Japan extradited 28-year-old Russian national Vladimir K. to Germany, where investigators suspect that he is one of the key members of the Qilin hacking group, according to a report by Der Spiegel. K., known online by the nickname “snake,” was detained in Osaka on May 26 while vacationing there with his girlfriend. He was flown from Tokyo to Frankfurt on Oct. 2 and is now in custody.
According to the North Rhine-Westphalia State Criminal Police Office, K. worked for Qilin primarily as a developer and received a substantial share of the ransom payments it facilitated. The group emerged in 2022 under the name Agenda and rents ransomware attack infrastructure to other criminals in exchange for a percentage of the proceeds. Germany’s Federal Criminal Police Office considers Qilin a criminal organization.
Investigators identified the Russian suspect after Qilin attacked a logistics company in North Rhine-Westphalia in September 2024 and demanded $165,000 in bitcoin. During a covert investigation, police gained access to the group’s network and K.’s computer, learning among other things that he planned to travel to Japan. German authorities then alerted their Japanese counterparts. Germany and Japan do not have an extradition treaty, but extradition can still take place after judicial review.
In Germany alone, 152 organizations have been targeted by Qilin, with the group demanding more than $70 million in total. About one-tenth of that amount was paid. Over the course of four years, the group sought $2.9 billion in ransom payments worldwide, and victims transferred more than $140 million. North Rhine-Westphalia Interior Minister Herbert Reul said:
“This is the biggest blow German investigators have managed to strike in the fight against cybercrime.”
Authorities have identified three other leading Qilin members, but they are believed to be in Russia.
In June, The New York Times reported that an investigation into the hacking of UK automaker Jaguar Land Rover found links between the attack and Russian hackers. The August 2025 cyberattack became the most costly in British history, shutting down the automobile company’s operations for several weeks.
