
Japan extradites suspected Russian Qilin ransomware developer to Germany
A 28-year-old Russian national accused of developing ransomware for the Qilin group has been extradited from Tokyo to Germany following a months-long undercover operation by North Rhine-Westphalia police.
Infiltration and cross-border arrest
German law enforcement authorities in North Rhine-Westphalia confirmed the arrest and extradition of a 28-year-old Russian national identified as Vladimir K., an alleged core developer of the Russian ransomware network Qilin. Known online by the alias Snake, the suspect was detained by Japanese police on 26 May 2026 while on holiday with his girlfriend in Osaka. The arrest followed months of covert work by the North Rhine-Westphalia State Criminal Police Office (LKA) and the Central and Contact Point for Cybercrime (ZAC), based at the Cologne public prosecutor's office. Investigators infiltrated the group's communications channels, monitored its operations, and tracked financial flows through cryptocurrency exchanges to uncover the suspect's real identity.
Interior Minister Herbert Reul announced the operation during a joint press conference in Dusseldorf on 7 October 2026.
We caught one of the leaders of this group: with the assistance of the Japanese police, we managed to detain a 28-year-old Russian in Tokyo in May.
- Ransomware group emerges under the initial name Agenda
- Suspect conducts ransomware attack against a German logistics company
- Japanese police arrest Vladimir K. in Japan during a vacation
- Suspect arrives at Frankfurt Airport on flight LH717 and enters German custody
- German officials announce the arrest and extradition in Dusseldorf
Extradition without a bilateral treaty
Following his detention in Japan, the suspect was handed over to German custody and transferred to Germany on 2 October 2026. Flight LH717 from Tokyo landed at Frankfurt Airport at approximately 16:20 local time, after which the 28-year-old was placed in pre-trial detention. The handover took place despite the absence of a formal bilateral extradition treaty between Germany and Japan. German Ambassador to Tokyo Petra Sigmund and regional ministers thanked Japanese authorities for executing the transfer based on evidence provided by German investigators.
Justice Minister Benjamin Limbach noted that the outcome demonstrated the strength of the digital evidence gathered during the covert phase of the investigation.
In the end, there was a name behind the pseudonym.
Limbach added that Japanese cooperation without a treaty reflected mutual trust in the investigation.
That shows that our investigative results are also convincing internationally.
Financial scale and corporate targets
The Qilin syndicate has extorted nearly 4,000 companies and public institutions worldwide since 2024. According to German investigative findings, global ransom demands from the group reached roughly $2.9 billion (around €2.7 billion), with targeted entities paying more than $140 million (around €125 million) in extortion fees. In Germany, the group struck 152 companies, including 30 located in North Rhine-Westphalia. Attackers demanded €62.6 million from German targets, extracting €6.5 million in payments.
- Demanded
- 62.6 €M
- Paid
- 6.5 €M
Specific cases linked to the suspect include a September 2024 intrusion against a German logistics enterprise. The attacker encrypted internal systems, extracted corporate files, and demanded €147,000 (roughly €150,000 in Bitcoin) to withhold public release. In Japan, Qilin crippled systems at food and beverage conglomerate Asahi Group in 2025, disrupting operations for several weeks.
Operational structure of the Qilin network
Classified as a criminal organization by the Federal Criminal Police Office (BKA), Qilin emerged in 2022 under the name Agenda before rebranding. The syndicate operates as a ransomware-as-a-service enterprise, developing malware and infrastructure while leasing access to affiliate hackers in exchange for a percentage cut of ransom payments. The group relies on double extortion, combining system encryption with data theft and threats of public leaks. Vladimir K. is accused of developing core software tools for the syndicate and profiting directly from extortion proceeds.

