Skip to content
feed: live
0dayNews
ransomware

Germany Arrests Core Qilin Member After Japan Extradition

German authorities arrested a Russian national suspected of being a core Qilin ransomware member after extradition from Japan, confirmed by Japan's National Police Agency.

Germany Arrests Core Qilin Member After Japan Extradition
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
loopNadia "Loop" Park·Published ·1 min read

German authorities have arrested a Russian national suspected of being a leading member of the Qilin ransomware operation, following extradition from Japan. BleepingComputer reported the arrest on October 9; Japan’s National Police Agency confirmed the handoff separately, according to The Record.

The suspect was held in Japanese custody before transfer to Germany. German prosecutors have jurisdiction because Qilin attacks targeted German organizations.

What Qilin targets

Qilin is a ransomware-as-a-service operation whose affiliates have consistently gone after network edge gear as an entry point. The group has exploited Cisco Firepower Management Center deployments and the PAN-OS GlobalProtect vulnerability CVE-2026-0257 to gain initial footholds. Network appliances that are still running unpatched firmware from months ago are the kind of entry point that makes a compromised FMC far more damaging than a phished workstation.

The group has also hit healthcare, critical infrastructure, and enterprise environments in Germany, the UK, and Australia over the past two years.

What this arrest means operationally

Ransomware-as-a-service infrastructure does not shut down when a core member is arrested. Affiliates hold their own copies of the encryptor and affiliate panel access, and can continue deploying ransomware independently. The value of arrests like this is intelligence and disruption, not immediate shutdown.

German law enforcement has not named the suspect or filed public charges as of this writing.

For organizations still running products in Qilin’s known targeting list, Cisco FMC, PAN-OS GlobalProtect, and similar network management platforms, this is a reminder that the threat is live. Mitigations for the specific CVEs Qilin has used for initial access are available from each vendor. Confirm they are applied.

The arrest follows a pattern of coordinated international enforcement actions in 2026, including a parallel ShinyHunters takedown and ransomware negotiation fraud charges against MonsterCloud’s CEO.

Found this useful? Share it.