Skip to content

Grafana Labs

Disclosed May 16, 20264 months agoUnverified

Grafana Labs says stolen GitHub token let hackers take its source code

Grafana Labs said attackers used a stolen GitHub access token, one that missed rotation after the TanStack supply-chain attack, to download its source code, and it refused an extortion demand. It found no customer data exposed.

What is known

People affectedNot stated in the sources we have
DisclosedMay 16, 2026
AttackSupply chain
Data exposedSource code
SectorTech · US
StatusUnverified: not yet confirmed by an official notice, a filing or the organization
Part ofTanstack (2026)

Sources

Notices filed

WhereFiledPeople
ResearchtotalMay 16

Same campaign

History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.

Everything about Grafana Labs

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.