Grafana Labs
Disclosed May 16, 20264 months agoUnverified
Grafana Labs says stolen GitHub token let hackers take its source code
Grafana Labs said attackers used a stolen GitHub access token, one that missed rotation after the TanStack supply-chain attack, to download its source code, and it refused an extortion demand. It found no customer data exposed.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | May 16, 2026 |
| Attack | Supply chain |
| Data exposed | Source code |
| Sector | Tech · US |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
| Part of | Tanstack (2026) |
Sources
| Source | |
|---|---|
| Open source tool maker Grafana Labs says hackers stole its code, refuses to pay ransomtechcrunch.com · News | News |
| Grafana says stolen GitHub token let hackers steal codebasebleepingcomputer.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | May 16 |
Same campaign
| Organization | Affected | ||||
|---|---|---|---|---|---|
| May 204 months ago | Supply chain | Tech | Confirmed | Unknown | |
| May 144 months ago | Supply chain | AI | Unverified | Unknown | |
| May 144 months ago | Supply chain | AI | Confirmed | Unknown |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.