What happened in Osaka
Japan's National Police Agency confirmed on 8 October 2026 that it had arrested a 28-year-old Russian national at a hotel in Osaka in May and extradited them to Germany in early October, The Record reported. Germany had issued the warrant over a ransomware attack on a German company, and the suspect is accused of involvement in the Qilin gang. Officials learned the suspect planned a Japanese holiday and acted on the warrant when they arrived. The suspect's name was not released, and German authorities did not comment.
The case has no stated French element. But Qilin does. The group listed the Paris rugby club Stade Français on its leak site in August 2026, and the club confirmed an attack, according to The Record. ANSSI, France's national cybersecurity agency, found Qilin was the most prevalent strain among the ransomware cases it saw in France in 2025, at 21% according to Infosecurity Magazine's summary of its annual report. The Record ranks Qilin as the second most active ransomware gang in July 2026, with 127 reported attacks.
So the arrest matters to France as a template. It was not a takedown of Qilin. It shows how a single affiliate can be caught: patience, an international warrant and a suspect who travelled somewhere that would act on it.
The case for tougher rules
The strongest argument for a harder line is simple. Ransom payments fund the next attack, and a legal ban on paying would, in theory, shrink the market. Some officials also argue that insurance-backed payments make victims price-insensitive and attackers richer. These are serious points, and France has partly engaged with them.
France already conditions cyber insurance payouts on a criminal complaint. Article L. 12-10-1 of the Insurance Code, created by the LOPMI law (loi n° 2023-22), makes compensation for attacks on automated data systems subject to the victim filing a complaint within 72 hours of learning of the attack. The rule took effect on 24 April 2023, as Jones Day explains. The Treasury has published a FAQ on the obligation. Jones Day also reports that the law's rapporteur noted no OECD country had banned ransom payments.
That design is a good one. It does not criminalise the victim. It uses the insurance relationship to pull incidents into the police system quickly, so investigators get indicators, wallet addresses and negotiation transcripts while they are still useful. The Osaka arrest depended on exactly this kind of accumulated case file reaching a country where the suspect could be detained.
Why a payment ban would backfire
A ban sounds tough but shifts the burden onto the wrong party. A hospital, a school or a sports club that cannot restore systems and is forbidden from paying has a worse choice than the attacker does. It may pay in secret, which removes the one channel through which police learn about the incident. Concealment is the predictable response, and it would erode the reporting that the 72-hour rule is meant to encourage.
The evidence in France points to policing, not prohibition, as the lever that works. ANSSI's Panorama de la cybermenace 2025, published 11 March 2026, records a decline in the use of ransomware. Infosecurity Magazine reports 128 ransomware attacks reported in France in 2025, down from 141 in 2024, and says ANSSI credited law enforcement operations and preventive work by defenders in part. No payment ban was needed for that decline.
There is a catch. ANSSI's English-language Cyber Threat Overview 2025 says that ransomware use appears to be declining in sharp contrast to a significant increase in data exfiltration. Extortion is moving to a model with no encryption at all: steal the data, threaten to publish it. The Stade Français case fits that pattern. SOCRadar reports Qilin posted images of identity documents as proof, though no public element independently verified the claimed data at the time. A policy built around encrypted systems and payment bans would miss this shift entirely, because a victim whose systems still run has no operational reason to pay, only a reputational and GDPR one.
What France should do
- Keep the complaint-first model and make it fast. The 72-hour rule works because it is tied to a benefit, not a penalty. Police units should be resourced to act on complaints, not merely receive them.
- Fund extradition and mutual legal assistance. Osaka worked because a warrant met a traveller. French prosecutors need the staff to issue warrants, share evidence and follow up with partners such as Japan and Germany on Russian-speaking affiliates who travel.
- Target the infrastructure, not the victim. Operation Endgame-style disruptions, which ANSSI named among the most impactful efforts according to Infosecurity Magazine, produced measurable effects. Those should get priority over new compliance burdens.
- Treat data-theft extortion as a first-class offence in guidance. Prosecutors, insurers and the CNIL should share a single playbook for incidents where nothing was encrypted.
- Do not ban payments. Treat payment as a decision of last resort that must be reported, not hidden.
The limits of the Osaka lesson
One arrest does not dent a group with dozens of attacks a month. Affiliates are replaceable, and the person caught was reportedly a single operative tied to one German incident. Most Russian-speaking operators will never holiday in a country with an extradition treaty. The honest reading is that international policing raises the cost of the job at the margin, makes travel risky, and generates intelligence. That is worth funding because the alternatives, bans and blame, do not reduce attacks and do reduce reporting.
France has the right structure in place. The task for 2027 is to make it faster, better staffed and aimed at the criminals, rather than adding new liabilities for the organisations they target.