Grafana Labs disclosed a security incident in its GitHub environment, stating that customer data was unaffected and refusing to pay the ransom.

PANews reported on May 18th that Grafana, an open-source data visualization tool, announced on its X platform that an unauthorized party recently obtained a token to access its Grafana Labs GitHub environment, which the threat actor used to download its codebase. The company's investigation determined that no customer data or personal information was accessed in this incident, and no impact was found on customer systems or operations. The company immediately initiated forensic analysis and believes it has identified the source of the credential breach. Grafana has now invalidated the compromised credential and implemented additional security measures.

Attackers attempted to blackmail the company, demanding a ransom to prevent the release of its codebase. Based on operational experience and the FBI's public stance (that paying a ransom does not guarantee data recovery and only incentivizes more such illegal activities), Grafana decided not to pay the ransom. As part of standard security practice, the company will share more information from its post-incident review upon completion of the investigation.

Share to:

Author: PA一线

This content is for market information only and is not investment advice.

Follow PANews official accounts, navigate bull and bear markets together
PANews APP
Analysts: Current trading enthusiasm in the crypto market is lower than at the bottom of the last bear market.
PANews Newsflash