Drooid Logo
Back to story perspectives

Full Breakdown

Japanese Extradition of a Core Qilin Ransomware Member to Germany

By Drooid · · How we work

The Extradition Event

On October 2, a 28-year-old Russian national identified as a core member of the Qilin ransomware group was transferred from Japan to German authorities. Japanese police detained the suspect in Osaka in late May while he was vacationing, and the Tokyo High Court approved the hand-over under Japan’s Extradition Act. German investigators allege that he participated in a September 2024 attack on a logistics company in North Rhine-Westphalia, encrypting data and demanding approximately $165,000 (about ¥26 million) in Bitcoin.

Background & Context

Qilin, also known as “Agenda,” emerged in October 2022 and operates as a ransomware-as-a-service platform, supplying malware and infrastructure to affiliates. By 2026 the group claimed responsibility for attacks on roughly 4,000 companies worldwide, including a high-profile outage at Japan’s Asahi Group Holdings in 2025 and a breach of a German logistics firm in 2024.

Japan has seen a surge in ransomware activity, with the National Police Agency recording 123 ransomware attacks in the first half of 2026, the highest semi-annual total since 2020. Unauthorized-access incidents involving Japanese entities rose to 600 between January and September 2026.

Timeline

  • October 2 – Flight from Tokyo to Frankfurt and hand-over to German investigators.
  • October 6 – Media reported details of the alleged September 2024 German logistics attack.

Data & Statistics

  • ? 4,000 companies – global victims claimed by Qilin since 2022.
  • 123 ransomware incidents – recorded in Japan’s first half of 2026.
  • 600 unauthorized-access incidents – disclosed in Japan from January to September 2026.

Official Statements & Responses

A senior official from Japan’s National Police Agency called the case “significant” for demonstrating the results of international cooperation. German authorities, represented by the North Rhine-Westphalia State Criminal Police Office, described the suspect as a developer who received a substantial share of ransom proceeds.

Why It Matters

1. Ransomware industrialisation – Qilin’s RaaS model separates infrastructure development from attacks, allowing operations across jurisdictions.

2. Cross-border enforcement – Coordination between Japanese and German law-enforcement agencies, facilitated by Interpol and mutual legal assistance, shows the practical value of international legal mechanisms.

Verbatim Quotes

  • “This is the biggest blow German investigators have managed to strike in the fight against cybercrime.” — Interior Minister Herbert Reul, Rhine-Westphalia interior minister

What’s Next

German prosecutors are expected to pursue charges related to extortion and unauthorized data access. Japanese authorities have indicated continued efforts to strengthen cyber-crime cooperation with international partners.