Germany arrests alleged leading Qilin ransomware figure after Japan extradites him
The arrest adds pressure on a ransomware operation that has still kept publishing victims since June.
Germany has arrested a Russian national it says was a leading Qilin ransomware figure after Japan extradited him, marking a notable hit against one of the most active ransomware operations. Japanese authorities confirmed the extradition and said the suspect was detained after entering Japan as a tourist. Qilin, which began in August 2022 as Agenda, has used double-extortion tactics and is tied to attacks on organizations in at least 62 countries, with more than 2,350 known targets. The group’s victims include Nissan, Asahi, Lee Enterprises, and Court Services Victoria, and it has also been linked to recent abuse of Check Point and Palo Alto VPN flaws. Even with the arrest, the group has kept publishing victims and has listed more than 450 since June.
Why it matters
The case shows law enforcement can still reach people linked to a major ransomware group even when the group keeps operating. For organizations that have been listed by Qilin, the arrest does not undo the exposure already caused, and the group’s continued victim postings mean the threat remains active despite the detention.
Keep or strike?
Does this story matter, or is it hype? Mark it before you see what everyone else did.
Sources
- BleepingComputer