Grafana Labs internal source code accessed
Summary
Grafana Labs disclosed that an unauthorized party obtained a token granting access to its GitHub environment, enabling the threat actor to download the company's codebase.
View Cached Full Text
Cached at: 05/17/26, 06:45 AM
🚨 We recently discovered that an unauthorized party obtained a token with access to the Grafana Labs GitHub environment, enabling the threat actor to download our codebase. (1/6)
We recently discovered that an unauthorized party obtained a token with access to the Grafana Labs GitHub environment, enabling the threat actor to download our codebase. (1/6)
Our investigation has determined that no customer data or personal information was accessed during this incident, and we have found no evidence of impact to customer systems or operations. (2/6)
We immediately initiated forensic analysis and we believe we’ve identified the source of the credential leak.
We have since invalidated the compromised credentials and implemented additional security measures to further secure our environment against unauthorized access. (3/6)
The attacker attempted to blackmail us, demanding payment to prevent the release of our codebase. (4/6)
Based on our operational experience and the published stance of the FBI, which notes that “paying a ransom doesn’t guarantee you or your organization will get any data back” and only “offers an incentive for others to get involved in this type of illegal activity,” (5/6)
… we’ve determined the appropriate path forward is to not pay the ransom.
As part of Grafana Labs’ standard security practices, we will share additional information from our post-incident review when our investigations are complete. (6/6)
Similar Articles
Grafana Labs GitHub repos breached via TanStack npm supply chain attack
Grafana Labs disclosed that a cybercrime group gained unauthorized access to its GitHub repositories via a TanStack npm supply chain attack, downloading codebase and internal data, but no customer production systems were compromised.
Github: internal repositories have been accessed
A security incident at GitHub led to unauthorized access to internal repositories.
GitHub Source Code Breach - TeamPCP Claims Access to Internal Source Code
TeamPCP claims to have accessed GitHub's internal source code, indicating a significant security breach at the popular development platform.
GitHub is investigating unauthorized access to their internal repositories
GitHub is investigating unauthorized access to its internal repositories, with no evidence of impact to customer data so far.
GitHub Compromised
GitHub disclosed a security incident where an employee device was compromised via a malicious VS Code extension, leading to unauthorized access to internal repositories. The company removed the extension and initiated incident response.