Qilin Ransomware Suspect Arrested in Japan, Extradited to Germany
A 28-year-old Russian national faces charges in Germany over a $160,000 extortion of a logistics company. The arrest comes as Qilin keeps up a punishing pace, and as a critical flaw in widely used VPN software gives the group a fresh way in.

Key points
- A 28-year-old Russian national was detained in Osaka in May 2025 and extradited to Germany on October 2, where he faces charges tied to a September 2024 attack on a German logistics company.
- Germany says the suspect extorted the logistics firm of more than $160,000 in cryptocurrency after encrypting the company's files.
- Throughout 2025 Qilin listed 400 victims on its dark-web leak site.
- Qilin was actively exploiting CVE-2026-50751 in June 2025, a critical flaw rated 9.3 out of 10 that lets an attacker break into a Check Point VPN without valid credentials.
- US federal agencies faced a June 11 deadline to patch that flaw after CISA added it to its Known Exploited Vulnerabilities catalogue on June 8.
German prosecutors got their man. Japanese police detained the suspect in Osaka in May, and on October 2 he stepped off a plane into German custody. He's described as a core member of Qilin, also tracked under the name Agenda, a ransomware-as-a-service (RaaS) operation: a criminal franchise where a central team builds the attack software and rents it to affiliated hackers who carry out break-ins in exchange for a cut of any ransom paid.
The charges stem from a September 2024 attack on a German logistics firm. Qilin-affiliated hackers broke in, locked the company's data using ransomware (malicious software that scrambles files and demands payment to restore them), and collected more than $160,000 in cryptocurrency before investigators traced a path back to the suspect.
How dangerous is Qilin right now?
Very. Arrests rarely slow these operations for long. Throughout 2025 the group posted 400 victims on its Tor-based leak site. The pace hasn't let up: we reported on Qilin's claim against Texas-based lender Genesis Credit Management just three days ago, and our 24 September story on Storm-2570 showed how a single affiliate was bouncing between Qilin and at least three other ransomware crews, the kind of flexibility that makes takedowns harder.
The group has a record of high-impact attacks. In 2024 it hit Synnovis, a pathology lab processing blood tests for London hospitals run by the National Health Service, disrupting patient care for weeks. Last year it claimed a breach of Asahi Group, the Japanese drinks company, with personal data on roughly two million people said to be involved. In August, the US Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed it had fallen victim after Qilin added it to the leak site.
How did the group get into so many networks?
One key route: a severe flaw in Check Point Security Gateways. Many companies use these products to run a VPN, an encrypted tunnel letting employees connect to company systems remotely. The flaw, CVE-2026-50751, scores 9.3 out of 10. It sits in an older protocol called IKEv1, used during VPN setup, and it lets an attacker log straight in without a username or password.
Qilin was exploiting it in June 2025. CISA, the US government's cybersecurity agency, added it to its known-exploited list on June 8 and ordered federal agencies to patch by June 11.
If your organisation runs Check Point VPN products and hasn't applied that patch, treat it as urgent. Employees at affected companies should flag any unexpected password-reset requests or login prompts to their IT team immediately.
Should you worry?
The arrest is a real enforcement win, first reported by SecurityWeek. But Qilin's a franchise, not a single actor. One suspect in custody doesn't switch the operation off, and the pace of claimed listings suggests the rest of the network hasn't noticed.



