Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE

May 24, 2026

Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt

May 24, 2026

Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming

May 24, 2026
Facebook X (Twitter) Instagram
Sunday, May 24
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt
News

Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt

Team-CWDBy Team-CWDMay 24, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Grafana has disclosed that an “unauthorized party” obtained a token that granted them the ability to access the company’s GitHub environment and download its codebase.

“Our investigation has determined that no customer data or personal information was accessed during this incident, and we have found no evidence of impact to customer systems or operations,” Grafana
said
in a series of posts on X.

The company also said it immediately launched a forensic analysis upon discovering the activity and that it identified the source of the leak, adding the compromised credentials have since been invalidated, and extra security measures have been implemented to secure against unauthorized access.

Furthermore, Grafana revealed the attacker tried to blackmail and extort the company, demanding they make a payment to prevent the stolen database from being published.

Grafana said it has opted not to pay the ransom, citing guidance issued by the U.S. Federal Bureau of Investigation (FBI). The agency has previously warned against negotiating ransoms with perpetrators, as there is no guarantee that doing so will help affected companies get their data back.

“It also encourages perpetrators to target more victims and offers an incentive for others to get involved in this type of illegal activity,” the FBI
states
on its website.

Grafana did not reveal when the incident took place or since when the threat actor had access to its environment, only revealing that it learned of the attack “recently.” The breach has not been attributed to any known threat actor or group. 

However, reports from
Hackmanac
and
Ransomware.live
indicate that a cybercrime group named CoinbaseCartel has claimed responsibility for the incident. 

Per details shared by Halcyon
and
Fortinet FortiGuard Labs, CoinbaseCartel is a data extortion crew that emerged in September 2025. It’s assessed to be an offshoot of the ShinyHunters, Scattered Spider, and LAPSUS$ ecosystems. 

The group, which only focuses on data theft and extortion unlike traditional ransomware groups, has amassed 170 victims across healthcare, technology, transportation, manufacturing, and business services. 

The company also did not reveal what codebase the attacker downloaded, but Grafana offers various solutions like
Grafana Cloud, a fully-managed, cloud-hosted observability platform for applications and infrastructure. The Hacker News has reached out to Grafana for comment, and we will update the story if we hear back.

The development comes days after American educational technology company Instructure
made the controversial decision
to settle with the ShinyHunters extortion group after the latter threatened to leak terabytes of data belonging to thousands of schools and universities across the U.S.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleFunnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming
Next Article NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE
Team-CWD
  • Website

Related Posts

News

NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE

May 24, 2026
News

Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming

May 24, 2026
News

Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access

May 24, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

How to help older family members avoid scams

October 31, 2025

Mobile app permissions (still) matter more than you may think

February 27, 2026

What parents should know to protect their children from doxxing

November 28, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.