Die Linke
Incident posture
Timeline
Summary
Qilin, a Russian-speaking ransomware group, claimed responsibility for a cyberattack on the German democratic socialist political party Die Linke, threatening to publish stolen data unless a ransom was paid. The party responded by shutting down parts of its IT systems to limit further damage and described the incident as a hybrid warfare operation linked to Moscow's broader geopolitical goals.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In March 2026, the Russian‑speaking ransomware group Qilin claimed responsibility for a cyberattack on the German democratic socialist political party Die Linke. The group asserted that it had exfiltrated data from the party’s systems and threatened to publish the stolen information unless a ransom was paid. According to the timeline, the attack occurred during the same month as several other notable incidents reported in the chronology. Qilin’s claim was made publicly, indicating that the party had been targeted by a ransomware operation. The party’s leadership confirmed that the attack involved the encryption of files and the potential release of sensitive data.
In response, Die Linke shut down parts of its IT systems to limit further damage and prevent the spread of the ransomware. The party characterized the incident as a hybrid warfare operation, asserting that Qilin’s actions were aligned with Moscow’s broader geopolitical objectives. No additional details about the specific data compromised or the ransom amount were provided in the source material. The shutdown of systems was intended to contain the breach and preserve operational capacity for essential functions. The incident was recorded in the timeline as part of the March 2026 entries detailing significant cyber events.
Sources
Sources available to members: 1 source.