Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Grafana GitHub token compromise led to codebase downloads and extortion attempts

The haves and have-nots of the AI ​​gold rush

Research repository ArXiv bans authors for a year if they let AI do all the work

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Grafana GitHub token compromise led to codebase downloads and extortion attempts
Identity

Grafana GitHub token compromise led to codebase downloads and extortion attempts

By May 17, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananMay 17, 2026Data breach/cyber crime

Grafana revealed that an “unauthorized party” obtained a token that gave them permission to access the company’s GitHub environment and download its codebase.

“Our investigation has determined that no customer data or personal information was accessed in this incident, and we found no evidence of any impact on customer systems or operations,” Grafana said in a series of posts on X.

The company also said that upon discovering this activity, it immediately began a forensic analysis and determined the source of the leak, adding that the compromised credentials have since been disabled and additional security measures have been put in place to prevent unauthorized access.

Additionally, Grafana revealed that the attackers attempted to blackmail and extort the company, demanding payment to prevent the publication of the stolen database.

Grafana, citing the US Federal Bureau of Investigation (FBI), said it chose not to pay the ransom. The agency has previously warned against negotiating ransoms with perpetrators, as there is no guarantee that it will help victim companies recover their data.

“It also encourages perpetrators to target more victims and provides an incentive for others to engage in this type of illegal activity,” the FBI says on its website.

Grafana did not say when the incident occurred or when the threat actor gained access to its environment, only that it learned of the attack “recently.” This breach was not caused by any known attacker or group.

However, a cybercrime group named CoinbaseCartel claimed responsibility for the incident, according to reports from Hackmanac and Ransomware.live.

According to a report by Halcyon and Fortinet FortiGuard Labs, CoinbaseCartel is a data extortion group that emerged in September 2025. It is considered an offshoot of the ShinyHunters, Scattered Spider, and LAPSUS$ ecosystems.

The group differs from traditional ransomware groups by focusing solely on data theft and extortion, and has amassed 170 victims across healthcare, technology, transportation, manufacturing, and business services.

The company did not say what codebase the attackers downloaded, but Grafana offers a variety of solutions, including Grafana Cloud, a fully managed, cloud-hosted observability platform for applications and infrastructure. Hacker News has reached out to Grafana for comment and will update the article if we hear back.

The development comes days after American education technology company Instructure made a controversial decision to settle with the extortion group ShinyHunters after the group threatened to leak terabytes of data belonging to thousands of schools and universities across the country.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleThe haves and have-nots of the AI ​​gold rush

Related Posts

Actively exploited funnel builder flaw allows WooCommerce checkout skimming

May 16, 2026

Turla turns Kazuar backdoor into modular P2P botnet for persistent access

May 15, 2026

Four OpenClaw flaws allow data theft, privilege escalation, and persistence

May 15, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Grafana GitHub token compromise led to codebase downloads and extortion attempts

The haves and have-nots of the AI ​​gold rush

Research repository ArXiv bans authors for a year if they let AI do all the work

Offline desk gadget that actually made me sit up straighter

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.