Tendvane

← All articles

SecurityOctober 10, 2026

A holiday in Osaka ended one Qilin operator's run

He flew to Japan as a tourist in May. Police there already knew he was coming and took him in at a hotel in Osaka, acting on a German arrest warrant. Five months later, with the Tokyo High Court's approval, he was handed over and arrested in Germany. He is 28, Russian, and prosecutors say he extorted German companies for cryptocurrency.

German investigators know him as Snake, and put him among the eight people who form the core of Qilin, the operation that led the attack counts for July to September. Qilin appeared in August 2022 under the name Agenda and has since claimed more than 2,350 organizations across 62 countries. Nissan is on the list, so are the American newspaper group Lee Enterprises and Court Services Victoria in Australia, and so is the brewer Asahi, whose breach spilled data on 1.5 million people.

His arrest changed nothing. He had been sitting in a Japanese cell since May, and Qilin still posted over 450 fresh victims through June alone. That is how ransomware as a service is built: a small core writes and runs the platform, affiliates do the breaking in, and taking one person out of the middle alters the staff list rather than the business.

Arrests like this are worth cheering and worth nothing to you personally. They do not lower the odds that a company holding your details gets hit this month, and they do nothing at all for the files sitting on your own hard drive. Keeping a second copy of those does, and Tendvane will copy Documents, Pictures and Desktop onto an external drive in one go whenever you plug one in.

Sources

Download Tendvane