2026 Die Linke — Qilin ransomware; internal and HQ staff data at risk (membership DB reported not taken)
Data compromised
Potential internal party documents and HQ employee personal data per disclosures; membership database reported not compromised
Technical writeup
Germany’s Die Linke (Left Party) disclosed a serious cyber incident after attackers compromised party systems, with public statements in late March 2026 describing risks to sensitive internal party materials and personal information of employees at party headquarters. The party stated that, according to current findings, its membership database was not impacted and that attackers had not succeeded in obtaining member data as sometimes attempted. Press and the party linked the operation to the Qilin ransomware group, which later listed Die Linke on its leak site. Die Linke filed criminal complaints, notified authorities, and framed the incident in the context of hybrid threats to political infrastructure. Full exfiltration scope remained subject to investigation.
Root cause
Ransomware / extortion (Qilin group cited by victim and reporting)