Japanese investigators detained a core member of the international ransomware group Qilin in Osaka in May and handed over the Russian national to Germany on Oct. 2, sources said.
German authorities, which are investigating the 28-year-old man on suspicion of extortion, had requested his detention and extradition.
Qilin has repeatedly carried out cyberattacks against companies and other organizations around the world.
Last year, the group claimed responsibility for a ransomware attack on Asahi Group Holdings Ltd., which disrupted its order processing and shipment operations.
Law enforcement agencies in Japan, Germany and other countries have been conducting joint investigations.
The handover was carried out under the Extradition Law, which sets rules for transferring fugitives wanted in connection with criminal cases committed abroad.
According to sources, the Russian national is believed to have accessed terminals at a logistics company in Germany in September 2024 and illegally obtained and encrypted data.
He is suspected of having extorted the company by threatening to release the information unless the company paid $165,000 (26 million yen) in bitcoin.
The man is said to have been responsible for building systems used in ransomware attacks.
Investigators said Qilin operates through multiple operational units that carry out ransomware attacks under the direction of core members, such as the suspect.
The ransom payments collected by operational teams are allegedly passed on to the group’s leadership.
Authorities have confirmed that the suspect received part of the proceeds in the case under investigation.
Japanese investigators obtained information about the man’s whereabouts in advance.
After securing a warrant from the Tokyo High Court, they detained him in late May while he was traveling in Osaka.
Following a Tokyo High Court ruling that the case met the requirements for extradition, Japan handed the suspect over to Germany.
GANG SAID ‘ONE OF THE MOST ACTIVE’
Ransomware is a type of malicious software that encrypts data on computers and other devices, rendering it unusable until a ransom is paid for restoration.
According to Mika Fukuda, a ransomware expert at Mitsui Bussan Secure Directions Inc., Qilin’s activities have been tracked since around the middle of 2022.
The group posts information about victimized companies and organizations on its “leak site.”
The number of listings has recently ranged from dozens to about 100 per month.
“Qilin is one of the most active large-scale ransomware groups,” Fukuda said, adding that its activities appear to be expanding globally.
Data compiled by Mitsui Bussan Secure Directions found that Qilin posted information on 161 victims on its leak site in August, the highest number among about 370 ransomware groups monitored by the company.
In September, the group listed 75 cases, the second highest.
This year, 14 companies and organizations in Japan appeared on Qilin’s leak site.
Japanese police recorded 123 ransomware attacks during the first half of this year, the highest figure since semiannual statistics began in 2020.
According to the National Police Agency, ransomware cases totaled 226 nationwide last year, with the annual figure hovering around 200 in recent years.
Of the 1,021 cases reported over the past five years, 583 involved small and midsize enterprises, accounting for about 60 percent of the total.
Large companies were affected in 310 cases.
By industry, manufacturing accounted for 353 cases, followed by service with 153 and wholesale and retailing with 148.
A survey of affected companies and organizations found that the most common infection route was through virtual private networks, accounting for about half of the cases.
The NPA has reported a growing use of a tactic known as “Ransomware as a Service,” or RaaS.
Under the arrangement, ransomware developers provide malware to cybercriminals who carry out attacks and receive a cut of the ransom in return.
This scheme allows criminals without advanced skills or specialized knowledge to launch sophisticated cyberattacks, resulting in a wider pool of perpetrators.
Qilin is believed to be one of the criminal organizations operating a RaaS provider.
