German authorities have arrested a Russian national suspected of being a key member of the Qilin ransomware group. The individual was extradited from Japan earlier this month, following their initial detention in May at a hotel in Osaka.
The arrest was officially confirmed by Japan's National Police Agency, which stated that the suspect was apprehended after arriving in the country as a tourist. German authorities had obtained an arrest warrant for the individual in connection with a ransomware incident that occurred in Germany. The Japanese Ministry of Justice and the Tokyo High Public Prosecutors Office collaborated with Germany to detain the suspect under the Extradition Law for Fugitives, securing a provisional detention warrant before facilitating the extradition.
Qilin, also known as Agenda, is a prominent ransomware-as-a-service (RaaS) operation that first emerged in August 2022. The group employs double-extortion tactics, stealing data before encrypting it. It has become one of the most active ransomware threats globally, reportedly targeting over 2,350 organizations across 62 countries.
Notable victims of Qilin attacks include Japanese automaker Nissan, Japanese brewery Asahi, U.S. newspaper publisher Lee Enterprises, and Australia's Court Services Victoria. The attack on Asahi, Japan's largest beer producer, reportedly caused significant operational disruptions and exposed sensitive data belonging to 1.5 million individuals.
More recently, the Qilin group has been linked to an incident affecting the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF). The group has also been associated with the exploitation of zero-day vulnerabilities in Check Point VPNs and n-day flaws in Palo Alto VPNs.
Despite the alleged core member's detention in May, the Qilin group has continued its operations. Since June, the group has listed more than 450 victims on its data leak site, indicating ongoing activity in the ransomware landscape.






