decrypted · 10 october 2026 · ransomware and cybercrime · vulnerabilities and patching · uk policy and law
A Qilin arrest is welcome, but the ransomware franchise runs on unlocked doors
A 28-year-old Russian man alleged to be a core member of the Qilin ransomware gang has been handed from Japan to Germany, and Japan's National Police Agency confirmed the arrest this week. It is a rare win against a group that has disrupted UK health services. It is also a good moment to ask what actually keeps a ransomware gang in business, because the answer is rarely its people. It is the unlocked doors they walk through.
What happened
Japanese police detained the man in Osaka in May, and SecurityWeek reports he was handed to Germany on 2 October. Germany wants him over a September 2024 attack on a logistics company, in which systems were encrypted and more than $160,000 in cryptocurrency was extorted. He has not been named in the reporting I could verify, and formal charge details have not been published. Qilin has operated since August 2022 as ransomware as a service, stealing data before it encrypts anything.
The franchise problem
Think of Qilin as a restaurant franchise. Head office supplies the recipes, the branding and the payment system. Independent affiliates do the cooking, and everyone takes a cut. Arresting one senior figure is welcome, but the franchisees still hold their own keys. That matters because affiliates choose the front door, and it is usually the one the victim forgot to lock.
A lock that still accepts the old key
In June, Check Point disclosed CVE-2026-50751, an authentication bypass in its Remote Access VPN and Mobile Access, according to Help Net Security. It affected gateways still using the deprecated IKEv1 key exchange. Picture a modern lock fitted to a door that still honours an old key cut years ago: the new lock is irrelevant while the old one works. An attacker could establish a VPN connection without a valid password. Check Point saw the earliest exploitation on 7 May and noticed suspicious activity on 4 June. It described the attacks as limited to a few dozen targeted organisations, with one case showing post-compromise activity tied to a Qilin affiliate.
What the defender sees
Very little, which is the point. A successful bypass looks like a legitimate remote worker connecting. Check Point's advice is to audit logs and configuration back to 7 May, a question only organisations with long log retention can answer. It also recommends confirming IKEv1 is not in use, removing support for legacy remote access clients, and requiring a machine certificate for gateway connections.
The Secure by Design lesson
SecurityWeek recalls that Qilin was blamed for the 2024 attack on pathology provider Synnovis, which disrupted several London NHS hospitals. That is the supplier version of the lesson: when one provider fails, many customers stop. Three design decisions change the odds, and none needs new technology. Switch off legacy protocols rather than keeping them for compatibility. Treat the VPN gateway as hostile ground, so that getting through it lands an attacker in a small, monitored segment rather than the whole network. And ask critical suppliers how you keep working when they fail. The cost is mostly a change window and an awkward conversation with whoever still depends on the old client. Arrests are good news, but a UK director's real control sits in their own configuration, not in a foreign police press release.
Also this week
Your staff's messages as an asset. Google won a $10 million auction for Spirit Airlines' business data, including about 100 million emails and 500 million Microsoft Teams messages, to improve its AI models, according to SiliconANGLE. Google says a third party will scrub personal information first, and passenger and loyalty records are excluded. The Record reports that 121 US lawmakers wrote to both companies on Thursday arguing that standard de-identification may not protect employees once AI is involved. The UK lesson is that when a firm fails, its internal messages can become a line on someone's balance sheet. Nothing in the reporting suggests UK staff are involved, but the question travels: who decides what happens to your people's messages when the business is sold for parts? Know what your retention policy leaves lying around, and what a buyer could do with it.
A fake installer with a real command. BleepingComputer reported on 9 October, citing Push Security, that attackers abused Google Ads and Bing's click-tracking redirects to push a fake Claude installer at Mac users. The ad displayed the genuine bing.com domain, and the page showed Anthropic's real install command while the copy button put a different one on the clipboard. Push Security found it after spotting a malicious ad for the search "claude mac", and the compromised site checked for a Bing referrer, so scanners that visit directly see only a 404 error. The final payload was not identified. Pasting a command into a terminal runs code with your authority, so give developers a vetted route for installing tools rather than a search engine.
Sources
- SecurityWeek: Qilin ransomware suspect arrested in Japan, extradited to Germany
- The Record: Japan confirms arrest of Russian Qilin operative, extradition to Germany
- Help Net Security: Qilin ransomware affiliate exploited Check Point VPN zero-day (CVE-2026-50751)
- The Record: Lawmakers warn Google could expose Spirit Airlines data in $10 million AI training deal
- SiliconANGLE: Google pays $10M to get its hands on Spirit Airlines business data for AI training
- BleepingComputer: Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks
If you want help closing the legacy doors in your own estate, get in touch.
More like this
- ShinyHunters hijacks Cl0p's leak site through an unauthenticated upload 21 september 2026
- SolarWinds fixes a hard-coded key in its access rights tool 21 september 2026
- MikroTik routers are being hijacked exactly as NCSC warned they would be 8 september 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.