INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Qilin ransomware group claims Die Linke German political party

| 2026-04-04 17:37 HIGH LOW RANSOMWARE & EXTORTION DATA BREACH
Executive Summary
AI-generated
On April 1, 2026, the Qilin ransomware group claimed to have hacked German political party Die Linke, threatening to leak stolen data; however, the incident was later confirmed by the party as a non-breach. The attack is attributed to the Russian-speaking cybercrime organization, with approximately 123,126 members affected in Germany. According to the attackers' statement, they stole data from Die Linke and are planning to publish it on Tor-based portals using double-extortion tactics, encrypting data while threatening to leak it via these platforms; however, as of now, no samples have been shared by Qilin as proof of the breach.
Technical Mitigations AI-generated
• Patch vulnerabilities in Tor-based portals to prevent data leaks. • Monitor for Qilin ransomware group's use of double-extortion tactics and customize defenses accordingly. • Implement robust phishing detection measures, leveraging global bulletproof hosting networks' known vulnerabilities.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
QilinQilin
Target & Sectors
DACH DACH
Incident Timeline
‎2026/04/04
The Qilin ransomware group claims to have stolen data from Germany's Die Linke political party.
victims 40 victims
data_breach 123,126 members
Tactical Metrics
Metrics
victims
40
Victims
Metrics
data_breach
123,126
Members
Intelligence Sources