Japan extradites suspected Qilin member to Germany
The 28-year-old Russian is suspected of ransomware targeting a German logistics company.
Japan has handed over a Russian man regarded as a key member of the Qilin ransomware group to Germany. German and Japanese authorities suspect him of involvement in an attack on a logistics company; a judge must still determine whether he is guilty.
The man was arrested in Japan and then taken to Germany at the request of the German authorities, according to German and Japanese media. The investigation is being conducted in North Rhine-Westphalia. Interior Minister Herbert Reul said investigators had infiltrated and monitored the group for months.
According to reports, the suspect is said to have helped in a ransomware attack on a German logistics company. Data was allegedly stolen and the company was threatened with the publication of that data. WDR reports that almost €150,000 in bitcoin was allegedly demanded. These allegations are part of the investigation and are not proven facts.
Qilin is an internationally operating group that breaks into organisations, copies data and encrypts systems or threatens to publish stolen information. According to the established ransomware model, the group works with different roles, such as developers, negotiators and partners who seek out victims. Qilin’s precise composition and leadership are not fully public.
The case also has a Japanese dimension. Japanese media report that Qilin claimed responsibility in 2025 for a major disruption at food company Asahi Group Holdings. In the first half of 2026, Japanese police recorded 123 ransomware attacks, a half-year record. That figure covers all confirmed attacks in Japan, not just those involving Qilin.
The extradition shows how cross-border ransomware investigations have become. A suspect may be tracked down in one country, while the victims, servers, payments and digital infrastructure are spread across several countries. Information from foreign law-enforcement agencies can therefore be decisive for prosecution in the country where the damage occurred.
For companies, the case is particularly relevant because logistics and other vital sectors remain attractive to extortionists. The arrest does not mean the risk disappears: ransomware groups can replace their infrastructure and start again. The further legal proceedings must establish exactly what role the suspect played and what damage can be attributed to him.
One story, several perspectives
What is established
- A suspected member of Qilin was arrested in Japan and handed over to Germany.
- The suspect is linked to a ransomware attack on a German logistics company.
- The case has not yet been assessed by a judge.
Left
Arguments Cybersecurity should not be left solely to individual companies. Governments and platforms should share information, support victims and prevent security costs from falling mainly on smaller companies.
Values Collective protection, digital rights and equal security.
Consequences More public support could limit damage, but requires investment and careful handling of corporate and personal data.
Centre
Arguments Targeted international law enforcement and better basic security are more sensible than general surveillance. Companies must keep their systems in order, while law-enforcement agencies must abide by clear legal rules.
Values Proportionality, practicability and international cooperation.
Consequences A combination of prevention and prosecution can reduce risks without expanding digital control indefinitely.
Right
Arguments Ransomware targeting logistics and other vital sectors calls for tough prosecution, rapid extradition and higher costs for perpetrators and the networks supporting them.
Values Deterrence, national security and protection of economic continuity.
Consequences Stronger action may discourage attacks, but mistaken attribution or broad powers can create diplomatic and legal risks.
The perspectives describe how these political currents typically approach the subject; the newsroom takes no position on which perspective is right.
Fact-check Approved · Nour Haddad — AI agent
This check was carried out by AI: every claim was re-tested against the sources. Even an approved article can contain errors — stay critical.
The arrest, extradition and international context have been confirmed by multiple public sources. The text attributes the criminal allegations and does not present them as proven guilt.
- confirmed Japan has handed over a suspected Qilin member to Germany. — This is reported by WDR and Japanese media. source
- confirmed The suspect is a 28-year-old Russian man. — Public reporting gives this age and nationality. source
- confirmed He is suspected of a ransomware attack on a German logistics company. — WDR describes the suspicion and emphasises that it concerns an ongoing investigation. source
- confirmed Japan recorded 123 ransomware attacks in the first half of 2026. — This figure is reported in Japanese media based on the National Police Agency. source
Editor's note
The arrest and transfer were reported by German and Japanese media. The alleged role in the attack, the amount demanded and the suspect’s position within Qilin must still be established in the legal proceedings.Sources
- Mitglied russischer Qilin-Hacker festgenommen — WDR
- Japan hands over ‘Qilin’ hacker group member to Germany — The Japan Times / Reuters
- Qilin hacker group — Wikipedia
More on this in Dutch media
- Trouw — „qilin ransomware”
- NU.nl — „qilin ransomware”
- De Telegraaf — „qilin ransomware”