LIVE · cybersecurity feed
Live wire
ransomware

Germany Arrests Suspected Qilin Ransomware Leader After Japan Detention

German authorities have arrested a Russian national suspected of being a key figure in the Qilin ransomware group. The individual was initially detained in Japan in May while traveling as a tourist in Osaka, following an arrest warrant issued by Germany in connection with a ransomware incident on German soil.

ZeroDay News ·

Source: Security Affairs

German authorities have arrested a Russian national suspected of being a key figure in the Qilin ransomware group. The individual was initially detained in Japan in May while traveling as a tourist in Osaka, following an arrest warrant issued by Germany in connection with a ransomware incident on German soil.

Japan's National Police Agency (NPA) confirmed its role in the arrest and extradition. The NPA, in cooperation with Japan's Ministry of Justice, the Tokyo High Public Prosecutors Office, and German authorities, detained the suspect under a provisional detention warrant in accordance with Japan's Act of Extradition. The suspect was subsequently handed over to Germany through established legal procedures.

The NPA emphasized the importance of international cooperation in combating cybercrime, particularly ransomware attacks that impact multiple countries. The agency also highlighted the contributions of the Kanto Regional Police Bureau’s Cyber Special Investigation Unit and other local police forces, which had been investigating Qilin ransomware attacks within Japan and collaborating with German investigators.

Qilin ransomware has been active since 2022 and emerged as a prominent Ransomware-as-a-Service (RaaS) group in 2025. The group employs double-extortion tactics, encrypting victim data and threatening to leak it on Tor-based portals. Qilin enables affiliates to deploy customized ransomware payloads and has targeted various sectors globally, including healthcare, manufacturing, and finance, often leveraging phishing and known vulnerabilities.

Japanese organizations have been direct victims of Qilin attacks. Notably, carmaker Nissan and brewing company Asahi have been impacted. The attack on Asahi resulted in prolonged operational disruptions and the exposure of data belonging to 1.5 million individuals.

Despite the suspect's detention in May, the Qilin ransomware group has continued its operations. Its Tor leak site has listed hundreds of new victims since June alone. In October 2025, Resecurity researchers detailed Qilin's reliance on global bulletproof hosting networks for its extortion activities. More recently, in early October, Qilin reportedly formed a ransomware alliance with DragonForce and LockBit, aiming to share tools and infrastructure to enhance attack effectiveness. In late March, the group allegedly breached chemical manufacturing giant Dow Inc.

ransomwarenation-state
ShareXLinkedInWhatsAppFacebook

More News

view all →
patch

Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks

A new malvertising campaign, dubbed "Adception" by security researchers at Push Security, is leveraging Google Ads and Bing redirects to distribute fake Claude installers that deploy "ClickFix" attacks. The campaign was identified after researchers observed malicious Google ads targeting users searching for "claude mac."

cybersecurity

AI Fuels Cybersecurity Mergers and Acquisitions

The cybersecurity industry is currently undergoing a substantial wave of mergers and acquisitions (M&A), with 117 deals reported in the most recent quarter. A key driver behind this heightened activity appears to be the increasing integration of artificial intelligence (AI) across various sectors, leading to a broader range of companies seeking to acquire cybersecurity capabilities.

cloud

AWS AgentCore security undone by prompt requesting credentials

Researchers have identified a critical vulnerability in Amazon Bedrock AgentCore that could allow an attacker to compromise all agents within an AWS account and region by exploiting insufficient network isolation and overly permissive default IAM roles. The flaw, disclosed by Zenity Labs, centers on an attacker's ability to extract temporary AWS credentials from an agent through a single prompt.

security

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

Cybersecurity researchers have reported an active credential-theft campaign leveraging GitHub Actions workflows, which has led to the compromise of tens of thousands of repositories. The campaign reportedly exploited two high-profile open-source maintainer accounts to propagate a malicious workflow into over 340 repositories directly. One notable instance involved the account of Takashi Kitao,…

breach

Hundreds of thousands impacted by data breach at biosensor firm iRhythm

Medical device manufacturer iRhythm has confirmed a data breach affecting at least 360,000 individuals, following a cyberattack that occurred in June. The company, known for its Zio Patch cardiac monitoring device, began issuing breach notifications to regulators and victims across multiple states this week.

security

Leader of vast money mule operation that laundered cybercriminal proceeds pleads guilty

Oleg Korniev, a 42-year-old dual citizen of Ukraine and Russia, pleaded guilty in U.S. federal court on Thursday to charges related to his leadership of an international money laundering operation known as Your Mule Cashout (YMCO). The organization, active from 2007 to 2014, utilized a network of over 15,000 unwitting money mules across the United States, Germany, Italy, the United Kingdom,…