← Blog

Grafana Labs: GitHub Token Theft and Ransom Standoff

Share on X

Grafana Labs joined the May 2026 wave of developer-targeted extortion after confirming that an unauthorized party used a GitHub token to download its source tree. Corporate statements on X emphasized that customer data and production operations were not impacted, credentials were rotated, and Grafana declined to pay ransom aligned with FBI guidance.

SecurityWeek tied the incident to the Coinbase Cartel leak brand—an ecosystem adjacent to ShinyHunters and Scattered Spider activity—after the group listed Grafana ahead of the company’s Sunday confirmation.

Canonical record: Grafana Labs 2026 GitHub incident on BreachHistory.

Sources: The Hacker News, SecurityWeek