A 28-year-old Russian national, identified as an alleged member of the Qilin ransomware group, was arrested in Osaka, Japan, in May. The suspect was subsequently extradited to Germany on October 2. German authorities sought the individual for a ransomware attack that occurred in September 2024 against a logistics company, which resulted in data encryption and an extortion demand of over $160,000 in cryptocurrency.
Qilin, also known as Agenda, has been active since August 2022 and operates as a ransomware-as-a-service (RaaS) model. The group has been responsible for numerous cyberattacks worldwide, causing significant financial damages and operational disruptions. In 2025, the group listed 400 victims on its leak site.
In 2024, Qilin was linked to an attack on pathology lab services provider Synnovis, which disrupted operations at multiple London hospitals. Last year, the group claimed responsibility for hacking Asahi Group, leading to operational issues and the compromise of personal information for approximately 2 million individuals. More recently, in August, the US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed it was a victim after Qilin added it to its leak site. In June, Qilin was exploiting a critical authentication bypass vulnerability in Check Point VPN and firewall products, tracked as CVE-2026-50751.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
An alleged member of the Qilin ransomware group was arrested in Japan and extradited to Germany, where the individual is wanted for a ransomware attack against a logistics company. This arrest targets a core member of a prolific ransomware-as-a-service operation responsible for attacks on hundreds of organizations globally.