Japanese and German officers apprehend a hooded suspect amid a cybercrime investigation linking Osaka and Cologne.
Germany now holds a 28-year-old Russian national suspected of being a leading member of the Qilin ransomware operation. He was caught on a sightseeing trip, held in Osaka for months and handed over this month. That's a rare outcome for ransomware cases. The arrest is a real law-enforcement milestone, but it is not a reason for IT teams to relax.

Japanese and German officers apprehend a hooded suspect amid a cybercrime investigation linking Osaka and Cologne. What happened​

Japanese police captured a Russian national believed to be a key member of the "Qilin" hacker group and extradited him to Germany, investigative sources told Jiji Press on October 6. Japan's National Police Agency (NPA) then confirmed it officially. BleepingComputer's translation of the NPA release says the man was subject to a German arrest warrant over a ransomware incident in Germany. After he arrived in Japan, the Justice Ministry, the Tokyo High Public Prosecutors Office and German authorities worked together. They obtained a provisional detention warrant under Japan's Extradition Law for Fugitives and then arranged the transfer.

The Japan Times, reporting on the NPA's account, adds the following:

  • The suspect is 28 years old and is wanted in Germany on suspicion of extortion, over attacks on German companies and demands for cryptocurrency.
  • After police learned of his planned tourist trip in May, the NPA's cyber special investigation department located him. It worked with the Tokyo, Osaka and Kyoto police.
  • He was arrested in Osaka in May and was handed to German authorities this month after a Tokyo High Court decision under the extradition law.

Two dates matter here, and they are easy to mix up. The detention was in May. The handover came in October. SecurityWeek reports he was handed to German authorities on October 2. That date comes from SecurityWeek's reporting, not from the NPA release as quoted by BleepingComputer.

The alleged German case​

Reported allegations differ in detail, and none of them has been tested in court.

  • SecurityWeek says he was wanted for hacking a logistics company in September 2024, encrypting its data and extorting more than $160,000 in cryptocurrency.
  • Sankei, via ITmedia, describes unauthorized access to a logistics company's terminal in Germany, data theft and a demand worth about $165,000 in cryptocurrency.
  • German public broadcaster ZDF says an NRW company was hit in September 2024, with data stolen and encrypted and publication threatened. It adds that Japanese media report the suspect was responsible for building attack systems and received part of the ransom.

Treat the exact sum and the description of his role as reported, not established. His name has not been published in the coverage reviewed, and there is no conviction.

The German investigation​

ZDF reports that North Rhine-Westphalia's state criminal police and its cybercrime prosecution unit (ZAC NRW) secretly infiltrated and monitored the group for months. Interior Minister Herbert Reul called it a historic blow, according to ZDF. Justice Minister Benjamin Limbach said there had been extensive investigative work analysing numerous digital traces, and that a name ended up behind the pseudonym.

ZDF also relays several claims from Reul:

  • Qilin has extorted nearly 4,000 companies since 2024, about 150 of them in Germany.
  • Ransom demands totalled almost $3 billion, with more than $140 million actually paid. The LKA NRW figures cover the whole group, not this suspect.
  • Japan extradited him even though the two countries have no bilateral extradition treaty.

The Japan Times uses a similar "about 4,000 companies" figure. BleepingComputer's figure is more than 2,350 known organizations in 62 countries, and the two should not be merged. They likely use different counting methods and time periods.

Why one arrest doesn't end Qilin​

Qilin is a ransomware-as-a-service operation. As the Japan Times describes it, numerous affiliates carry out intrusions and extortion using ransomware supplied by core members who handle malware development and system management. ZDF says several hundred affiliate groups work with the core operators and share the proceeds. Removing one person from that structure is significant, but it does not switch the service off.

The activity since the Osaka detention shows this. BleepingComputer notes that Qilin kept operating and has listed more than 450 victims on its leak site since June. The group also hit the U.S. ATF, which confirmed in August that it had been hit after Qilin added it to its leak site. In June, Qilin was exploiting a critical authentication bypass in Check Point VPN and firewall products, tracked as CVE-2026-50751. BleepingComputer also links the group to Palo Alto VPN flaws. These are separate from the German case and from the suspect.

Cybernews cites researchers who tied Qilin to 1,022 attacks in 2025 and an estimated $193 million in revenue. That is a single outlet's summary of third-party research, so treat it as indicative only.

Why extradition without a treaty stands out​

Cybernews, citing Heise, calls the extradition surprising because Japan and Germany have no extradition treaty. Cypro, a UK security firm, says Japanese law allows surrender on a non-treaty basis when the legal conditions are met and a court approves. ZDF adds that the NRW evidence convinced Japanese courts. The takeaway is that cybercriminals who travel for leisure can be caught in countries with no treaty. Japan's NPA stresses that cross-border cooperation is essential for this kind of crime.

What defenders should do​

None of the sources announces a takedown of Qilin's infrastructure or a new defensive advisory. The following is general practice, not guidance from the NPA or German authorities:

  • Patch edge devices first. VPNs and firewalls were reported entry points in recent Qilin activity.
  • Review remote-access logs for unusual authentication, especially on gateways affected by the vulnerabilities above.
  • Protect backups so that they can't be reached with compromised domain credentials.
  • Prepare for data theft, not just encryption. Double extortion means restoring from backup does not stop a leak.
  • Rehearse incident response, including evidence preservation and legal and regulatory notification.

Bottom line​

This is a meaningful win for international policing: a suspected core member was tracked, held for months and handed over without a bilateral treaty. For Windows and enterprise admins, though, the threat is unchanged. Qilin's affiliates, its leak site and the edge-device flaws it has exploited are all still there. Watch the German proceedings for confirmed charges, and for any sign the arrest has disrupted the group.

 

References

  1. Germany arrests alleged core Qilin ransomware member after extradition BleepingComputer 2026-10-09T11:38:56-04:00
  2. Qilin Ransomware Suspect Arrested in Japan, Extradited to Germany - SecurityWeek securityweek.com
  3. Qilin ransomware suspect extradited from Japan to Germany cybernews.com