Alleged core Qilin ransomware member, a 28-year-old Russian national, was arrested in Osaka in May and handed to Germany on 2 October over a 2024 attack on a German logistics company
A 28-year-old Russian national believed to be a core member of the Qilin (also called Agenda) ransomware group was detained in Osaka, Japan, in May 2026 and handed over to German authorities on 2 October, SecurityWeek reported on 7 October. Germany wants him for breaking into a logistics company in September 2024, encrypting its data and extorting more than US$160,000 in cryptocurrency. Qilin has run as a ransomware-as-a-service operation since August 2022 and is one of the most active groups: it was blamed for the 2024 Synnovis pathology attack that disrupted London NHS hospitals, claimed the Asahi Group attack, listed about 400 victims on its leak site in 2025, and this year exploited the Check Point VPN and firewall authentication bypass CVE-2026-50751. Qilin listings regularly name Australian organisations, and the group was named after the August 2026 cyber incident at the US ATF. Neither the suspect's name nor a German prosecutor's statement has been published in the reporting. Source: SecurityWeek.
- Product
- Qilin (Agenda) ransomware-as-a-service operation
- Versions
- n/a
- Exploited in Australia?
- unknown
- Patch to
- Nothing to patch. One arrest does not stop an affiliate model, so keep Qilin-relevant controls in place: patch edge VPN and firewall devices quickly, enforce phishing-resistant MFA on remote access, keep offline backups, and watch leak-site listings for your organisation and suppliers.
Primary: SecurityWeek — Qilin ransomware suspect arrested in Japan, extradited to Germany (7 Oct 2026) · Vendor: Cyberstack — ATF confirms cyber incident after Qilin listing (related card) · CVE: CVE-2026-50751
