Ransomware & Extortion · Ransomware

Qilin Ransomware Steals Internal and Employee Data from German Party

The Qilin ransomware group compromised Die Linke, a German political party with Bundestag representation, causing an IT outage and stealing internal party files and employee personal data. Die Linke confirmed the cyber incident but said the extent of data theft is unclear and that its membership database was not accessed. Qilin publicly claimed the attack and threatened to leak the stolen data to pressure the party for ransom.

This incident is primarily a data-exfiltration and extortion operation, not just ransomware encryption. Restoring systems from backups addresses availability but does not mitigate the risk of data leaks or extortion. The party has involved law enforcement and is working with IT experts to contain the breach and restore systems safely.

1 source · Apr 3

Timeline

Sources

Part of the PlainSec briefing for 2026-04-03

Every edition of this story: Qilin Ransomware Steals Internal and Employee Data from German Party