GERMANY has arrested a Russian national suspected of leading the Qilin ransomware operation, following his detention in Japan earlier this year. Japanese authorities detained him in Osaka in May under a provisional detention warrant as he travelled as a tourist, and subsequently handed him over to Germany under extradition procedures. The German arrest aligns with an existing warrant over a ransomware incident on German soil.
Japan’s National Police Agency (NPA) confirms the transfer and credits international cooperation with German authorities, the Tokyo High Public Prosecutors Office, and the Ministry of Justice for detaining the suspect and facilitating extradition. The NPA emphasises that effective cross-border cooperation is crucial in pursuing ransomware suspects.
Qilin ransomware has been active since 2022 and operates as a ransomware as a service (RaaS) model, with affiliates deploying customised payloads and employing double-extortion tactics—encrypting data and threatening leakage via Tor-based portals. The group has targeted a range of sectors worldwide, including healthcare, manufacturing and finance, and has previously disrupted Japanese organisations such as Nissan and Asahi, exposing data from about 1.5 million people.
In 2025, Qilin reportedly averaged dozens of victims per month and spiked to around 100 in June, while continuing to publish new victims on its Tor leak site after the May detention. Observers have noted that Qilin benefited from global bulletproof hosting networks to support its operations, and that late-2025 saw a renewed alliance with DragonForce and LockBit to enhance attack capabilities.