Japan Arrests Qilin Ransomware Member and Extradites Him to Germany

· Original article ↗

Summary

A 28-year-old Russian man suspected of belonging to Qilin was arrested in Japan and extradited to Germany over a ransomware attack on a German logistics company. The article also describes Qilin’s activity and rising ransomware incidents in Japan.

Key points

  • Japanese authorities arrested the man in Osaka last May and handed him to German authorities on October 2.
  • He is suspected of infiltrating a German logistics company’s network in September 2024, stealing data, and demanding $165,000 in Bitcoin to keep it from being disclosed.
  • Qilin operates a ransomware-as-a-service model in which its core team provides malware and criminal infrastructure while recruited affiliates carry out attacks.
  • An NCC Group report cited in the article counted 1,022 Qilin attacks last year, the highest among ransomware groups, within a worldwide total of 7,874 attacks.
  • Japan recorded 123 ransomware cases in the first half of this year, its highest half-year total since tracking began in 2020; VPNs accounted for about half of infection routes over the period cited.
  • A ransomware attack on Osaka Public University caused about 500 servers to go offline; systems holding information on at least 130,000 current and former students were compromised.

Article Details

Event Type
Arrest and extradition of a suspected Qilin ransomware group member
Impact
The man is suspected of stealing data from a German logistics company in September 2024 and demanding $165,000 in Bitcoin to avoid disclosing it. The article does not report whether the ransom was paid.

Threat Actors

Countries

Industries

Related Articles