An alleged member of the Qilin ransomware group was arrested in Japan and subsequently extradited to Germany.
The suspect, a 28-year-old Russian national, was detained in Osaka in May and was reportedly handed over to the German authorities on October 2.
Believed to be a core member of the ransomware gang, the individual was wanted in Germany for hacking into a logistics company in September 2024, encrypting data on its systems, and extorting it of over $160,000 in cryptocurrency.
Also known as Agenda, Qilin has been active since August 2022 and has become one of the most prolific ransomware-as-a-service (RaaS) operations, hitting hundreds of organizations worldwide and causing millions of dollars in damages.
In 2024, the group was blamed for hacking into pathology lab services provider Synnovis and causing disruptions at multiple London hospitals run by the National Health Service.
Last year, Qilin claimed responsibility for hacking beer giant Asahi Group. The incident caused operational disruptions and resulted in the personal information of roughly 2 million people being compromised.
Throughout 2025, the group listed 400 victims on its Tor-based leak site, including Lee Enterprises and pharma company Inotiv.
In June this year, Qilin was exploiting a critical authentication bypass vulnerability in Check Point VPN and firewall products, tracked as CVE-2026-50751.
In August, the US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed it had fallen victim to a cyberattack after Qilin added it to its leak site.
Related: FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware
Related: Alleged ShinyHunters Leader Arrested in Jordan
Related: In Rare Move, Alleged Iranian State Hacker Extradited to US
Related: Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader


