Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (10 days ago).

← Intel index

This coverage is stale.

Last updated May 20, 2026 (about 3 months ago).

market · May 20, 2026

Grafana Labs Admits Attackers Downloaded Codebase from GitHub via Stolen Token

Share the canonical public link.

Share as image

Grafana Labs revealed on May 18, 2026 that attackers accessed its GitHub environment using a stolen privileged token and downloaded non-open-source codebase components. Grafana Labs identified the credential leak source, invalidated the token, and implemented additional security measures to prevent further unauthorized access. The company refused to pay the ransom demanded to prevent code publication, citing FBI statements that payment does not guarantee recovery and encourages further crime. Grafana Labs confirmed no customer data or personal information was accessed during the incident. Education software company Instructure paid extortionists last week after similar claims involving over 275 million students and faculty data.

Below validation threshold — auto-passed without scoring

Supporting evidence