Security News

Suspected Qilin Ransomware Operative Arrested on Holiday in Japan and Sent to Germany

The Record · 10 Oct 2026
Key Takeaway Arrests may not slow a busy ransomware group, so keep offline backups, enforce multi-factor authentication and rehearse how your business would operate if systems were locked.

Japan's National Police Agency has confirmed the arrest and extradition of a Russian national accused of involvement in the Qilin ransomware gang. The 28-year-old, whose name has not been released, was wanted by Germany over an alleged role in a ransomware attack on a German company. Japanese media reported that officials learned in May that the suspect planned a holiday in Japan. He was arrested at a hotel in Osaka that month and sent to Germany in June. German law enforcement did not respond to requests for comment.

Qilin has been behind dozens of high-profile attacks. Its claimed victims include the German political party Die Linke in April and Japanese beverage giant Asahi last year, which spent weeks recovering after its order processing, shipping and customer services were disrupted. Attackers also leaked Asahi's financial records, employee data and contracts. Earlier targets include a British healthcare company, the government of Palau, Kuala Lumpur International Airport and the Texas city of Sugar Land.

The group remains active in 2026. Researchers say it was the second most active ransomware gang in July, with 127 reported attacks. In August, it claimed an attack on the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives, allegedly stealing information about investigation targets. This summary covers only the opening of the original report.

ransomware Qilin law enforcement extradition

Summarised by CISO AI from The Record, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.