Key takeaways

  • Japanese authorities detained a 28-year-old Russian national described as a core member of the Qilin ransomware group in Osaka in late May 2026, and handed him over to Germany on October 2, the Asahi Shimbun reported on October 6, citing unnamed sources.
  • Germany is investigating him for extortion over a September 2024 attack on a German logistics company, which paid about US$165,000 in bitcoin, according to the report.
  • No official statement has been published by Japanese or German authorities, and we found no other independent reporting. Treat the details as reported, not confirmed.
  • Qilin claimed the 2025 attack on Asahi Group, the Japanese brewer. The report does not say this man was involved in that attack.

What the Asahi Shimbun reported#

According to the newspaper, which cited "people involved":

  • The man, a Russian national aged 28, is a core member of Qilin and was responsible for building the systems the group uses for its crimes. Several operational teams carry out attacks under the core members, and ransom payments pass through those teams to the core.
  • Japanese investigators learned of his whereabouts in advance. In late May 2026, they obtained a warrant from the Tokyo High Court and detained him while he was traveling in Osaka.
  • The detention and extradition were requested by Germany under Japan's Act of Extradition. After the Tokyo High Court ruled that extradition was permissible, Japan handed him over on October 2.
  • He is suspected of accessing a terminal at a logistics company in Germany in September 2024, stealing and encrypting data, and extorting bitcoin worth US$165,000 (about ¥26 million) by threatening to publish the data. Investigators confirmed he received part of the ransom, the paper says.
  • Authorities in Japan, Germany and other countries are investigating Qilin jointly.

The paper did not name the man or the German company.

What is not confirmed#

  • No official source. As of midday on October 6, we found no statement from Japan's Ministry of Justice or National Police Agency, or from German prosecutors or the Federal Criminal Police Office (BKA). The Asahi Shimbun report is the only original source.
  • The Asahi Group attack. The headline mentions Asahi Group, and the report notes that Qilin claimed the 2025 attack on the brewer. It does not say that this man took part. Some Japanese sites that rewrote the story have described him as "involved in the Asahi attack". The original report does not support that.
  • First arrest? A profile of Qilin published by security company Adaptive Security in September 2026 said that no arrest, indictment or sanction had targeted the group as of August 2026. If the report is accurate, this may be the first publicly known detention of a Qilin member, but we cannot rule out cases that were not made public.

We will update this article if officials confirm or correct the report.

Who is Qilin?#

Qilin, also known as Agenda, is a ransomware-as-a-service operation first seen in 2022. Its operators provide the ransomware and infrastructure, and affiliates carry out attacks in exchange for a share of the ransom. That matches the structure described in the Asahi Shimbun report: a core that builds the system, and operational teams that attack.

First listed on leak site trackers October 2022
Victims listed on ransomware.live 2,336 in total. 1,058 in 2025 and 1,041 so far in 2026
Japanese victims listed 44 (28 in 2025, 14 so far in 2026)
Best-known Japanese case Asahi Group, September 2025: order and shipment systems stopped for about two months
Recent Japanese listings Nissho Electric (Sep 28), SKLG (Sep 28), Mutsumi Group (Oct 4)

Qilin has been one of the most active ransomware groups in the world over the past two years. In Japan, IPA's white paper names it in connection with the Asahi attack, one of the year's most damaging incidents.

Our analysis#

Japan can extradite without a treaty#

Japan has extradition treaties with only two countries: the United States and South Korea. It has none with Germany. But under the Act of Extradition, Japan can hand over a suspect to another country if that country guarantees reciprocity, according to the Ministry of Justice. If the report is accurate, this case shows that route being used for a ransomware suspect, and quickly: about four months from detention to handover.

It also shows something about how the case was kept quiet. The man was detained in May. Nothing was made public until after he had left Japan.

One arrest does not stop a ransomware service#

Removing the person who builds the system can hurt a ransomware operation, but it rarely stops one. Qilin listed Japanese victims on its leak site on September 28 and October 4, while the man was already in custody. Affiliates can keep attacking with existing tools, and other core members can keep the service running. Past disruptions of large groups have usually needed coordinated action against their infrastructure, not only individual arrests.

Travel is a risk for ransomware operators#

Many ransomware operators are thought to be based in countries that do not extradite their own citizens. Arrests usually happen when they travel. According to the report, that is what happened here: the man was detained while on a trip to Osaka, after Japanese investigators learned where he would be. For Japan, which has suffered heavily from ransomware, being a place where such suspects can be caught matters as much as defending against attacks.

What this means for readers#

  • For organizations hit by Qilin, including in Japan, nothing changes yet. The group's leak site is still active, and its affiliates are still attacking.
  • For readers following the case, watch for statements from German prosecutors or the BKA, which would confirm the charges, and for any statement from Japan's Ministry of Justice.

Japanese terms at a glance#

Japanese Reading Meaning
キリン(Qilin) Kirin Qilin ransomware group
中心メンバー chūshin membā Core member
逃亡犯罪人引渡法 Tōbō Hanzainin Hikiwatashi Hō Act of Extradition
身柄の引き渡し migara no hikiwatashi Handing over custody (extradition)
実動部隊 jitsudō butai Operational unit (here, affiliates who carry out attacks)
関係者への取材 kankeisha e no shuzai Reporting based on people involved (unnamed sources)