Skip to content

Japan Hands Suspected Qilin Ransomware Member to Germany

Japanese authorities have transferred a Russian national suspected of being a key member of the Qilin ransomware operation to Germany.

The unnamed 28-year-old man is being investigated in connection with a ransomware attack against a German company, according to The Japan Times and other Japanese media reports citing investigative sources.

Suspect Detained in Osaka

Japanese investigators reportedly detained the suspect while he was staying in Osaka in late May 2026.

The detention followed a request from German authorities, which had been searching for the man over his suspected involvement in an attack against a German logistics company.

After the Tokyo High Court approved the transfer, Japan handed the suspect to German authorities on October 2, according to Japanese media reporting.

Japan and Germany do not have a bilateral extradition treaty. Japan’s National Police Agency states that its extradition treaties are with the United States and South Korea.

Japanese law can still permit transfers to countries without extradition treaties when applicable legal and reciprocity requirements are satisfied.

German Company Allegedly Paid Cryptocurrency Ransom

The suspect is accused of participating in a September 2024 ransomware attack against an unnamed German logistics company.

Investigators allege that the attackers accessed the company’s systems, stole and encrypted data and threatened to publish it.

The company reportedly paid approximately ¥26 million, equivalent to about $165,000, in cryptocurrency. Investigators believe the suspect received part of the payment, according to TV Asahi.

The German company and the Russian suspect have not been publicly identified.

Suspected Central Role in Qilin

Japanese reporting describes the man as a central Qilin member involved in developing or maintaining systems used by the ransomware operation.

Qilin operates as a ransomware-as-a-service organization, supplying ransomware infrastructure to affiliates who compromise organizations, encrypt systems and steal data for extortion.

A Cisco Talos report identified Qilin as one of the most frequently observed ransomware operations affecting Japanese organizations during the first half of 2026.

Qilin claimed responsibility for the 2025 cyberattack against Japanese food and beverage company Asahi Group Holdings.

However, current reporting does not establish that the transferred suspect participated in the Asahi incident.

According to figures cited by The Japan Times, Japan’s National Police Agency confirmed 123 ransomware attacks during the first half of 2026, the highest total recorded for a six-month period.

Japanese and German authorities had not released an official statement or public charging document identifying the suspect at the time of publication.

Latest