Qilin hacker caught in Japan and handed over to Germany
The suspect’s visit to Japan ended with a one-way trip to Germany.

- Japanese authorities arrested a 28-year-old Russian alleged core Qilin member in Osaka and extradited him to Germany.
- Germany sought the suspect over a ransomware attack that seriously damaged a German company.
- Qilin runs ransomware for affiliates, who steal data, lock systems, and demand payment.
- Researchers tied Qilin to 1,022 attacks in 2025 and an estimated $193 million in revenue.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Law enforcement authorities in Japan have apprehended an alleged core member of the ransomware extortion group Qilin. He has been extradited to Germany.
The suspect is said to be a 28-year-old Russian national who’s believed to be a key member of Qilin, one of the most active ransomware operations as of writing.
According to Japanese news outlet The Japan Times, the man was arrested last May in the western city of Osaka.
Sources say that Germany had been searching for the man in connection with a ransomware attack that caused serious damage to a German company.
At Germany's request, the Russian national has been extradited.
According to German news outlet Heise, this is surprising because Japan and Germany don’t have an extradition treaty. Furthermore, Japanese extradition law prohibits the extradition of suspects who are to be prosecuted in Japan or who haven’t served their sentence yet.
Qilin is a so-called ransomware-as-a-service (RaaS) operation that first appeared in 2022. The group is believed to be based in Russia, although the physical locations and identities of its core operators aren’t officially confirmed.
According to cybersecurity experts, Qilin employs a double extortion scheme. Qilin operators develop and provide ransomware and digital infrastructure to affiliates. They use it to break into a victim’s network, steal sensitive data, and encrypt systems and files.
Has your password leaked?
Next, the attackers demand a ransom in exchange for a decryption key. If the victim refuses to pay, the hackers threaten to release the stolen data on the dark web. Once the attackers have received the extortion money, they split the proceeds with the operators.
Over the years, Qilin has attacked many companies worldwide, including Asahi Holdings, Volkswagen, Nissan, MedImpact, Tulsa International Airport, Malaysia Airlines, and Scientology.
Cybersecurity firm NCC Group recorded 1,022 cyberattacks that were carried out by Qilin in 2025. North America was the most targeted region, accounting for 56% of all cyberattacks. Europe represented 22% of claimed incidents, followed by Asia at 12%.
Cybersecurity firm Check Point recorded 279 victims in Q2 2026 alone, making Qilin the most prolific ransomware operation for four consecutive quarters.
Rapid7 researchers noted that Qilin made an estimated $193 million between July 2025 and March 2026.