arrow_backBack to Radio
News

Grafana Labs discloses GitHub environment security incident, states customer data unaffected and refuses to pay ransom

en
On May 18, the open-source data visualization tool Grafana posted on X that an unauthorized party recently obtained a token to access its Grafana Labs GitHub environment, and the threat actor used this to download its code repositories. The company's investigation determined that no customer data or personal information was accessed during this incident, nor were any impacts found on customer systems or operations. The company has immediately initiated forensic analysis and believes it has identified the source of the credential leak. Grafana has since invalidated the compromised credentials and implemented additional security measures. The attacker attempted to extort the company, demanding a ransom to prevent the release of the code repositories. Based on operational experience and the FBI's public stance (paying ransoms does not guarantee data recovery and only encourages more such illegal activities), Grafana decided not to pay the ransom. As part of standard security practices, the company will share more information in a post-mortem review after the investigation is complete.
Share