INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Die Linke data stolen by Qilin ransomware attack

| 2026-04-03 16:36 CRITICAL LOW RANSOMWARE & EXTORTION DATA BREACH
Executive Summary
AI-generated
On March 27, the Qilin ransomware group compromised the network of Die Linke, a German democratic socialist political party, and is threatening to leak stolen data. The attackers are described as Russian-speaking cybercriminals motivated by both financial and political interests. With over 123,000 registered members, primarily in eastern Germany, Die Linke's membership database was not impacted. The Qilin ransomware group has since confirmed the attack on its website, listing Die Linke among its victims without publishing any data samples. This is a standard tactic to coerce victims into paying a ransom; however, no further details have been provided by the attackers or the party regarding the extent of the breach.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
APT29APT29 QilinQilin
Target & Sectors
DACH DACH governmentgovernment
Incident Timeline
‎2026/04/03
Threat actors using Qilin ransomware targeted Die Linke, a German democratic socialist political party.
data_breach 123,000 registered members
data_breach 64 members
threat_actor APT29
Tactical Metrics
Metrics
data_breach
123,000
Registered Members
Metrics
data_breach
64
Members
Intelligence Sources