Japan’s National Police Agency has confirmed the extradition of a 28-year-old Russian national linked to the Qilin ransomware gang, following an arrest based on a German warrant. The suspect was detained in Osaka in May while reportedly on vacation, and was subsequently extradited to Germany in June to face charges related to a ransomware attack on a German company.
The Qilin group has been implicated in numerous high-profile cyberattacks, including a significant incident involving the German political party Die Linke in April and a major breach affecting Japanese beverage company Asahi last year. The attack on Asahi was particularly damaging, disrupting its order processing and customer services while also leaking sensitive financial and employee data.
Details of the Extradition
Japanese authorities acted on an arrest warrant issued by Germany, which prompted a coordinated effort by Japan’s Ministry of Justice to detain the suspect. The operation began when officials learned of the suspect’s travel plans to Japan. Following the arrest at a hotel in Osaka, the extradition process was initiated, culminating in the suspect’s transfer to German law enforcement.
Qilin’s Criminal Activity
The Qilin ransomware gang has gained notoriety for its aggressive tactics and high-profile targets. In 2024, the group faced intensified scrutiny after a ransomware attack on a British healthcare provider that severely disrupted medical services. Despite this, Qilin continued its operations, launching attacks on various entities, including the government of Palau and major U.S. newspaper chains.
In 2026, Qilin was reported as the second most active ransomware group, with 127 attacks in July alone. Notably, the French rugby club Stade Français Paris confirmed it had fallen victim to the group, which has also claimed responsibility for an attack on the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF), allegedly stealing sensitive information related to ongoing investigations.
The extradition of the Russian national marks a significant development in the ongoing efforts to combat ransomware operations globally, highlighting the international cooperation between law enforcement agencies in addressing cybercrime.


