The Qilin ransomware group has claimed responsibility for a cyberattack on Die Linke, a German political party, and threatened to leak allegedly stolen data on its Tor-based extortion site. Die Linke disclosed the incident shortly after detecting the compromise, took parts of its IT infrastructure offline, notified staff, alerted German authorities, and filed a criminal complaint. The party said the attack appeared to target sensitive internal party information and personal data belonging to employees at party headquarters.
Die Linke said its membership database was not affected and that no member data was stolen, although it warned that internal records and employee information may be at risk. Qilin later added the party to its leak site without publishing proof-of-theft samples. The group is described as a Russian-speaking ransomware-as-a-service operation known for double-extortion tactics, and Die Linke said the incident may not have been random, citing both financial and possible political motives as independent IT experts work to restore affected systems.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
On April 1, 2026, the Qilin ransomware group added Die Linke to its dark web leak site and threatened to leak allegedly stolen data. No proof samples or leaked data were published at that time.
On March 27, 2026, Die Linke disclosed the cyberattack, warned that sensitive internal party data and personal information of headquarters employees might be affected, and said its membership database was not impacted. The party also notified staff, alerted German authorities, filed a criminal complaint, and engaged external IT experts to help restore systems.
Die Linke said the compromise occurred on March 26, 2026. The party took parts of its IT systems offline and began responding to a suspected attack targeting internal systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcetherecord.media
Open sourceteiss.co.uk
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.