logo

Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt

ID: 4f327253-4ee6-54ff-b8da-79399957156e

STIX ID: report--4f327253-4ee6-54ff-b8da-79399957156e

Feed Name: The Hacker News

Threat Score
60/100

Date Published: 2026-05-17

Date Updated: 2026-05-17

Author: [email protected] (The Hacker News)

...
...

Grafana disclosed that an unauthorized actor used a token to access its GitHub environment and download company code, then attempted to extort the company; Grafana says no customer data or systems were affected, revoked the credentials and implemented additional security measures. External reporting links the claim of responsibility to a data-extortion group (CoinbaseCartel) associated with other extortion ecosystems, but Grafana has not publicly attributed the breach to a known actor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.