Japan extradites suspected Qilin operative to Germany over ransomware extortion
Japan detained a 28-year-old Russian national in Osaka in May and handed him to Germany on 2 October, where he is wanted over a ransomware attack on a German logistics company. The case links to Qilin, which claimed responsibility for a 2025 attack that disrupted Japanese drinks maker Asahi’s operations.
Bottom line — The suspect is accused of demanding €142,000 ($165,000) in Bitcoin from a German company.
Go deeper 5
-
According to Asahi, the suspect is believed to have accessed the German company’s terminals in September 2024, stolen and encrypted data, and threatened to publish it unless paid.
-
Asahi reports that he was suspected of building systems used in Qilin attacks and received part of the proceeds in the German case.
-
The Asahi report says a Tokyo High Court ruling found the extradition requirements were met before Japan transferred him to Germany.
-
NHK reports that Qilin claimed to have stolen data from Asahi’s network in the 2025 attack; the articles do not establish whether the suspect was involved.
-
Mitsui Bussan Secure Directions data cited by Asahi recorded 161 Qilin victim listings in August, the highest among about 370 ransomware groups it monitored.