logo

Grafana confirms GitHub token breach cybercrime group claims the attack

ID: 7d7232a5-cca3-59ac-b846-6a96537e8a0e

STIX ID: report--7d7232a5-cca3-59ac-b846-6a96537e8a0e

Feed Name: Security Affairs

Threat Score
65/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: Pierluigi Paganini

...
...

Grafana Labs confirmed a security incident after a compromised GitHub token exposed parts of its source code and was claimed by the extortion group Coinbase Cartel; the company says no customer data or systems were impacted, revoked the credentials, and is conducting a forensic investigation while refusing to pay the ransom. The report highlights token security weaknesses, the risks of source-code theft for supply-chain and phishing attacks, and links the extortion group to other credential-focused threat actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.