logo

Grafana Labs admits all its codebase are belong to someone who popped its GitHub account

ID: 5c806166-bc20-59eb-b20e-adfbf5b212ab

STIX ID: report--5c806166-bc20-59eb-b20e-adfbf5b212ab

Feed Name: The Register (Security)

Threat Score
45/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

...
...

## Executive Summary Grafana Labs disclosed that an unauthorized party used a leaked token to access its GitHub repositories and exfiltrate portions of its codebase, then threatened to release the code unless a ransom was paid; Grafana invalidated credentials, implemented extra security controls, reported no customer data or operational impact, and declined to pay.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.