Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt
ID: 4f327253-4ee6-54ff-b8da-79399957156e
STIX ID: report--4f327253-4ee6-54ff-b8da-79399957156e
Feed Name: The Hacker News
Grafana disclosed that an unauthorized actor used a token to access its GitHub environment and download company code, then attempted to extort the company; Grafana says no customer data or systems were affected, revoked the credentials and implemented additional security measures. External reporting links the claim of responsibility to a data-extortion group (CoinbaseCartel) associated with other extortion ecosystems, but Grafana has not publicly attributed the breach to a known actor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
