A suspected member of the Qilin ransomware group has been arrested in Japan and extradited to Germany, where he is expected to face charges related to cyberattacks and ransomware extortion. The case is important as it reveals a growing international effort to identify and prosecute individuals involved in major ransomware operations.
According to a report by SecurityWeek, the suspect is a 28-year-old Russian national who was arrested in Osaka, Japan, in May 2026. German authorities accuse him of playing a role in the Qilin ransomware operation, which has targeted organizations in several countries.
The suspect was extradited to Germany on October 2, 2026, following legal proceedings in Japan. German investigators allege that he was involved in an attack against a logistics company in September 2024.
Ransomware attack
Investigators say the targeted logistics company had its computer systems encrypted during the attack. The attackers allegedly demanded more than $160,000 in cryptocurrency in exchange for restoring access to the affected systems.
The incident is believed to have been connected to the Qilin ransomware operation, also known as Agenda. Qilin emerged as a ransomware-as-a-service (RaaS) operation in 2022. Under this model, ransomware developers provide malware and infrastructure to affiliates, who conduct attacks against victims and share the proceeds with the operators.
This business model has allowed ransomware groups to expand their operations without every attacker needing to develop their own malware or infrastructure.
Qilin's global activity
Qilin has become one of the more active ransomware groups in recent years. It has targeted organizations across different industries, including healthcare, manufacturing, professional services and other critical sectors.
The group attracted international attention after attacks linked to it disrupted healthcare services in the United Kingdom. It was associated with the 2024 attack against Synnovis, a medical services provider whose systems were used by several London hospitals. The incident caused significant disruption to healthcare operations.
Qilin has also been linked to attacks against major companies in other countries, demonstrating the international reach of the ransomware operation.
Experts have continued to track the group's activities and techniques. In 2026, Qilin was also reported to have exploited a critical vulnerability affecting Check Point security products as part of its attack activity.
Read the original article:
