Asahi Qilin Ransomware Operative Extradited to Germany After Arrest in Japan
Article Content
- •A Russian national linked to Qilin was arrested in Japan and extradited to Germany.
- •He is accused of extorting a German logistics firm for $165,000 in Bitcoin.
- •Qilin has been responsible for multiple high-profile ransomware attacks, including one on Asahi Group.
A 28-year-old Russian national, a core member of the ransomware group Qilin, was detained in Osaka, Japan, in May 2025 and extradited to Germany on October 2, 2026. He is accused of extorting a German logistics company by accessing its systems in September 2024 and demanding $165,000 in Bitcoin to prevent the release of encrypted data. Qilin, known for its extensive ransomware operations, claimed responsibility for a significant attack on Asahi Group Holdings in September 2025, disrupting operations at multiple facilities. The suspect's arrest was facilitated by international cooperation among law enforcement agencies, highlighting the ongoing efforts to combat cross-border cybercrime. Qilin has been active since mid-2022, with reports indicating it has targeted numerous organizations globally, making it one of the most prolific ransomware groups.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Qilin and Asahi Group Holdings in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What charges does the suspect face?
How has Qilin impacted businesses?
What measures are being taken against Qilin?
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
CISA Adds Multiple Exploited Flaws in AI and Networking Tools to KEV Catalog On September 11, 2026, CISA added five actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. These vulnerabilities include CVE-2026-42016, which has a CVSS score of 8.1. This update follows the addition of…