Translating into Русский. The English version is shown until it is ready.
Japan detains alleged Qilin ransomware member, hands him to Germany
Коротко
Japanese investigative authorities detained a 28-year-old Russian national described as a central member of the ransomware group Qilin and handed him to Germany, several outlets reported on October 6. Germany is investigating him on suspicion of extortion over a September 2024 attack on a German logistics company in which data was obtained and encrypted and a payment worth $165,000, about 26 million yen, was demanded. Qilin issued a claim of responsibility for a 2025 attack on Asahi Group Holdings, and police agency data cited by one outlet link the group to 32 of the 149 ransomware cases with a confirmed strain in Japan in 2025.
Читать полностью 2 мин чтения
Japanese investigative authorities detained a 28-year-old Russian national described as a central member of the ransomware group Qilin and handed him to Germany, several outlets reported on October 6, citing people familiar with the matter. Asahi Shimbun, Yahoo! News Japan and Yomiuri Shimbun said the handover took place on October 2, while NHK, Sankei Shimbun, Jiji Press and Nishi-Nippon Shimbun said it happened this month. Germany had requested his detention and transfer, Asahi Shimbun reported, and Jiji Press said the handover was made at Germany's request. [ 1 , 2 , 3 , 4 , 5 , 6 , 7 , 8 , 9 ]
According to Asahi Shimbun and Sankei Shimbun, the man is suspected of accessing the terminal of a German logistics company in September 2024, illegally obtaining and encrypting its data, and demanding payment worth $165,000, about 26 million yen, in exchange for not publishing it. Asahi Shimbun described the demand as bitcoin; Sankei Shimbun and Yomiuri Shimbun described the same amount as crypto assets. German authorities are investigating him on suspicion of extortion, the reports said. [ 1 , 5 , 9 ]
Asahi Shimbun said Japanese authorities learned where he was in advance, obtained a warrant from the Tokyo High Court in late May 2026 and detained him while he was travelling in Osaka; the transfer followed a Tokyo High Court decision that he could be handed over, under Japan's Act on Extradition of Fugitives. Sankei Shimbun said he was detained in Osaka in late May with court permission. Jiji Press said authorities had information he was in Japan, located him and handed him over at Germany's request. [ 1 , 5 , 6 , 9 ]
Asahi Shimbun reported that the man was responsible for building the systems used in attacks and that several operational units carried out ransomware attacks under the group's central members, with ransom payments passed to them through those units; it said it confirmed he received part of the payment in this case. No document names the suspect. [ 1 ]
Qilin has repeatedly attacked companies in various countries. Asahi Shimbun and Jiji Press said investigators in Japan, Germany and other affected countries are conducting a joint investigation. The group issued a claim of responsibility for a 2025 cyberattack on Asahi Group Holdings that, according to Asahi Shimbun, caused order and shipment stoppages; Jiji Press described the incident as a large-scale system failure, and Yomiuri Shimbun dated it to September last year. [ 1 , 2 , 3 , 4 , 5 , 6 , 7 , 9 ]
Nishi-Nippon Shimbun, citing the police agency, reported that 32 of the 149 ransomware cases with a confirmed strain in Japan in 2025 were believed to be Qilin's. Yomiuri Shimbun, citing the security company Mitsui Bussan Secure Directions, said Qilin's activity has been confirmed since around 2022 and that it claimed involvement in about 1,500 cyberattacks in the year to September. [ 7 , 9 ]
Почему это важно
The handover, carried out under Japan's Act on Extradition of Fugitives, shows Japanese authorities acting on a German request in a criminal case abroad, in an investigation that reports say involves several affected countries. The documents tie the group to a 2025 attack that disrupted ordering and shipping at Asahi Group Holdings, and police agency figures cited by one outlet indicate Qilin accounted for a notable share of the ransomware cases with a confirmed strain in Japan in 2025. Figures cited by Yomiuri Shimbun suggest the group's claimed activity runs to roughly 1,500 attacks in a single year.
Ключевые факты
- A 28-year-old Russian national described as a central member of the ransomware group Qilin was detained by Japanese investigative authorities and handed to Germany, according to multiple outlets. [ 1 , 2 , 3 , 4 , 5 , 6 , 7 , 8 , 9 ]
- Asahi Shimbun, Yahoo! News Japan and Yomiuri Shimbun said the handover took place on October 2; Germany had requested his detention and transfer, and NHK, Sankei Shimbun and Jiji Press said it happened this month. [ 1 , 2 , 4 , 5 , 6 , 9 ]
- He is suspected of accessing a German logistics company's terminal in September 2024, obtaining and encrypting data, and demanding a payment worth $165,000, about 26 million yen. [ 1 , 5 ]
- Japanese authorities detained him in Osaka in late May 2026, and the transfer followed a Tokyo High Court decision under the Act on Extradition of Fugitives. [ 1 , 5 , 9 ]
- Qilin issued a claim of responsibility for a 2025 cyberattack on Asahi Group Holdings, which Asahi Shimbun said caused order and shipment stoppages and Jiji Press described as a large-scale system failure. [ 1 , 2 , 3 , 4 , 5 , 6 , 7 , 9 ]
- Police agency data cited by Nishi-Nippon Shimbun said 32 of the 149 ransomware cases with a confirmed strain in Japan in 2025 were believed to be Qilin's. [ 7 ]
- Yomiuri Shimbun, citing the security company Mitsui Bussan Secure Directions, said Qilin's activity has been confirmed since around 2022 and that it claimed involvement in about 1,500 cyberattacks in the year to September. [ 9 ]
Подтверждено несколькими источниками
- A Russian national described as a central member of the ransomware group Qilin was detained by Japanese investigative authorities and handed to Germany. [ 1 , 2 , 3 , 4 , 5 , 6 , 7 , 8 , 9 ]
- Qilin issued a claim of responsibility for a 2025 cyberattack on Asahi Group Holdings, and the group has attacked companies in various countries. [ 1 , 2 , 3 , 4 , 5 , 6 , 7 , 9 ]
- Germany is investigating the man on suspicion of extortion. [ 1 , 5 , 9 ]
- The man was detained in Osaka and the transfer followed a decision by the Tokyo High Court under Japan's Act on Extradition of Fugitives. [ 1 , 5 , 9 ]
Пока неясно
- The suspect's name and other identifying details. No document names the suspect; he is described only as a 28-year-old Russian national.
- The exact place of the handover to Germany. Asahi Shimbun gives the date, October 2, but not the location, and the other documents do not add it.
- Whether the ransom demand was specifically in bitcoin. Asahi Shimbun says bitcoin worth about $165,000; Sankei Shimbun and Yomiuri Shimbun describe the same amount as crypto assets.
- The precise day of his detention in Osaka. Asahi Shimbun, Sankei Shimbun and Yomiuri Shimbun say only late May 2026.
- Whether the suspect faces any charges in Japan. The documents describe only the German extortion investigation and the transfer; none mentions a Japanese prosecution.
- Police agency data that 32 of the 149 ransomware cases with a confirmed strain in Japan in 2025 were believed to be Qilin's. Reported by a single outlet in these documents.
- Yomiuri Shimbun's figures that Qilin has been active since around 2022 and claimed about 1,500 attacks in the year to September. Attributed to one security company and carried by a single outlet in these documents.
Что пишут местные СМИ
Хронология, местное время
- The suspect allegedly accesses a German logistics company's terminal, obtains and encrypts data, and demands a payment worth about $165,000. [ 1 , 5 ]
- Asahi Group Holdings is hit by a ransomware attack and Qilin issues a claim of responsibility; Yomiuri Shimbun dates the attack to September. [ 1 , 5 , 9 ]
- Japanese authorities detain the suspect, who was travelling in Osaka, after obtaining a court warrant and a Tokyo High Court decision. [ 1 , 5 , 9 ]
- Japan hands the suspect over to Germany, which is investigating him on suspicion of extortion. [ 1 , 2 , 9 ]
- Asahi Shimbun publishes its report on the detention and handover. [ 1 ]
- Yahoo! News Japan publishes its aggregation of the report. [ 2 ]
- TBS NEWS DIG publishes its report on the detention and handover. [ 3 ]
- NHK reports the detention and the possible link to the Asahi Group Holdings attack. [ 4 ]
- Sankei Shimbun reports the detention in Osaka and the handover to Germany. [ 5 ]
- Jiji Press reports the detention, the joint investigation and the handover at Germany's request. [ 6 ]
- Nishi-Nippon Shimbun reports the detention and cites police agency figures on 2025 ransomware cases in Japan. [ 7 ]
- Tokyo Shimbun reports the detention and transfer of the Russian national to Germany. [ 8 ]
- Yomiuri Shimbun reports the case and cites a security company's figures on Qilin's claimed attacks. [ 9 ]