Cybersecurity — 2026-05-19
Grafana Labs Refuses Ransom After Hackers Steal Entire Codebase via GitHub Token Breach
BLUFGrafana's refusal contains its own exposure, but CoinbaseCartel's rapid scaling and token-theft tradecraft signal that software vendors serving critical infrastructure should expect repeated GitHub credential intrusions.
Grafana Labs disclosed in a series of posts on X beginning May 16 that an unauthorized party obtained a stolen access token, accessed the company's GitHub environment, and downloaded its source code 123. The attacker exploited a misconfigured pull_request_target GitHub Actions workflow by forking a public Grafana repository, injecting a malicious curl command to dump environment variables and extract a privileged token, then deleting the fork to erase forensic traces; Grafana's security team was alerted when a deployed canary token fired 23. Grafana's forensic analysis found no customer data, personal information, or financial data was accessed and no customer systems were affected 123. The attacker demanded payment to suppress publication of the stolen code; Grafana said it declined, citing FBI guidance against paying ransoms 23. BleepingComputer and The Hacker News report that CoinbaseCartel, a data extortion group assessed as a ShinyHunters/Scattered Spider/LAPSUS$ offshoot that emerged in September 2025 and has claimed roughly 170 victims, added Grafana to its data leak site, though no data had been published as of reporting time 23.
Analysis
Grafana's refusal eliminates CoinbaseCartel's financial incentive to withhold the code, and the group's acknowledgment of a pending-leak backlog increases pressure toward publication. The extortion may be a bluff if captured repositories contain only already-public open-source material with no proprietary content capable of inflicting harm. Residual risk concentrates in proprietary Grafana Cloud or enterprise components taken during the intrusion. Reporting traces solely to Grafana's own X thread, amplified without independent collection, constraining reliability to moderate. CoinbaseCartel's assessed nexus with ShinyHunters, Scattered Spider, and LAPSUS$ affiliates and 170 claimed victims since September 2025 mark a rapidly scaling operation. The incident validates GitHub token compromise as a repeatable vector against software vendors.
5 sources
- Open source tool maker Grafana Labs says hackers stole its code, refuses to pay ransom - TechCrunch
- Grafana says stolen GitHub token let hackers steal codebase - BleepingComputer
- Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt - The Hacker News
- Grafana Labs admits all its codebase are belong to someone who popped its GitHub account - The Register
- Grafana Labs security incident disclosure (six-part thread on X)
View in full brief →