Japan Transfers Suspected Qilin Ransomware Member to Germany

Summary
Japan transferred a 28-year-old Russian national to Germany over his suspected role in a 2024 ransomware attack on a German logistics company. He is alleged to have been involved with Qilin; authorities have not publicly identified him or released charges.
Key points
- Japanese authorities transferred the suspect to Germany on October 2, after his detention in Osaka in late May and approval by the Tokyo High Court.
- He is suspected of involvement in a September 2024 attack in which attackers allegedly accessed a German logistics company’s systems, stole and encrypted data, and threatened publication.
- The company reportedly paid about ¥26 million ($165,000) in cryptocurrency; investigators believe the suspect received part of the payment.
- Japanese media describe the suspect as a central Qilin member involved in developing or maintaining systems used by the ransomware operation.
- Current reporting does not link the suspect to Qilin’s claimed 2025 attack on Asahi Group Holdings.
- Neither the suspect nor the company has been publicly identified, and authorities had not released an official statement or public charging document at publication.
Article Details
- Event Type
- Transfer of a suspected ransomware operative from Japan to Germany for investigation
- Impact
- Investigators allege that attackers stole and encrypted data from a German logistics company in September 2024 and threatened to publish it. The company reportedly paid approximately ¥26 million in cryptocurrency.