According to BlockBeats, Grafana disclosed on May 18 that an unauthorized attacker obtained access tokens to its GitHub environment and downloaded the company’s code repository. The company confirmed the breach did not result in customer data or personal information leakage, and no customer systems or business operations were impacted. Grafana has identified the credential compromise source, revoked the affected credentials, and deployed additional security measures.
The attacker attempted extortion, demanding payment to prevent the code repository from being publicly released. Grafana refused to pay the ransom and plans to publish a detailed incident review after completing its investigation.
Related News