HomeSecurityGrafana GitHub token breach: Code theft and blackmail

Grafana GitHub token breach: Code theft and blackmail

Grafana revealed that an unauthorized person gained access to the company's GitHub token , which allowed them to break into the GitHub environment and download the platform's code . An extortion attempt followed, with the attackers demanding a sum of money to not make the stolen data public.

Grafana GitHub token breach

According to Grafana's official statement, was accessed customer data or personal information during the incident. "Our investigation determined that no customer data or personal information was accessed during this incident, and we found no evidence of an impact to customer systems or operations," the company said.

See also: GitHub Phishing: Fake OpenClaw tokens to steal crypto wallets

The incident was detected in late April, triggering an immediate investigation by the security team. The company identified the source of the leak and immediately revoked the compromised credentials, while implementing additional security measures to protect against unauthorized access.

Blackmail Attempt and Grafana's Reaction

After the code was stolen, the attackers attempted to blackmail Grafana, demanding payment to prevent the publication of the stolen database. The company chose not to pay the ransom, following the recommendations of the FBI, which has warned against negotiating with blackmailers.

Grafana GitHub token breach: Code theft and blackmail

The FBI has stressed that there is no guarantee that paying the ransom will help affected companies recover their data, while also encouraging criminals to target more victims and providing an incentive for others to engage in illegal activities.

See also: EtherRAT pretends to be management tools via fake profiles on GitHub

As The Hacker News reports, the incident comes a few days after the company Instructure extortion group ShinyHunters 's controversial decision to negotiate with the , following a recent attack.

Reports indicate that a cybercriminal group called CoinbaseCartel has claimed responsibility for the incident. According to Fortinet FortiGuard Labs, CoinbaseCartel is a data extortion group that emerged in September 2025 and is believed to be an offshoot of the ShinyHunters, Scattered Spider , and LAPSUS$.

Grafana GitHub token breach: Code theft and blackmail

Protection Measures and Security Recommendations

Grafana announced that it has implemented additional security measures to prevent a similar incident from happening again. The company is moving to short-lived tokens, compartmentalized vaults, and stronger CI/CD.

Security experts recommend that organizations avoid using pull_request_target unless absolutely necessary, not expose secrets in workflows that process untrusted pull requests, and use tokens with the least necessary privileges. Additionally, it is recommended to use canary tokens to detect accidental or malicious access.

See also: GitHub fixed critical RCE vulnerability in less than 6 hours

The incident highlights the importance of properly configuring GitHub Actions and protecting automation credentials. Organizations should maintain rotation playbooks for GitHub tokens,deploy keys, and service account credentials, while also monitoring for unusual workflow executions and new GitHub Actions files.

The Grafana is yet another example of the risks that technology companies face from sophisticated attacks targeting CI/CD systems and development environments.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS