CTIPilot

Die Linke ransomware breach

incident · incident:die-linke-qilin-2026 single-source

Qilin ransomware attack on the German party Die Linke, 1.5 TB claimed, DPA notified (April 2026).

Coverage timeline
1
first 2026-05-08 → last 2026-05-08
Peak priority
notable
1 notable
Sources cited
1
1 hosts
Sections touched
1
active-threats
Co-occurring entities
1
see Co-occurring entities below
ATT&CK techniques
0
no mapped behavior yet

Hunting pivots

Story timeline

  1. 2026-05-08Qilin ransomware hits Die Linke (Germany): 1.5 TB claimed, DPA notified (~April 2026, first coverage)
    active-threats

Where this entity is cited

  • active-threats1

Source distribution

  • heise.de1 (100%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Die Linke ransomware breach (1)

2026-05-08 · view entry permalink →

NOTABLE

Qilin ransomware hits Die Linke (Germany): 1.5 TB claimed, DPA notified (~April 2026, first coverage)

The German federal party Die Linke confirmed in April 2026 that the Qilin ransomware group (also known as Agenda, a Rust-based RaaS platform known for double extortion) encrypted and exfiltrated its systems, with the gang claiming 1.5 TB of internal data. The party's data protection officer notified the responsible Landesdatenschutzbehörde (state DPA). Die Linke issued a victim statement acknowledging operational disruption; no ransom figure has been publicly disclosed. Qilin has targeted political parties and civil-society organisations across Western Europe since 2023. This breach is approximately four weeks old but has not been previously covered in this brief series.

incident08 May 05:00Zsingle-sourceOpen finding ↗