Grafana Labs confirmed a cyberattack on its systems, revealing that hackers exploited a stolen token credential to gain access to the company's GitHub environment. The firm has stated that customer records and financial data remain secure, and it has taken steps to enhance its security protocols by invalidating the compromised token.
The hackers attempted to extort the company by threatening to release its codebase unless a ransom was paid. In a statement, Grafana emphasized its commitment to not comply with such demands, citing guidance from the FBI that advises against paying hackers, as this does not ensure the return of stolen data.
Unlike the recent incident involving education technology company Instructure, which agreed to pay a ransom after multiple breaches, Grafana's code remains open source and accessible to the public. The investigation into the breach is ongoing, and further findings will be shared once completed. A company spokesperson did not provide immediate comments on the situation.