logo

Grafana Rejects Ransom Demand After GitHub Breach Exposes Codebase Theft

ID: a941f337-ca6f-583c-b3e5-417d359eeb75

STIX ID: report--a941f337-ca6f-583c-b3e5-417d359eeb75

Feed Name: TechRepublic Security

Threat Score
70/100

Date Published: 2026-05-18

Date Updated: 2026-05-20

Author: Aminu Abdullahi

...
...

Grafana disclosed that an unauthorized party used a compromised GitHub access token to download portions of its codebase and then attempted to extort the company; Grafana revoked the token, implemented additional controls, found no evidence of customer data or operational impact, and reporting has tied the incident to a data-extortion group known as CoinbaseCartel while a full investigation continues.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.