Japan has handed a Russian man to Germany, where he was arrested on suspicion of being a leading member of the Qilin ransomware gang, BleepingComputer reported on 9 October 2026. Japan's National Police Agency confirmed the transfer. It said Germany held a warrant linked to a ransomware attack in Germany. Japanese authorities detained him after he arrived as a tourist. Japanese media had run the story days earlier, citing internal sources.
Several points are still open. The report does not name the man. It does not describe the German case, the charges or the victim. Media reports said Japan first held him in May at an Osaka hotel, and the article does not explain the gap. Qilin began in August 2022 as Agenda. It uses double extortion: attackers steal data first, then lock the files, so victims face two threats. BleepingComputer counts more than 2,350 known targets in 62 countries, and over 450 victims listed on the group's leak site since June.
One arrest removes one person, not the group's methods. BleepingComputer says Qilin stayed active despite the May detention. It also links the group to Check Point VPN zero-days (flaws the maker did not know about) and to Palo Alto VPN flaws that were already known. VPN devices sit at the network edge. Buyers should ask how fast those devices get patched, and who owns that job.