product · May 18, 2026
Grafana Labs Refuses Ransom After Attacker Steals Source Code via GitHub Token
Share the canonical public link.
Grafana Labs announced on May 17, 2026 via X that an attacker used a compromised GitHub token to access part of its GitHub environment and download the company's codebase. The company launched a forensic investigation, invalidated the compromised credentials, and added new safeguards around the affected environment. Grafana Labs rejected the attacker's demand for payment to prevent release of the stolen code based on FBI guidance that ransom payments do not guarantee data recovery and encourage illegal activity. Grafana Labs stated its investigation found no evidence of customer data exposure or impact to customer systems or operations. Grafana Labs plans to release more details after completing its post-incident review.