precise involvement in individual attacks will need to be established through legal proceedings. Meanwhile, Qilin continues to pose a threat to organizations worldwide.
