Suspected Qilin Ransomware Leader Arrested in Japan and Extradited to Germany

German investigators infiltrated Qilin for months before a suspected leading member of the ransomware operation was arrested in Japan and extradited.
Suspected Qilin ransomware member being escorted by law enforcement following arrest in Japan and extradition to Germany.

German investigators say they infiltrated the Qilin ransomware operation and monitored it for months before an alleged leading member of the group was arrested in Japan and extradited to Germany.

North Rhine-Westphalia Interior Minister Herbert Reul announced the arrest on Oct. 7, describing the 28-year-old Russian national as one of Qilin’s suspected leading figures. Japanese authorities arrested the man in May while he was visiting Japan, and he was transferred to Germany on Oct. 2.

The arrest represents a significant international law enforcement action against Qilin, one of the world’s most active ransomware-as-a-service operations.

Authorities have not publicly identified the suspect by name. BreachNews does not publish the identities of alleged individual cybercriminals unless necessary for public-interest reporting.

Investigators infiltrated Qilin for months

The operation went beyond tracking ransomware attacks attributed to Qilin.

Investigators from the North Rhine-Westphalia State Criminal Police Office and the state’s Central Cybercrime Contact Office reportedly infiltrated Qilin and secretly monitored the operation for months.

German Justice Minister Benjamin Limbach said investigators followed extensive digital evidence before connecting activity conducted under an online identity to the suspect. Authorities also reportedly analyzed cryptocurrency transactions and communications associated with the ransomware operation.

German authorities learned that the suspect planned to travel to Japan and coordinated with Japanese law enforcement, which detained him in May. Germany subsequently requested his transfer despite the countries not having a bilateral extradition treaty.

The suspect is now being held in Germany and is expected to face criminal proceedings.

German logistics attack led investigators to suspect

The investigation centers in part on a September 2024 ransomware attack against a German logistics company.

Authorities allege the attacker gained unauthorized access to the company’s systems, stole information and encrypted data before demanding cryptocurrency to prevent publication of the stolen material.

Reports from Japan put the payment associated with the attack at approximately $165,000 in cryptocurrency. German reporting has described the amount as nearly €150,000 in Bitcoin.

The allegations describe the double-extortion model commonly associated with Qilin, where attackers combine system encryption with data theft and threaten to publish stolen information if victims refuse to pay.

Authorities have not publicly disclosed the identity of the logistics company or detailed the initial access method used in the attack.

Authorities claim nearly 4,000 Qilin victims

German officials provided unusually large estimates for Qilin’s overall activity while announcing the arrest.

According to Reul, Qilin is suspected of targeting nearly 4,000 companies and institutions worldwide since 2024. Authorities attributed approximately 150 attacks to the operation in Germany, including around 30 in North Rhine-Westphalia.

German officials said total ransom demands associated with the operation approached $3 billion, while victims allegedly paid more than $140 million.

Those figures have not been independently verified by BreachNews and likely include attacks conducted by affiliates using Qilin’s ransomware-as-a-service infrastructure rather than activity personally conducted by the arrested suspect.

Qilin operates through an affiliate model in which outside cybercriminals can use the group’s ransomware, infrastructure and extortion platform to conduct attacks. German investigators said the operation is connected to several hundred affiliates.

Qilin has remained highly active in 2026

The arrest comes during a period of sustained activity from the ransomware operation, including attacks and intrusion activity involving major organizations and internet-facing enterprise infrastructure.

BreachNews reported in June on Qilin-linked activity exploiting a critical Check Point VPN authentication bypass after the vulnerability was added to the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog.

In July, Qilin ransomware attacks were also linked to exploitation of a PAN-OS VPN authentication bypass, highlighting the group’s continued focus on externally accessible enterprise infrastructure.

The operation continued claiming prominent victims later in the year. Qilin claimed an August attack against Danone, alleging the theft of 221 GB of internal information.

Days later, the group drew additional attention in the United States after targeting a federal law enforcement agency. The Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed a major cybersecurity incident after Qilin claimed responsibility for the attack.

Arrest unlikely to immediately dismantle operation

German authorities have characterized the arrest as a major breakthrough against Qilin, but there is currently no indication that the ransomware operation itself has been dismantled.

The group’s ransomware-as-a-service structure means responsibility for attacks is distributed among operators and affiliates rather than concentrated in a single individual. Even the arrest of a suspected senior member does not necessarily remove the infrastructure, affiliates or other personnel required to continue attacks.

The months-long infiltration could prove more consequential if investigators obtained information identifying additional Qilin members, affiliates, infrastructure or cryptocurrency flows. Authorities have not disclosed the full extent of the intelligence collected during the operation.

The investigation also demonstrates the increasing international reach of ransomware enforcement. The suspect was allegedly identified through an investigation in Germany, tracked while traveling abroad, arrested with assistance from Japanese authorities and ultimately transferred back to Germany for prosecution.

For Qilin, the arrest places new pressure on an operation that has continued to rank among the most active ransomware groups despite repeated scrutiny from international law enforcement and security researchers.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site →