A Russian man whom German investigators describe as a core member of the Qilin ransomware gang was detained in Osaka in May and handed over to Germany on October 2. Days later, the gang sent a Japanese broadcaster a statement of its own. Japan, it said, is one of the countries with the worst computer security in the world. The verdict comes from the side doing the attacking, and the statement offered no evidence for it.
A Suspect Caught in Osaka, Tried in Germany
Qilin is the group that claimed the September 29, 2025 attack on the Japanese beer and beverage group Asahi Group Holdings, which disrupted its orders and shipments for months (we covered the damage here). Ransomware is malicious software that locks a victim's files by encrypting them; the attackers then demand payment, and increasingly also threaten to publish what they stole.
According to TBS, the suspect is a 28-year-old Russian national who was detained in Osaka in May. The German case against him is not about Asahi. He is suspected of stealing and encrypting data from a logistics company in the state of North Rhine-Westphalia in September 2024 and extorting about $165,000 in cryptocurrency. German reporting says he was responsible for building the attack systems and received part of the ransom.
The state's interior minister, Herbert Reul, and its justice minister, Benjamin Limbach, presented the case in Düsseldorf on October 7. The state criminal police (LKA NRW) and the prosecutors' cybercrime unit (ZAC NRW) had infiltrated the group and watched it for months. Reul put Qilin's toll at almost 4,000 companies and institutions worldwide since 2024, 150 of them in Germany. Across the whole group, ransom demands added up to almost $3 billion, and more than $140 million was actually paid.
The handover itself was unusual. Japan and Germany have no bilateral extradition treaty, and Japan has such treaties only with the United States and South Korea, as the German tech outlet heise noted.
One Group Builds the Tools, Hundreds Use Them
Qilin runs what is called ransomware as a service, or RaaS. A core team provides the malicious software and the technical infrastructure. Several hundred affiliates, separate crews, carry out the attacks and hand part of each ransom back to the operators. It works much like a franchise: the brand and the equipment come from the center, while the work is done by people the center may never meet.
In its statement, Qilin claimed to work with more than 300 anonymous people worldwide and said pressure from investigators had never once stopped it. Check Point Research counted 2,122 victims listed on ransomware leak sites in January to March 2026, and Qilin posted 338 of them, topping the list for a third straight quarter.
German officials see it differently. Reul's point was that investigators now know the group from the inside, and that its members can no longer be sure of each other.
Weighing "One of the World's Worst"
The statement did not come from the man in custody. TBS reported that Qilin sent JNN, its news network, an official statement on behalf of the team on October 7. In it, Qilin would neither confirm nor deny that the detained man was a colleague, and it accused the authorities of trying to ruin the life of someone not proven guilty.
The TBS headline said "the world's worst." The statement itself, as quoted in the body of the article, called Japan one of the countries with the worst computer security in the world. In the statement as TBS published it, no evidence was offered for that ranking. Qilin added that attacks on Japanese companies and government bodies may increase, and that this was not a threat but its professional view.
An extortion business has every reason to sound confident and to make targets feel exposed. In May, when TBS first reached the group, it said there was no longer any way to fully prevent a cyberattack. That line works in any language, against any country. And "worst" from an attacker most plausibly means easiest or most profitable to hit, which is a different measure from how well a country protects its people.
What the Rules Actually Require
Japan's law on strengthening cyber response capability, the legal basis for what the government calls active cyber defense, partly took effect on October 1, 2026. From that date, 258 operators in 15 critical-infrastructure sectors must report incidents on designated critical computer systems to the responsible minister and the prime minister. The government can also access and neutralize servers used in attacks. The use of communications data to spot those servers starts in autumn 2027.
The 15 sectors run from power and water to finance and telecoms. Food and drink are not among them, so a brewer like Asahi sits outside this duty. Japanese companies do face a separate, broader obligation: a business of any size whose personal data may have leaked through a malicious attack must report it to the Personal Information Protection Commission within 60 days of discovery.
The EU's NIS2 directive, which member states had to write into national law by October 17, 2024, casts a wider net. Food companies are covered once they reach medium size, such as 50 or more employees. A significant incident requires an early warning within 24 hours, a notification within 72 hours and a final report within a month. Management bodies must approve and oversee security measures and can be held liable for breaches. For the operators the directive treats as most essential, the fine ceiling is at least €10 million or 2% of worldwide turnover, whichever is higher.
The United States is not as far ahead as the "Japan lags" story assumes. Its critical-infrastructure reporting law, CIRCIA, requires reports within 72 hours for incidents and 24 hours for ransom payments, but its final rule only reached the White House Office of Management and Budget for review on October 1, 2026, and as of October 9 it was still pending and not in force. What does apply is a securities rule: listed companies must disclose a material cyber incident within four business days of deciding it is material, in force for most listed companies since December 18, 2023.
So Japan's new duty is narrower than NIS2 and puts no comparable liability on management. But the broadest American rule is still on paper. Whether Japan is "behind" depends entirely on what you measure.
Why Hit a Country That Doesn't Pay?
Japanese companies are unusually reluctant to pay. In a 15-country survey by the security firm Proofpoint, 18% of Japanese victims paid in 2022, the lowest of any country (we looked at why).
Asahi is a sharper example. At a November 27, 2025 press conference, president Atsushi Katsuki said the attackers had never made contact, so no ransom was demanded or paid. He added that he would ask them what they were after if he could.
So why spend effort on targets that do not pay? There is no settled answer. One way to read it is that RaaS affiliates work at volume and do not tailor their choices to national payment habits, and that a famous name on a leak site has value to a gang even without a payment. That is an interpretation, not something Qilin or the police have said. Japan also has a route back that does not involve the attackers at all: its National Police Agency has built tools that decrypt files locked by some ransomware families (details here).
"Don't Pay. Report It."
At the Düsseldorf press conference, Reul ended with an appeal to companies: if you are hit, don't pay, report it. Paying, he said, feeds the predator that just bit you. Going by the 2022 survey, most Japanese victims were already making the first half of that choice.
If a company in your country were hit tomorrow, who would it call first: the police, a regulator, its insurer, or the attackers?
References
- https://newsdig.tbs.co.jp/articles/-/2995228
- https://newsdig.tbs.co.jp/articles/-/2994191
- https://www.nippon.com/en/news/yjj2026100600755/
- https://www.zdfheute.de/politik/hackergruppe-qilin-nordrhein-westfalen-japan-100.html
- https://www.t-online.de/finanzen/aktuelles/id_101470606/nrw-gelingt-schlag-gegen-qilin-hacker-russe-festgenommen.html
- https://www.heise.de/en/news/Rare-occurrence-Japan-extradites-ransomware-suspect-to-Germany-11478532.html
- https://research.checkpoint.com/2026/the-state-of-ransomware-q1-2026/
- https://www.npa.go.jp/publications/statistics/cybersecurity/data/R7/R07_cyber_jousei.pdf
- https://www.cao.go.jp/cybersecurity/pdf/sekousetsumei.pdf
- https://www.ppc.go.jp/personalinfo/legal/leakAction/
- https://www.nis-2-directive.com/NIS_2_Directive_Article_23.html
- https://www.ruokavirasto.fi/en/foodstuffs/food-sector/setting-up-a-food-business/kyberturvallisuusdirektiivi-nis2-elintarviketoimialalla/
- https://digital-strategy.ec.europa.eu/en/policies/nis2-directive
- https://www.nis-2-directive.com/NIS_2_Directive_Article_20.html
- https://www.nis-2-directive.com/NIS_2_Directive_Article_34.html
- https://www.reginfo.gov/public/do/eoDetails?rrid=1550967
- https://www.hipaajournal.com/cisa-circia-final-rule-white-house-review/
- https://www.govinfo.gov/content/pkg/FR-2023-08-04/pdf/2023-16194.pdf
- https://www.proofpoint.com/jp/blog/threat-insight/Japans-Ransomware-Payment-Result-2023
- https://cloud.watch.impress.co.jp/docs/news/2066886.html
Global Discussion
4 comments