Trusence Every claim has a source
Last updated 9 October 2026 Search Türkçe
← All stories
Security

Germany arrests alleged leading Qilin ransomware figure after Japan extradites him

The arrest adds pressure on a ransomware operation that has still kept publishing victims since June.

Germany has arrested a Russian national it says was a leading Qilin ransomware figure after Japan extradited him, marking a notable hit against one of the most active ransomware operations. Japanese authorities confirmed the extradition and said the suspect was detained after entering Japan as a tourist. Qilin, which began in August 2022 as Agenda, has used double-extortion tactics and is tied to attacks on organizations in at least 62 countries, with more than 2,350 known targets. The group’s victims include Nissan, Asahi, Lee Enterprises, and Court Services Victoria, and it has also been linked to recent abuse of Check Point and Palo Alto VPN flaws. Even with the arrest, the group has kept publishing victims and has listed more than 450 since June.

Why it matters

The case shows law enforcement can still reach people linked to a major ransomware group even when the group keeps operating. For organizations that have been listed by Qilin, the arrest does not undo the exposure already caused, and the group’s continued victim postings mean the threat remains active despite the detention.

Sources

  • BleepingComputer