According to Grafana Labs' latest investigation released on May 20, the May 16 security incident was limited to the company's GitHub environment and did not affect customer production systems, operations, or Grafana Cloud platform. The downloaded content included source code and internal repositories with business contact information, but no data from production systems or cloud platforms. The code was accessed but not modified.
Grafana Labs has rotated automated credentials, enhanced monitoring, audited all commits since May 11, and strengthened GitHub security configurations. The company has notified federal law enforcement and declined to pay the ransom demand received on May 16.