SecurityReports disagree2 publishers2 min readPublished
Japan extradites an alleged Qilin core member to Germany after he arrived as a tourist
Japan detained a Russian national alleged to be a core Qilin ransomware member in Osaka in May and has extradited him to Germany. Qilin went on listing victims while he was held, more than 450 since June by BleepingComputer's count.
The Watch · Security desk

What happened
- Japan's National Police Agency confirmed the extradition and said the suspect was detained after he arrived in the country as a tourist.
- He was handed over to German authorities on October 2, SecurityWeek reported.
- Germany wants him for a September 2024 intrusion at a logistics company that encrypted its systems and extorted over $160,000 in cryptocurrency.
- By BleepingComputer's count, Qilin has targeted more than 2,350 known organisations across 62 countries.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Organisations running Check Point VPN and firewall products or unpatched Palo Alto VPNs face the same Qilin exploitation as before, because the group kept using edge-device flaws while the suspect was in Japanese custody.
- constraint Alleged Qilin members named in a German warrant now face a demonstrated arrest risk when they travel to Japan, or to any country prepared to act on such a warrant through provisional detention.
- precedent Germany won custody on the strength of one domestic intrusion and a ransom of just over $160,000, so a single national case was enough to reach an alleged core member of a group with thousands of claimed victims.
The legal route ran on one German warrant tied to one German incident. Japan's release reads, in BleepingComputer's machine translation: "When a Russian national for whom Germany had obtained an arrest warrant in connection with a ransomware incident in Germany arrived in Japan, the Japanese Ministry of Justice, the Tokyo High Public Prosecutors Office, and Germany worked together to detain the suspect under the Extradition Law for Fugitives by obtaining a provisional detention warrant, and then facilitated the extradition." [3] Japanese media reported the arrest earlier in the week from internal sources. The government confirmed it afterward [4].
SecurityWeek gives the suspect's age as 28 [10]. Media reports put the detention at an Osaka hotel in May [9]. From a May detention to the October 2 handover is a gap of roughly four to five months [16].
The public account of the German case covers only the logistics company [15]. Qilin's record runs much wider. SecurityWeek ties the group to the 2024 Synnovis intrusion that disrupted multiple London hospitals run by the NHS [11]. BleepingComputer lists Nissan, Asahi, Lee Enterprises and Court Services Victoria among its victims [7]. The two outlets disagree on Asahi: BleepingComputer puts the exposure at 1.5 million people [18], SecurityWeek at roughly 2 million [19].
For defenders, what the group did after the detention matters more than the arrest. Qilin is a ransomware-as-a-service operation that steals data before encrypting it [5]. BleepingComputer reported that the gang stayed a major player after the May detention [14]. In June, the month after he was detained, the group was exploiting CVE-2026-50751, a critical authentication bypass in Check Point VPN and firewall products, according to SecurityWeek [12][17]. BleepingComputer also links Qilin to Check Point VPN zero-days and Palo Alto VPN n-day flaws [8]. In August the US Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed a cyberattack after Qilin added the agency to its leak site [13].
The case shows that Japan's Extradition Law for Fugitives and a provisional detention warrant were enough to hold a visitor wanted in Germany and hand him over [2][3]. It is one case. Neither report documents other Qilin members detained while travelling, or any rise in arrests of ransomware suspects abroad.
What to watch
- Whether German prosecutors publish what role they say the 28-year-old held inside Qilin, or name further members or infrastructure.
- Whether Qilin's leak-site posting rate changes in the weeks after the October 2 handover.
- Whether other ransomware suspects under European warrants are detained during travel to Japan or elsewhere.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence66
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Germany has arrested a Russian national suspected of being a leading member of the Qilin ransomware group following extradition from Japan earlier this month.
- [2]
Japan's National Police Agency confirmed the extradition to Germany and said the suspect was detained after arriving in the country as a tourist.
- [3]
"When a Russian national for whom Germany had obtained an arrest warrant in connection with a ransomware incident in Germany arrived in Japan, the Japanese Ministry of Justice, the Tokyo High Public Prosecutors Office, and Germany worked together to detain the suspect under the Extradition Law for Fugitives by obtaining a provisional detention warrant, and then facilitated the extradition" (Japanese press release, machine translated by BleepingComputer).
ReportedSupportedSource: Japanese National Police Agency press release, as machine translated by BleepingComputer2 sources— create a free account to open themView cited source - [4]
Earlier this week, Japanese media reported the arrest based on internal sources, and authorities have now officially confirmed the action.
- [5]
Qilin is a ransomware-as-a-service operation that emerged in August 2022 under the name Agenda and deploys double-extortion attacks, stealing data before encrypting it.
- [6]
By recent statistics, the Qilin group targeted more than 2,350 known organizations across 62 countries.
- [7]
Qilin's victims include Nissan, Asahi, Lee Enterprises and Australia's Court Services Victoria.
- [8]
Qilin hit the US ATF and has been linked to exploitation of Check Point VPN zero-days and Palo Alto VPN n-day flaws.
- [9]
According to media publications, Japan detained the alleged Qilin leading member in May at a hotel in Osaka.
- [10]
The suspect, a 28-year-old Russian national, was detained in Osaka in May and was reportedly handed over to German authorities on October 2.
- [11]
In 2024, Qilin was blamed for hacking pathology services provider Synnovis and causing disruptions at multiple London hospitals run by the NHS.
- [12]
In June, Qilin was exploiting a critical authentication bypass vulnerability in Check Point VPN and firewall products, tracked as CVE-2026-50751.
- [13]
In August, the US Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed it had fallen victim to a cyberattack after Qilin added it to its leak site.
- [14]
Despite the detention, the gang continued to be a major player; since June, the group has listed more than 450 victims on its data leak site.
- [15]
The suspect was wanted in Germany for hacking into a logistics company in September 2024, encrypting data on its systems, and extorting it of over $160,000 in cryptocurrency.
- [16]
The gap between the May detention and the October 2 handover is roughly four to five months.
- [17]
Qilin's exploitation of CVE-2026-50751 was under way in June, the month after the suspect's May detention.
- [18]
The Asahi attack disrupted operations for an extended period and exposed sensitive details about 1.5 million people.
- [19]
The Asahi incident caused operational disruptions and compromised the personal information of roughly 2 million people.
Sources
2 independent publishers whose own reporting we read for this story.
- bleepingcomputer.comGermany arrests alleged core Qilin ransomware member after extradition
1 article · October 9, 2026
- securityweek.comQilin Ransomware Suspect Arrested in Japan, Extradited to Germany
1 article · October 7, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Cybercrime extradition and prosecutionFollow
- RansomwareFollow
- Ransomware-as-a-ServiceFollow
Entities
- Palo Alto NetworksFollow
- Lee EnterprisesFollow
- SynnovisFollow
- Check PointFollow
- National Health ServiceFollow
- CVE-2026-50751Follow
- Court Services VictoriaFollow
- QilinFollow
- Asahi GroupFollow
- Bureau of Alcohol, Tobacco, Firearms and ExplosivesFollow
- NissanFollow
- National Police Agency (Japan)Follow