Skip to main content

Morning Overview

Germany arrested an alleged core Qilin ransomware member after Japan extradited him

A 28-year-old Russian man detained at an Osaka hotel in late May was handed over to Germany on October 2, 2026 and is now in German custody as an alleged leading figure in the Qilin ransomware group. North Rhine-Westphalia officials announced the case at a press conference in Düsseldorf on October 7, calling it the first arrest of a member of the gang.

The suspect had gone to Japan as a tourist, according to Japan’s National Police Agency as relayed by BleepingComputer, and Germany had a warrant tied to a ransomware attack on a company in its own territory in September 2024.

From a hotel in Osaka to a German cell

Der Spiegel, as summarized by Ukraine’s Liga.net, puts the Japanese arrest on May 26. ZDFheute reported that he was handed over to Germany on the Friday before the announcement, around October 2, and that Japan agreed to extradite him even though the two countries have no bilateral extradition treaty; the evidence gathered in North Rhine-Westphalia also persuaded the Japanese courts, the broadcaster said. BleepingComputer adds that Japan’s Ministry of Justice and the Tokyo High Public Prosecutors Office worked with German authorities under Japan’s law on extradition of fugitives, using a provisional detention warrant.

The German investigation sits with two units of the North Rhine-Westphalia government: the State Criminal Police Office (LKA NRW) and the Central and Contact Point for Cybercrime (ZAC NRW). The state’s press invitation for October 7 named Interior Minister Herbert Reul and Justice Minister Benjamin Limbach as the speakers and described the event as the announcement of an arrest and extradition, adding that a background briefing with LKA cybercrime specialists would follow the statements. None of the sources read names the prosecutor or court handling the case, and the formal charges have not been published.

The September 2024 logistics attack behind the warrant

The only specific allegation reported is the September 2024 attack. Qilin hit a company in North Rhine-Westphalia, stole and encrypted data and threatened to publish it, per ZDFheute. Japanese media put the ransom at about $165,000 in Bitcoin and say the suspect built attack infrastructure and took part of the payment. SecurityWeek’s October 7 report describes the target as a logistics company and the demand as more than $160,000 in cryptocurrency.

His name has not been given officially. Liga.net’s photo caption calls him “Volodymyr K.” while Der Spiegel is quoted using “Vladimir K.”, and the same report says he operated under the alias “snake.” Those details come from press reports, not from a statement by the authorities, and the discrepancy in the spelling is itself a reason to treat the identification as unconfirmed until the German authorities publish a name or an indictment.

Infiltration, and the scale of Qilin’s operation

Reul called the case a historic blow and said it was the first time authorities had successfully infiltrated such a network, ZDFheute reported. Investigators from LKA NRW and the cybercrime unit monitored the group for months, and the case grew from a small clue in the 2024 investigation. Limbach said that in the end “a name stood behind the pseudonym.” Both ministers said the group should now be uncertain of its safety.

The numbers attached to Qilin differ by source and by what they count. Officials cited by ZDFheute say the group has extorted nearly 4,000 companies worldwide since 2024, about 150 in Germany and about 30 in North Rhine-Westphalia, with demands totaling almost $3 billion and more than $140 million actually paid. BleepingComputer’s report instead cites statistics of more than 2,350 known organizations across 62 countries and over 450 victims listed on the leak site since June.

The victims named in the reporting

The same reporting ties Qilin to Asahi, the Japanese brewer whose operations were disrupted for an extended period, Nissan’s design studio, the U.S. newspaper publisher Lee Enterprises, Court Services Victoria in Australia and, according to BleepingComputer, the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives, which confirmed a “major incident” after Qilin posted claims. ZDFheute also links the group to a March 2026 attack on the German party Die Linke.

BleepingComputer also lists Qilin’s lineage: the operation emerged in August 2022 under the name Agenda as a ransomware-as-a-service business, selling its tools to affiliates, and uses double extortion, stealing data before encrypting files. The same report says the group was linked to exploitation of Check Point VPN zero-days and Palo Alto GlobalProtect flaws, which helps explain how a single crew reached so many organizations in so many countries.

Reul and Limbach said investigations into the wider group continue. The sources read do not say whether other members have been identified, and a trial date and formal charges remain unannounced. Liga.net reports that he is set to stand trial in Germany, a claim the NRW government has not detailed in the material available.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview


Morning Overview is reader-supported. Some links in our articles are affiliate links, and we may earn a commission at no extra cost to you. As an Amazon Associate I earn from qualifying purchases. Full disclosure.