Japanese authorities have confirmed the arrest and extradition of a Russian national suspected of involvement with the Qilin ransomware group. The 28-year-old individual, whose identity has not been publicly disclosed, was apprehended in Japan based on an arrest warrant issued by Germany.
The National Police Agency of Japan stated on Thursday that the suspect was sought by German law enforcement in connection with a ransomware attack targeting a German company. The Japanese Ministry of Justice facilitated the detention and subsequent extradition of the individual to Germany.
Reports indicate that Japanese officials became aware in May that the suspect intended to travel to Japan for a vacation. The arrest took place at a hotel in Osaka that same month, with the extradition to Germany occurring in June. German law enforcement has not yet commented on the matter.
The Qilin ransomware group has been linked to numerous high-profile cyberattacks globally. In Germany, the group claimed responsibility for an April ransomware incident affecting the democratic socialist political party Die Linke.
In Japan, Qilin was implicated in a significant attack last year against the beverage giant Asahi. That incident caused weeks of disruption to Asahi's order processing, shipping, and customer services. The attackers also reportedly exfiltrated and leaked sensitive data, including financial records, employee information, contracts, and development forecasts from Asahi.
The group faced heightened scrutiny from law enforcement in 2024 following an attack on a British healthcare company that led to substantial disruptions in medical services. Despite this, Qilin continued its operations, targeting the government of Palau and a major U.S. newspaper chain.
In 2025, Qilin was identified as one of the most active ransomware operations, with reported attacks on Kuala Lumpur International Airport and the city of Sugar Land, Texas. The group's activity persisted into 2026; researchers noted it was the second most active ransomware gang in July, with 127 reported attacks.
Recent incidents attributed to Qilin in 2026 include an attack on the French rugby club Stade Français Paris, which confirmed it had been compromised after appearing on Qilin's leak site. In August, Qilin actors also claimed responsibility for a ransomware attack against the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF), alleging the theft of information related to ATF investigations.






