market · May 18, 2026
Grafana Labs Discloses GitHub Token Breach Allowing Codebase Download
Share the canonical public link.
Grafana Labs disclosed on May 16, 2026 that an unauthorized party obtained a privileged token granting access to its GitHub environment and downloaded the company's private codebase. The company identified the intrusion after a canary token triggered an alert and determined the root cause was a misconfigured GitHub Action workflow vulnerable to pull_request_target events. Grafana Labs invalidated the compromised credentials, removed the vulnerable workflow, disabled workflows across public repositories, and refused a ransom demand citing FBI guidance that payments incentivize further attacks. Grafana Labs investigation found no customer data or personal information was accessed and no evidence of impact to customer systems or operations. Grafana Labs will share additional findings from its post-incident review once investigations complete.