Pandorex
Security

Ransomware Attack on Die Linke: Qilin Group Steals Data from German Party Headquarters

Published Pandorex Redaktion·6 min read
—

On Thursday, March 26, 2026, the IT network of German political party Die Linke (The Left) was targeted by a severe cyberattack. The Qilin ransomware group, a Russian-speaking cybercrime organization, has claimed responsibility and is threatening to publish stolen data.

What Happened

According to Die Linke's federal business manager Janis Ehling, the party detected the attack on Thursday and responded immediately. Parts of the IT infrastructure were taken offline as a precaution. Staff at the federal headquarters were informed about necessary measures without delay. A criminal complaint was filed with the police.

The attackers are reportedly targeting sensitive data from the party's internal organizational areas and personal information of headquarters employees. Whether and to what extent data exfiltration was successful remains unclear.

Membership Database Not Compromised

The party explicitly states that its membership database was not affected. The attackers did not manage to obtain member data. Die Linke has approximately 123,000 registered members and 64 seats in the German Bundestag.

Qilin: Ransomware-as-a-Service

Qilin operates a Ransomware-as-a-Service model and has been active since at least 2022. The group is known for double extortion: encrypting systems while simultaneously stealing data and threatening to publish it.

On April 1, Qilin added Die Linke to its dark web leak site without publishing data samples yet. This is a standard pressure tactic to coerce payment.

Political Dimension

Die Linke describes the attack as potentially part of "hybrid warfare," noting that targeting a democratic party "does not appear coincidental." Russia-linked threat actors have previously targeted German political organizations, including the 2024 attack on the SPD.

Sources: Die Linke Press Release (27.03.2026), BleepingComputer, Golem, Der Spiegel, b2b-cyber-security.de.

Comments

Sign in to write a comment.

Swipe up
Next Article

Trump Proposes $707M CISA Budget Cut – US Cybersecurity at Risk

Security