The arrest was confirmed by Japan's National Police Agency, which said Japanese and German authorities worked together to detain the man under the Extradition Law for Fugitives before handing him over to Germany. A machine-translated press release said Germany had obtained an arrest warrant in connection with a ransomware incident, and that a provisional detention warrant was obtained when the suspect arrived in Japan. Japanese media first reported the arrest this week based on internal sources; authorities have now officially confirmed it.
The suspect is alleged to be a leading member of Qilin, a ransomware-as-a-service operation that emerged in August 2022 under the name Agenda and deploys double-extortion attacks, in which data is stolen before being encrypted. The group has become one of the most active ransomware threats worldwide, targeting more than 2,350 known organizations across 62 countries by recent statistics.
Known victims include Japanese automaker Nissan, Japanese brewery Asahi, US newspaper publisher Lee Enterprises, and Australia's Court Services Victoria. The Asahi attack disrupted operations for an extended period and exposed sensitive data of 1.5 million people. More recently, the group has hit the US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) and has been linked to the exploitation of Check Point VPN zero-days.