Qilin Ransomware Targets German Political Party with Data Theft and Extortion

The Qilin ransomware group attacked Die Linke, a German political party represented in the Bundestag, causing an IT outage and claiming to have stolen internal party files and employee personal data. Die Linke confirmed the cyber incident but said the extent of data exfiltration is unclear and that its membership database was not compromised. Qilin added Die Linke to its data leak site but has not published any stolen data yet. This attack is primarily a data theft and extortion operation, not just ransomware encryption. Restoring systems from backups will not address the risk of sensitive data leaks. The party has notified German authorities and is working with IT experts to restore systems safely. The incident raises reputational and legal risks, especially under EU data protection laws, and requires forensic investigation, breach notification planning, and containment of exfiltration channels.

Part of the PlainSec briefing for 2026-04-04

Sources