market · May 20, 2026
Grafana Labs Admits Attackers Downloaded Codebase from GitHub via Stolen Token
Share the canonical public link.
Grafana Labs revealed on May 18, 2026 that attackers accessed its GitHub environment using a stolen privileged token and downloaded non-open-source codebase components. Grafana Labs identified the credential leak source, invalidated the token, and implemented additional security measures to prevent further unauthorized access. The company refused to pay the ransom demanded to prevent code publication, citing FBI statements that payment does not guarantee recovery and encourages further crime. Grafana Labs confirmed no customer data or personal information was accessed during the incident. Education software company Instructure paid extortionists last week after similar claims involving over 275 million students and faculty data.