Core Qilin ransomware member arrested in Japan and extradited to Germany

Core Qilin ransomware member arrested in Japan and extradited to Germany

N
News Editor
2026-10-06 07:32:51
A 28-year-old Russian national identified as a core member of the globally known ransomware group Qilin has been arrested in Japan and extradited to Germany on Oct. 2, according to ChainCatcher. The man is suspected of illegally breaching the systems of a German logistics company in September 2024, encrypting data and demanding a Bitcoin ransom worth about $165,000, or roughly 26 million yen. Investigators said he was responsible for building attack systems inside the Qilin criminal network and took a proportional cut of ransom payments collected by affiliate execution teams. Japanese police took him into custody in late May this year while he was traveling in Osaka. He was later transferred to German authorities after the Tokyo High Court ruled that the legal conditions had been met. Qilin operates under the ransomware-as-a-service, or RaaS, model. The report added that the group had previously claimed responsibility in 2025 for a cyberattack targeting Japan’s Asahi Group.

A 28-year-old Russian national described as a core member of the globally known ransomware group Qilin was arrested in Japan and extradited to Germany on Oct. 2, according to ChainCatcher.

The report said the man is suspected of illegally infiltrating the systems of a German logistics company in September 2024, encrypting data and demanding a Bitcoin ransom worth about $165,000, or roughly 26 million yen.

Role inside the Qilin network

Investigators said he was responsible for building attack systems within the Qilin criminal network and received a proportional share of ransom proceeds collected by affiliate teams.

Custody in Japan and transfer to Germany

Japanese police took him into custody in late May this year while he was visiting Osaka. He was later handed over to German authorities after the Tokyo High Court ruled that the legal requirements for the transfer had been satisfied.

Qilin’s operating model

Qilin runs on a ransomware-as-a-service, or RaaS, model. The report added that the group had previously claimed responsibility in 2025 for a cyberattack on Japan’s Asahi Group.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.