ctipilot.ch

Die Linke ransomware breach

incident · incident:die-linke-qilin-2026 single-source

Qilin ransomware attack on the German party Die Linke — 1.5 TB claimed, DPA notified (April 2026).

Coverage timeline
2
first 2026-05-04 → last 2026-05-08
Peak priority
notable
2 notable
Sources cited
2
2 hosts
Sections touched
2
active-threats, weekly-sector-patterns
Co-occurring entities
1
see Related entities below
ATT&CK techniques
0
no mapped behavior yet
2026-05-042 appearances2026-05-08

Story timeline

  1. 2026-05-08Qilin ransomware hits Die Linke (Germany): 1.5 TB claimed, DPA notified (~April 2026, first coverage)
    active-threats
  2. 2026-05-04Media and political (HU, DE)
    weekly-sector-patterns

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

attributed to

Where this entity is cited

  • weekly-sector-patterns1
  • active-threats1

Source distribution

  • heise.de1 (50%)
  • therecord.media1 (50%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Die Linke ransomware breach (2)

2026-05-08 · view entry permalink →

NOTABLE

Qilin ransomware hits Die Linke (Germany): 1.5 TB claimed, DPA notified (~April 2026, first coverage)

The German federal party Die Linke confirmed in April 2026 that the Qilin ransomware group (also known as Agenda, a Rust-based RaaS platform known for double extortion) encrypted and exfiltrated its systems, with the gang claiming 1.5 TB of internal data. The party's data protection officer notified the responsible Landesdatenschutzbehörde (state DPA). Die Linke issued a victim statement acknowledging operational disruption; no ransom figure has been publicly disclosed. Qilin has targeted political parties and civil-society organisations across Western Europe since 2023. This breach is approximately four weeks old but has not been previously covered in this brief series.

incident08 May 05:00Zsingle-sourceOpen finding ↗

2026-05-04 · view entry permalink →

NOTABLE

Media and political (HU, DE)

Two European political / media targets in the week: Mediaworks Kft (Hungary) — World Leaks claimed 8.5 TB of exfiltrated data including payroll, contracts, and internal editorial communications; Mediaworks confirmed "a significant amount of illegally obtained data may have come into the possession of unauthorized persons"; no public regulator notification announcement at window close (The Record, 2026-05-04 · daily 2026-05-06). Die Linke (Germany) — German federal political party confirmed Qilin ransomware encryption and 1.5 TB exfiltration; state DPA notified; no public ransom figure (heise online — covered in daily, 2026-05-08). Two distinct operators (data-theft-only WorldLeaks versus encrypt-and-exfiltrate Qilin), shared targeting of politically significant European entities. The defender lesson: data-theft-only operators defeat backup-centric ransomware defences entirely — effective detection requires egress monitoring and data-loss-prevention tooling capable of alerting on large-volume exfiltration before the attacker goes public on a leak site.

synthesis04 May 05:00Zsingle-sourceOpen finding ↗