France ransomware and cyber extortion policy

Osaka Arrest Shows Cross-Border Policing Beats Ransom Bans, and France Should Fund It Over New Payment Prohibitions

A Qilin suspect was caught in Japan and sent to Germany. France's best ransomware lever is patient police cooperation, not criminalising victims who pay.

Ransomware in France: ANSSI 2025 Data People of Internet Research · France 128 Ransomware attacks in 2025 Down from 141 in 2024, per ANSSI's… 21% Qilin share of cases Most prevalent strain in France in… 72h Insurance complaint deadline Victims must file a complaint with… 127 Qilin attacks, July 2026 Ranked second most active ransomwa… peopleofinternet.com
Ransomware in France: ANSSI 2025 Data People of Internet Research · France 128 Ransomware attacks in 2025 21% Qilin share of cases 72h Insurance complaint deadli… 127 Qilin attacks, July 2026 peopleofinternet.com

Key Takeaways

What happened in Osaka

Japan's National Police Agency confirmed on 8 October 2026 that it had arrested a 28-year-old Russian national at a hotel in Osaka in May and extradited them to Germany in early October, The Record reported. Germany had issued the warrant over a ransomware attack on a German company, and the suspect is accused of involvement in the Qilin gang. Officials learned the suspect planned a Japanese holiday and acted on the warrant when they arrived. The suspect's name was not released, and German authorities did not comment.

The case has no stated French element. But Qilin does. The group listed the Paris rugby club Stade Français on its leak site in August 2026, and the club confirmed an attack, according to The Record. ANSSI, France's national cybersecurity agency, found Qilin was the most prevalent strain among the ransomware cases it saw in France in 2025, at 21% according to Infosecurity Magazine's summary of its annual report. The Record ranks Qilin as the second most active ransomware gang in July 2026, with 127 reported attacks.

So the arrest matters to France as a template. It was not a takedown of Qilin. It shows how a single affiliate can be caught: patience, an international warrant and a suspect who travelled somewhere that would act on it.

The case for tougher rules

The strongest argument for a harder line is simple. Ransom payments fund the next attack, and a legal ban on paying would, in theory, shrink the market. Some officials also argue that insurance-backed payments make victims price-insensitive and attackers richer. These are serious points, and France has partly engaged with them.

France already conditions cyber insurance payouts on a criminal complaint. Article L. 12-10-1 of the Insurance Code, created by the LOPMI law (loi n° 2023-22), makes compensation for attacks on automated data systems subject to the victim filing a complaint within 72 hours of learning of the attack. The rule took effect on 24 April 2023, as Jones Day explains. The Treasury has published a FAQ on the obligation. Jones Day also reports that the law's rapporteur noted no OECD country had banned ransom payments.

That design is a good one. It does not criminalise the victim. It uses the insurance relationship to pull incidents into the police system quickly, so investigators get indicators, wallet addresses and negotiation transcripts while they are still useful. The Osaka arrest depended on exactly this kind of accumulated case file reaching a country where the suspect could be detained.

Why a payment ban would backfire

A ban sounds tough but shifts the burden onto the wrong party. A hospital, a school or a sports club that cannot restore systems and is forbidden from paying has a worse choice than the attacker does. It may pay in secret, which removes the one channel through which police learn about the incident. Concealment is the predictable response, and it would erode the reporting that the 72-hour rule is meant to encourage.

The evidence in France points to policing, not prohibition, as the lever that works. ANSSI's Panorama de la cybermenace 2025, published 11 March 2026, records a decline in the use of ransomware. Infosecurity Magazine reports 128 ransomware attacks reported in France in 2025, down from 141 in 2024, and says ANSSI credited law enforcement operations and preventive work by defenders in part. No payment ban was needed for that decline.

There is a catch. ANSSI's English-language Cyber Threat Overview 2025 says that ransomware use appears to be declining in sharp contrast to a significant increase in data exfiltration. Extortion is moving to a model with no encryption at all: steal the data, threaten to publish it. The Stade Français case fits that pattern. SOCRadar reports Qilin posted images of identity documents as proof, though no public element independently verified the claimed data at the time. A policy built around encrypted systems and payment bans would miss this shift entirely, because a victim whose systems still run has no operational reason to pay, only a reputational and GDPR one.

What France should do

The limits of the Osaka lesson

One arrest does not dent a group with dozens of attacks a month. Affiliates are replaceable, and the person caught was reportedly a single operative tied to one German incident. Most Russian-speaking operators will never holiday in a country with an extradition treaty. The honest reading is that international policing raises the cost of the job at the margin, makes travel risky, and generates intelligence. That is worth funding because the alternatives, bans and blame, do not reduce attacks and do reduce reporting.

France has the right structure in place. The task for 2027 is to make it faster, better staffed and aimed at the criminals, rather than adding new liabilities for the organisations they target.

Sources & Citations

  1. The Record: Japan confirms arrest of Qilin operative
  2. ANSSI/CERT-FR: Panorama de la cybermenace 2025
  3. ANSSI/CERT-FR: Cyber Threat Overview 2025
  4. Infosecurity Magazine: France ANSSI ransomware report
  5. Jones Day: French law on insurability of cyber ransoms
  6. French Treasury: FAQ on Article L. 12-10-1 complaint obligation