A 28-year-old Russian national identified as a core member of the Qilin ransomware group was arrested in Japan and extradited to Germany on Oct. 2, according to an Odaily report citing Nada News. He is suspected of illegally breaching the systems of a German logistics company in September 2024, encrypting its data, and demanding roughly $165,000 worth of Bitcoin, or about 26 million yen.
Investigators said the man helped build the attack infrastructure used by the Qilin criminal network. They also alleged that he took a proportional cut from ransom payments collected by affiliate teams operating under the group’s structure. Japanese police detained him in late May this year while he was traveling in Osaka. He was later transferred to German authorities after the Tokyo High Court ruled that the legal conditions for extradition had been met.
The report said Qilin operates under a ransomware-as-a-service, or RaaS, model. It also noted that the group had previously claimed responsibility in 2025 for a cyberattack targeting Japan’s Asahi Group.
A 28-year-old Russian national described as a core member of the Qilin ransomware group was arrested in Japan and extradited to Germany on Oct. 2, according to Odaily, which cited Nada News.
Suspected of demanding Bitcoin from a German logistics company
The report said the man is suspected of illegally infiltrating the systems of a German logistics company in September 2024, encrypting its data, and extorting about $165,000 worth of Bitcoin, or roughly 26 million yen.
Investigators say he built attack systems for the network
Investigators said he was responsible for building attack systems within the Qilin criminal network and took a proportional share of ransom proceeds collected by affiliate execution teams.
Detained in Osaka in late May
Japanese police took him into custody in late May this year while he was traveling in Osaka. He was later handed over to German authorities after the Tokyo High Court found that the conditions for extradition had been satisfied.
Qilin operates under a RaaS model
The report added that Qilin runs on a ransomware-as-a-service, or RaaS, model. It also said the group had claimed responsibility in 2025 for a cyberattack involving Japan’s Asahi Group.
The report cited Nada News as the source.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.