Skip to main content
Cyber News & CTI Reports :: 2026-10-09 | Germany arrests alleged core Qilin ransomware member after extradition
Contact Page | Privacy Policy

2026-10-09 | Germany arrests alleged core Qilin ransomware member after extradition

1. AI Summary

Germany has extradited a Russian national from Japan for alleged leadership in the Qilin ransomware group; the RaaS operation targets 2,350+ organizations across 62 countries via double-extortion attacks; notable victims include Nissan, Asahi, Lee Enterprises, ATF, and Court Services Victoria; the gang exploited Check Point and Palo Alto VPN vulnerabilities.

2. IOCs

IOC Type Value Description Relevant MITRE ATT&CK Techniques
Malwarename Qilin Most prevalent ransomware variant in 2025 T1486
Vulnerability Check Point VPN Exploited by Qilin for initial access to victim networks T1190
Vulnerability Palo Alto VPN Exploited by Qilin for initial access to victim networks T1190

3. MITRE ATT&CK

Code Title
T1190 Exploit Public-Facing Application (VPN zero-days/n-days)
T1560.001 Archive Collected Data via Utility (data staging)
T1486 Data Encrypted for Impact (ransomware encryption)

4. Targets

Type Value
Company Asahi
Company ATF
Company Court Services Victoria
Company Lee Enterprises
Company Nissan
Country Australia
Country Germany
Country Japan
Country United States
Sector Automotive
Sector Brewing
Sector Media and Publishing
Sector Public Administration

5. Article Details

6. Original text

Germany
has arrested a Russian national suspected of being a leading member of the
Qilin
ransomware group following extradition from
Japan
earlier this month.
Japan
has confirmed the extradition to
Germany
, with the National Police Agency saying that the suspect was detained after arriving in the country as a tourist. “When a Russian national for whom
Germany
had obtained an arrest warrant in connection with a ransomware incident in
Germany
arrived in
Japan
, the
Japan
ese Ministry of Justice, the Tokyo High Public Prosecutors Office, and
Germany
worked together to detain the suspect under the Extradition Law for Fugitives by obtaining a provisional detention warrant, and then facilitated the extradition,” [machine translated] reads the  press release . Earlier this week,
Japan
ese media reported the arrest based on internal sources, but authorities in the country have now officially confirmed the action.
Qilin
is a notorious ransomware-as-a-service (RaaS) operation that emerged in August 2022 under the name Agenda, and deployed typical double-extortion attacks, where data is stolen before being encrypted. The operation became one of the most active ransomware threats worldwide. By more recent statistics, the group targeted more than 2,350 known organizations across 62 countries. Among the victims are
Japan
ese automaker
Nissan
,
Japan
ese brewery
Asahi
, U.S. newspaper publisher
Lee Enterprises
, and
Australia
’s
Court Services Victoria
. The attack on
Asahi
,
Japan
’s largest beer producer, was particularly damaging, disrupting operations for an extended period and exposing sensitive details about 1.5 million people . More recently, the threat group hit the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (
ATF
) and was also linked to the exploitation of
Check Point VPN
zero-days and
Palo Alto VPN
n-day flaws . According to media publications,
Japan
detained the alleged
Qilin
leading member in May at a hotel in Osaka.

Despite this, the gang continued to be a major player on the ransomware stage. Since June, the group has listed more than 450 victims on its data leak site. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat