market · May 18, 2026
Grafana Official Account Reports Unauthorized GitHub Token Access and Codebase Download
Share the canonical public link.
Grafana Labs posted on May 17, 2026 that an unauthorized party obtained a token with access to the Grafana Labs GitHub environment enabling the threat actor to download the codebase. The company initiated forensic analysis and identified the source of the credential leak. Grafana Labs invalidated the compromised credentials and implemented additional security measures to further secure the environment. The attacker attempted to blackmail Grafana Labs demanding payment to prevent release of the codebase. Grafana Labs determined not to pay the ransom based on operational experience and the published stance of the FBI.