Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (10 days ago).

← Intel index

This coverage is stale.

Last updated May 18, 2026 (about 4 months ago).

product · May 18, 2026

Grafana Labs Refuses Ransom After Attacker Steals Source Code via GitHub Token

Share the canonical public link.

Share as image

Grafana Labs announced on May 17, 2026 via X that an attacker used a compromised GitHub token to access part of its GitHub environment and download the company's codebase. The company launched a forensic investigation, invalidated the compromised credentials, and added new safeguards around the affected environment. Grafana Labs rejected the attacker's demand for payment to prevent release of the stolen code based on FBI guidance that ransom payments do not guarantee data recovery and encourage illegal activity. Grafana Labs stated its investigation found no evidence of customer data exposure or impact to customer systems or operations. Grafana Labs plans to release more details after completing its post-incident review.

Spend governor blocked model creation: provider_circuit_open (lane=dev, provider=together)

Supporting evidence