LIVE · cybersecurity feed
Live wire
ransomware

Japan confirms arrest of Russian Qilin operative, extradition to Germany

Japanese authorities have confirmed the arrest and extradition of a Russian national suspected of involvement with the Qilin ransomware group. The 28-year-old individual, whose identity has not been publicly disclosed, was apprehended in Japan based on an arrest warrant issued by Germany.

ZeroDay News ·

Source: The Record

Japanese authorities have confirmed the arrest and extradition of a Russian national suspected of involvement with the Qilin ransomware group. The 28-year-old individual, whose identity has not been publicly disclosed, was apprehended in Japan based on an arrest warrant issued by Germany.

The National Police Agency of Japan stated on Thursday that the suspect was sought by German law enforcement in connection with a ransomware attack targeting a German company. The Japanese Ministry of Justice facilitated the detention and subsequent extradition of the individual to Germany.

Reports indicate that Japanese officials became aware in May that the suspect intended to travel to Japan for a vacation. The arrest took place at a hotel in Osaka that same month, with the extradition to Germany occurring in June. German law enforcement has not yet commented on the matter.

The Qilin ransomware group has been linked to numerous high-profile cyberattacks globally. In Germany, the group claimed responsibility for an April ransomware incident affecting the democratic socialist political party Die Linke.

In Japan, Qilin was implicated in a significant attack last year against the beverage giant Asahi. That incident caused weeks of disruption to Asahi's order processing, shipping, and customer services. The attackers also reportedly exfiltrated and leaked sensitive data, including financial records, employee information, contracts, and development forecasts from Asahi.

The group faced heightened scrutiny from law enforcement in 2024 following an attack on a British healthcare company that led to substantial disruptions in medical services. Despite this, Qilin continued its operations, targeting the government of Palau and a major U.S. newspaper chain.

In 2025, Qilin was identified as one of the most active ransomware operations, with reported attacks on Kuala Lumpur International Airport and the city of Sugar Land, Texas. The group's activity persisted into 2026; researchers noted it was the second most active ransomware gang in July, with 127 reported attacks.

Recent incidents attributed to Qilin in 2026 include an attack on the French rugby club Stade Français Paris, which confirmed it had been compromised after appearing on Qilin's leak site. In August, Qilin actors also claimed responsibility for a ransomware attack against the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF), alleging the theft of information related to ATF investigations.

ransomwarenation-state
ShareXLinkedInWhatsAppFacebook

More News

view all →
ransomware

FBI Arrests Founder of Ransomware Negotiation Firm

Federal agents have arrested a Canadian cybersecurity professional in Pennsylvania, linking him to an ongoing investigation into the ShinyHunters hacking group. Edward Dubrovsky, co-founder of the Canadian firm CyberSteward, was taken into custody on October 8, facing charges of conspiracy to threaten to impair the confidentiality of information with intent to extort money, and interference…

ransomware

Germany Arrests Suspected Qilin Ransomware Leader After Japan Detention

German authorities have arrested a Russian national suspected of being a key figure in the Qilin ransomware group. The individual was initially detained in Japan in May while traveling as a tourist in Osaka, following an arrest warrant issued by Germany in connection with a ransomware incident on German soil.

saashigh

ASOS Breach Reveals the Risks in Customer-Facing SaaS

A recent security incident involving the British online fashion retailer ASOS has brought to light the inherent risks associated with customer-facing Software-as-a-Service (SaaS) platforms. The breach reportedly showcased how the compromise of a single user identity could serve as an initial access vector, subsequently allowing attackers to achieve broad penetration into a company's internal…

patch

Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks

A new malvertising campaign, dubbed "Adception" by security researchers at Push Security, is leveraging Google Ads and Bing redirects to distribute fake Claude installers that deploy "ClickFix" attacks. The campaign was identified after researchers observed malicious Google ads targeting users searching for "claude mac."

cybersecurity

AI Fuels Cybersecurity Mergers and Acquisitions

The cybersecurity industry is currently undergoing a substantial wave of mergers and acquisitions (M&A), with 117 deals reported in the most recent quarter. A key driver behind this heightened activity appears to be the increasing integration of artificial intelligence (AI) across various sectors, leading to a broader range of companies seeking to acquire cybersecurity capabilities.

cloud

AWS AgentCore security undone by prompt requesting credentials

Researchers have identified a critical vulnerability in Amazon Bedrock AgentCore that could allow an attacker to compromise all agents within an AWS account and region by exploiting insufficient network isolation and overly permissive default IAM roles. The flaw, disclosed by Zenity Labs, centers on an attacker's ability to extract temporary AWS credentials from an agent through a single prompt.