Qilin ransomware group has hit 53 companies in Japan since 2023

· CyberSecurity

TLDR

  • Japan's National Police Agency says the Qilin ransomware group has attacked 53 companies in Japan since its activity there was first confirmed in April 2023, spanning manufacturing, services, construction, hospitals and schools.1
  • Qilin, which began operating around October 2022, has attacked roughly 4,000 companies worldwide and is believed responsible for a 2025 cyberattack on Japanese beverage maker Asahi Group Holdings.12
  • Japanese police detained a 28-year-old Russian national suspected of being a key Qilin member at an Osaka hotel in May and extradited him to Germany earlier this month, where he has since been arrested on extortion charges tied to a 2024 attack on a German logistics firm.2
  • Japan's cybersecurity minister, Toshiharu Furukawa, said the government will urge businesses to fix system vulnerabilities, citing recent unrelated breaches including one exposing 6.6 million "Times Car" car-sharing accounts.1

The National Police Agency disclosed the 53-victim count on Thursday, saying the names of the affected organisations have not been released.1 Qilin operates through a network of affiliates who carry out the intrusions and extortion using ransomware supplied by core members responsible for malware development and system management, encrypting victims' data and threatening to publish it if they refuse to pay.2

The disclosure followed Japan's extradition of the suspected Qilin member to Germany. According to the Japan Times, German authorities had obtained an arrest warrant for the 28-year-old Russian citizen over the alleged extortion of cryptocurrency from a German company; after learning he planned to visit Japan as a tourist, the NPA's cyber special investigation department tracked him down through a joint operation involving the Tokyo, Osaka and Kyoto police departments and detained him at an Osaka hotel in May.2 He was handed over to German authorities this month following a Tokyo High Court extradition ruling.2 "It was significant that we identified and arrested a [Qilin] member through international cooperation," a senior NPA official said.2 Kyodo News reports the man allegedly extorted crypto assets from a German logistics firm in 2024.1

The case has drawn renewed domestic attention to Qilin's activity in Japan, where it has operated since April 2023 and is believed to be behind the 2025 breach of Asahi Group Holdings.12 Separately, Kyodo reports that following a run of unrelated data-leak disclosures in Japan, including a breach of the "Times Car" car-sharing service exposing roughly 6.6 million accounts and 1.6 million driver's licence images, plus attacks on Daiwa Securities Group and the operator of the Yakiniku King restaurant chain, cybersecurity minister Toshiharu Furukawa said the government will press businesses to address system vulnerabilities and prevent leaked information from being misused.1

Why it matters: 53 confirmed Japanese victims out of roughly 4,000 Qilin has hit worldwide shows the group's affiliate model scaling attacks across sectors as different as hospitals, schools and manufacturers, and the Osaka arrest demonstrates one of the few concrete enforcement wins against an active ransomware operator rather than just another victim-count disclosure.

Sources

  1. 53 companies in Japan hit by Qilin ransomware group (Kyodo News)
  2. Germany arrests member of Qilin hacker group who was extradited from Japan (The Japan Times (JIJI))