Ransomware Group ‘Qilin’ Operative Detained in Osaka, Extradited to Germany — BigGo Finance | #ransomware | #cybercrime


A Russian national believed to be a core member of the ransomware group “Qilin,” which has repeatedly targeted corporations and public institutions worldwide, was detained in Japan and extradited to German authorities on October 2. The extradition, carried out under Japan’s Extradition Act, stems from extortion charges related to Bitcoin allegedly coerced from a German logistics company.

According to a report by the Asahi Shimbun on October 6, the man is suspected of gaining unauthorized access to a German logistics company’s terminals in September 2024, exfiltrating and encrypting data, and demanding Bitcoin worth $165,000 (approximately ¥26 million) as a condition for preventing its public release.

The man is believed to have been a key member responsible for building the attack infrastructure used by Qilin. Within the group’s structure, where multiple operational teams execute ransomware attacks, he was confirmed to have received a portion of the ransom payments.

Detained During Osaka Trip, Extradited After High Court Ruling

Japanese investigative authorities had prior intelligence on the man’s whereabouts. In late May 2025, he was detained while visiting Osaka as a tourist.

Subsequently, the Tokyo High Court approved the extradition, and the transfer to German investigative authorities was completed under Japan’s Extradition Act. The case represents a scenario where a cybercriminal who had evaded extradition by remaining in his home country was physically apprehended after a lapse in judgment during international travel.

The outcome is seen as a result of information sharing through the International Criminal Police Organization (ICPO) and the functioning of international mutual legal assistance frameworks. Japan’s National Police Agency Cyber Special Investigation Unit and other agencies continue to strengthen cooperation with investigative bodies in other countries to address cross-border cybercrime.

Qilin Also Claimed Responsibility for Asahi Attack

Qilin is known as a “Ransomware-as-a-Service” (RaaS) criminal organization, in which the developers and operators of ransomware are separate from the affiliates who actually carry out attacks.

In September 2025, Qilin claimed responsibility for a cyberattack on Asahi Group Holdings (2502.T), in which the company’s internal network was compromised, forcing the temporary suspension of operations at 30 domestic factories and six beer breweries across Japan. Order processing and logistics functions ground to a halt, causing widespread secondary damage including shipment delays on business partners’ e-commerce platforms.

The company also reported that more than 1.5 million personal records belonging to employees and business partners were leaked. It remains unclear whether the detained individual was personally involved in the Asahi attack.

Rising Ransomware Damage

According to research by blockchain analytics firm Chainalysis, the number of ransomware incidents in 2025 increased 50% year-over-year, while total payment amounts remained flat. This suggests that while attack frequency is rising, corporate defense postures and law enforcement crackdowns are also intensifying.

In 2025, Japan’s National Police Agency identified a North Korea-linked hacker group as responsible for the theft of approximately ¥48.2 billion (around $304.8 million) worth of assets from the cryptocurrency exchange DMM Bitcoin. As cybercrime becomes increasingly internationalized, this extradition stands as one of the notable outcomes of international joint investigations involving Japan.

Cases in which senior members of ransomware groups are detained in third countries and extradited to victim countries remain rare internationally. Because RaaS-type criminal organizations separate developers from operational units, apprehending individuals responsible for attack infrastructure is expected to have a disruptive effect on the organization’s overall activities.



Click Here For The Original Source.

——————————————————–

..........

.

.