CSIDB logo
Incident

Die Linke

Incident posture

Attack window
Mar 2026
Location
Germany
Status
Ongoing
CIA posture
Available to members
Updated
2026-09-10 10:03

Linked entities

Victim
Die Linke
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Mar 2026
Discovered
Undetermined
Disclosed
Mar 2026
Resolved
Pending

Summary

Qilin, a Russian-speaking ransomware group, claimed responsibility for a cyberattack on the German democratic socialist political party Die Linke, threatening to publish stolen data unless a ransom was paid. The party responded by shutting down parts of its IT systems to limit further damage and described the incident as a hybrid warfare operation linked to Moscow's broader geopolitical goals.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

In March 2026, the Russian‑speaking ransomware group Qilin claimed responsibility for a cyberattack on the German democratic socialist political party Die Linke. The group asserted that it had exfiltrated data from the party’s systems and threatened to publish the stolen information unless a ransom was paid. According to the timeline, the attack occurred during the same month as several other notable incidents reported in the chronology. Qilin’s claim was made publicly, indicating that the party had been targeted by a ransomware operation. The party’s leadership confirmed that the attack involved the encryption of files and the potential release of sensitive data.

In response, Die Linke shut down parts of its IT systems to limit further damage and prevent the spread of the ransomware. The party characterized the incident as a hybrid warfare operation, asserting that Qilin’s actions were aligned with Moscow’s broader geopolitical objectives. No additional details about the specific data compromised or the ransom amount were provided in the source material. The shutdown of systems was intended to contain the breach and preserve operational capacity for essential functions. The incident was recorded in the timeline as part of the March 2026 entries detailing significant cyber events.

Sources

Sources available to members: 1 source.

CSIDB