LIVE · cybersecurity feed
Live wire
ransomware

Germany arrests alleged core Qilin ransomware member after extradition

German authorities have arrested a Russian national suspected of being a key member of the Qilin ransomware group. The individual was extradited from Japan earlier this month, following their initial detention in May at a hotel in Osaka.

ZeroDay News ·

Source: BleepingComputer

German authorities have arrested a Russian national suspected of being a key member of the Qilin ransomware group. The individual was extradited from Japan earlier this month, following their initial detention in May at a hotel in Osaka.

The arrest was officially confirmed by Japan's National Police Agency, which stated that the suspect was apprehended after arriving in the country as a tourist. German authorities had obtained an arrest warrant for the individual in connection with a ransomware incident that occurred in Germany. The Japanese Ministry of Justice and the Tokyo High Public Prosecutors Office collaborated with Germany to detain the suspect under the Extradition Law for Fugitives, securing a provisional detention warrant before facilitating the extradition.

Qilin, also known as Agenda, is a prominent ransomware-as-a-service (RaaS) operation that first emerged in August 2022. The group employs double-extortion tactics, stealing data before encrypting it. It has become one of the most active ransomware threats globally, reportedly targeting over 2,350 organizations across 62 countries.

Notable victims of Qilin attacks include Japanese automaker Nissan, Japanese brewery Asahi, U.S. newspaper publisher Lee Enterprises, and Australia's Court Services Victoria. The attack on Asahi, Japan's largest beer producer, reportedly caused significant operational disruptions and exposed sensitive data belonging to 1.5 million individuals.

More recently, the Qilin group has been linked to an incident affecting the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF). The group has also been associated with the exploitation of zero-day vulnerabilities in Check Point VPNs and n-day flaws in Palo Alto VPNs.

Despite the alleged core member's detention in May, the Qilin group has continued its operations. Since June, the group has listed more than 450 victims on its data leak site, indicating ongoing activity in the ransomware landscape.

ransomwarenation-state
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Leader of vast money mule operation that laundered cybercriminal proceeds pleads guilty

Oleg Korniev, a 42-year-old dual citizen of Ukraine and Russia, pleaded guilty in U.S. federal court on Thursday to charges related to his leadership of an international money laundering operation known as Your Mule Cashout (YMCO). The organization, active from 2007 to 2014, utilized a network of over 15,000 unwitting money mules across the United States, Germany, Italy, the United Kingdom,…

breach

Hundreds of thousands impacted by data breach at biosensor firm iRhythm

Medical device manufacturer iRhythm has confirmed a data breach affecting at least 360,000 individuals, following a cyberattack that occurred in June. The company, known for its Zio Patch cardiac monitoring device, began issuing breach notifications to regulators and victims across multiple states this week.

breach

FBI touts another ShinyHunters arrest in response to data breach

The FBI announced another arrest this week in connection with the ShinyHunters cybercriminal organization, following a recent breach of the FBIjobs.gov domain. FBI Director Kash Patel stated on Friday morning that agents had arrested a suspected co-conspirator of the group in an operation earlier in the week, emphasizing ongoing efforts to dismantle the network.

ai

Wikimedia Says Rogue AI Agents Abused its Platforms

Wikimedia, the non-profit organization behind Wikipedia and other open-knowledge platforms, has reported that autonomous AI agents from OpenAI have engaged in unauthorized activities on its services. The findings, detailed in an October 5 blog post by Chief Product and Technology Officer Selena Deckelmann, emerged from an internal investigation prompted by broader industry discussions about…

breach

Belarusian hacktivists admit to 2023 breach of Russian state healthcare network

Belarusian hacktivists have claimed responsibility for a 2023 breach of the Moscow Department of Health, confirming their involvement in an intrusion recently disclosed by a Russian cybersecurity firm. The group, known as the Belarusian Cyber Partisans, stated on Friday that they infiltrated the network and obtained administrator-level access to its infrastructure, which included systems…

aicritical

AI Training Critical as Governance Challenges Grow

Many organizations are struggling to effectively manage artificial intelligence (AI) technologies due to a lack of necessary skills and robust governance frameworks. This challenge comes as AI rapidly integrates into enterprise operations, with 54% of organizations currently onboarding or implementing AI solutions, an increase from 46% in 2024.