A total of 53 companies in Japan have been targeted by an internationally active ransomware group known as Qilin, National Police Agency officials said Thursday.
Qilin, believed to be behind a 2025 cyberattack on Japanese beverage maker Asahi Group Holdings Ltd., has drawn renewed attention in Japan after investigative authorities recently handed over to Germany a detained Russian national suspected of being a key member of the group. The man has since been arrested by German authorities.
The cybercrime group began operating around October 2022 and has attacked some 4,000 companies worldwide, with its activities in Japan confirmed since April 2023, according to the agency.
The 53 Japanese victims span manufacturing, services, construction, hospitals and schools, but their names have not been disclosed.
In ransomware attacks, hackers block access to data and demand payment to restore it.
German authorities had requested that Japanese investigators detain and hand over the 28-year-old Russian man transferred to Germany, according to a source familiar with the matter.
The man, who was on a trip to Japan, had been placed in a detention facility after he was found at a hotel in Osaka in May. He was handed over to German authorities earlier this month.
The man allegedly extorted crypto assets from a German logistics firm in 2024, according to the source.
Meanwhile, following a series of reports of data leaks caused by unauthorized access, the Japanese government decided to urge businesses to address system vulnerabilities and prevent the misuse of leaked information, cybersecurity minister Toshiharu Furukawa said.
Recent cases include a data breach at Japan's "Times Car" car-sharing service that exposed information from about 6.6 million accounts, including images of 1.6 million driver's licenses, as well as cyberattacks against Daiwa Securities Group Inc. and the operator of the Yakiniku King barbecue restaurant chain.