Japan extradited a 28-year-old Russian man to Germany in early October over his alleged involvement in the Qilin ransomware group. The suspect allegedly developed ransomware and directly manipulated systems at a German logistics company compromised in September 2024. According to reporting citing Asahi Shimbun, the company paid a Bitcoin ransom to prevent publication of stolen data, and part of that payment allegedly reached the suspect, providing the basis for a German arrest warrant. His alleged role has not been proven.
Japanese authorities arrested the man in Osaka in May after obtaining confirmation of the German warrant from the Tokyo High Court. The handover is unusual because Japan has extradition treaties only with South Korea and the United States, highlighting cross-border enforcement against ransomware suspects outside established treaty relationships. Qilin has been linked to ransomware attacks against companies worldwide, including Japan’s Asahi brewery, but the reporting does not establish this suspect’s involvement in the brewery attack.

See the reporting duties and controls this puts on the clock.
12 events from the most recent confirmed update back to the earliest known activity.
Japan’s National Police Agency confirmed the arrest and extradition to Germany of a 28-year-old Russian national accused of Qilin involvement and participating in a ransomware attack on a German company. The report says Japanese authorities arrested him at an Osaka hotel in May and extradited him in June.
The US Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed that it had suffered a cyberattack after Qilin added the agency to its leak site.
In September 2024, Qilin compromised an unnamed German logistics company’s IT systems and extorted the company. The Russian suspect later extradited to Germany allegedly manipulated the company’s systems himself.
Qilin was associated with a 2024 ransomware attack against Synnovis, a UK medical services provider whose systems were used by several London hospitals. The attack significantly disrupted healthcare operations.
Qilin attacked Japanese carmaker Nissan. The reference does not specify the attack's timing or impact.
German authorities arrested a Russian national suspected of being a leading Qilin ransomware member following his extradition from Japan. Germany had obtained an arrest warrant in connection with a ransomware incident in Germany.
Japan extradited the 28-year-old Russian suspect to Germany in early October to face criminal proceedings. The handover was unusual because Japan has extradition treaties only with South Korea and the United States.
Authorities arrested the Russian suspect in Osaka in May. He was alleged to be an important Qilin member who developed ransomware and participated directly in the German logistics company attack.
Authorities obtained confirmation of the German arrest warrant from the Tokyo High Court before arresting the suspect. Investigators reportedly knew in advance that he would travel to Japan.
The article reports that Qilin attacked Germany’s Die Linke political party in March, without explicitly specifying the year.
Qilin attacked Japan’s Asahi brewery, disrupting beer supplies and production of nonalcoholic beverages and other food products. The report does not establish that the extradited suspect participated in this attack.
According to Asahi Shimbun, the company paid a Bitcoin ransom to prevent publication of stolen data. Part of the payment allegedly reached the Russian suspect, helping form the basis of the German arrest warrant.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
12 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourcecysecurity.news
Open sourcemalware.news
Open sourcejapantimes.co.jp
Open sourceasahi.com
Open sourcenpa.go.jp
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.