Grafana confirms GitHub token breach cybercrime group claims the attack


Grafana confirms GitHub token breach cybercrime group claims the attack

Pierluigi Paganini
May 18, 2026

Grafana confirmed a GitHub token breach that exposed source code, but said no customer data or systems were affected.

Grafana Labs confirmed a security incident after the extortion group Coinbase Cartel listed it on a leak site and claimed data theft on May 15. The breach was triggered by a compromised token that gave attackers access to the company’s GitHub environment.

Grafana Labs is a software company best known for building open-source tools used to monitor and visualize data from IT systems, applications, and infrastructure. Its main product, Grafana, lets organizations create dashboards to track performance metrics, logs, and alerts in real time. It is widely used in cloud computing, DevOps, and cybersecurity environments to help teams understand system health and troubleshoot issues quickly.

The group Coinbase Cartel later added Grafana to its victim portal. Grafana said attackers accessed parts of its source code, but found no evidence of customer data theft, personal data exposure, or impact on customer systems or operations.

The company revoked and reset the compromised credentials. The company has also launched a forensic investigation to determine how the token was exposed, what repositories were accessed, and whether any additional systems may have been affected. Grafana promised to release more details once the investigation is complete.

Grafana Labs said it will not pay the ransom demanded by attackers to prevent publication of the stolen source code. At the time of writing, the group Coinbase Cartel had not published Grafana’s data, but reportedly issued threats warning of potential consequences if its demands were ignored.

Coinbase Cartel has been active since at least September 2025 and has claimed more than 100 victims. Unlike traditional ransomware gangs, the group focuses on stealing data and extorting companies instead of encrypting systems. This approach allows victims to remain operational while still facing serious risks tied to stolen files, credentials, and intellectual property.

Researchers have linked Coinbase Cartel to the broader ecosystem around ShinyHunters, Scattered Spider, and Lapsus$, groups known for attacks based on stolen credentials, social engineering, cloud abuse, and compromise of developer environments.

A compromised or exposed GitHub token can give attackers direct access to sensitive source code repositories, making platforms like GitHub critical targets in modern attacks. In the case of Grafana Labs, the company said no customer systems were impacted, but stolen source code can still be risky because private repositories may contain internal logic, secrets, build processes, or unreleased features that attackers can analyze for vulnerabilities or use in phishing and supply chain attacks.

The incident underscores the importance of strong token security. Access tokens should be short-lived, tightly scoped, regularly rotated, monitored, and quickly revoked if suspicious activity is detected, while repository access should be protected with phishing-resistant MFA and strict least-privilege controls.

The incident highlights how source code platforms have become prime targets for extortion groups because they sit at the heart of software development.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, security breach)







Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


Love him or hate him, Seth MacFarlane has an immovable place in the realm of TV comedy, and Ted is an excellent showcase for the writer at his best. A seasoned actor and writer of over 3 decades, he has created numerous hit productions, including adult animation tentpoles like Family Guy and American Dad!, as well as The Orville.

However, his talents have also allowed him to make the leap from television to the big screen, including his 2012 comedy Ted, which asked what would happen to a child who wished their teddy bear for life once they grew into adults.

However, in 2024, MacFarlane brought Ted to the small screen with a television series that dived into the times not seen in the 2012 movie. And I personally feel that the show has become one of MacFarlane’s finest projects to date:

How Does Ted Tie Into The Movies?

A new side of John and Ted

Ted is set between the opening 1985 sequence of the original 2012 movie and the present-day sequence, honing in on John’s teenage years at high school as Max Burkholder takes on the role. When Ted pushes things too far, he is forced to attend school with John, leading to the pair experiencing many major developmental milestones together. From falling in love to going against his parents’ wishes and trying weed for the first time, the pair take on the world together.

Alongside the main duo, Ted also shines a light on the rest of the Bennett household. Frequent MacFarlane collaborator Scott Grimes takes on the voice of John’s loudmouthed conservative father Matty, while Alanna Ubach portrays his soft-spoken, good-hearted mother Susan. The Bennett family is rounded out by Giorgia Wigham’s Blaire, John’s politically minded cousin staying with the family who is always looking out for the leading pair.

A new addition to the lore

Much like Family Guy and American Dad took on The Simpsons‘ animated family sitcom and The Orville lampooned Star Trek, Ted twists a certain style of sitcom. There have been no shortage of throwback sitcoms set in the past since the late 2010s, with The Goldbergs and Young Sheldon playing into the nostalgia people either have for that time or recognize through long-running franchises or series like Stranger Things to attract viewer attention.

In Ted, the show turns its lens to the 1990s, with Blaire being part of the youthful generation who wants to challenge the status quo. However, she butts heads with various authority figures. Plus, Matty and Jon find themselves affected by the OJ Simpson case in varying ways.

Collage featuring 1990s sitcoms around an old TV.


Go Retro and Stream These 10 Sitcoms of the 1990s

These are the 1990s prime time sitcoms that have held up better than my collection of Pogs.

Despite this setting and inevitable plays on the events of the decade, the show isn’t entirely dependent on nostalgia. Ted’s very existence already set the series up in a position where it could do anything, and MacFarlane doesn’t hold back. From new talking toys and the relatable gag about how hot McDonald’s apple pies are to an entire episode that cuts between the group playing a Dungeons and Dragons game around a table and their characters within the game’s world, the series isn’t afraid to get strange. Because of that, it is hard to find an underwhelming episode throughout its run.

Ted has a surprising amount of heart

Is this the best of Seth MacFarlane?

While MacFarlane is a seasoned comedic writer whom audiences are incredibly familiar with, from his strengths to his stylistic flaws, I do feel that Ted is, for the most part, the best of what he has to offer. The series does have the sharper edge his humor can have at times, with Ted himself having some absolutely devastating insults towards the bullies at John’s school, as well as the cast overall tiptoeing between crass humor and smartly written gags. But this is a story about a bear brought to life with a child’s wish, so there is always a good deal of heart within every episode.

Thanks to the incredible chemistry between the cast, the Bennett family unit is easy to root for. Part of the enjoyment of the show is seeing John grow into the man he was in the original movie, but it is also heartwarming to see Blaire find her place in the Bennett household, even if she butts heads with Matty. Meanwhile, even Matty has several moments of vulnerability despite his hard-headed, typically politically incorrect self, which show just why Susan, who is the delightful and lovable heart of the show, fell for him.

One week the family may be playing a Dungeons and Dragons game to replenish their stash of weed, and the next will see them dedicating themselves to fulfilling Susan’s unrealized dream or helping Matty through the stranger side of his experiences in Vietnam. Even John’s bully Clive (Jackson Seavor McDonald) gets an off-kilter spotlight where the leading pair go from pulling a horrible revenge prank on him to becoming his unlikely father figures. MacFarlane’s edge is always there, but there is always a softer side to tug at your heartstrings and cushion you if not every gag lands.​​​​​​​

Where to watch Ted

All episodes are now streaming

Ted falls out of the tumble dryer in Ted. Credit: Peacock

​​​​​​​ Both seasons of Ted are currently available in their entirety on Peacock. Season 1 consists of 7 episodes, while season 2 received a larger episode count of 8. However, even after having an overall positive response and viral attention thanks to shared and reposted clips, MacFarlane confirmed that there were no current plans for season 3, as the costs to bring Ted to life on a television budget are incredibly high.

However, as Ted said himself, “Don’t be sad because it’s over; be happy because it happened.” Even against the costs, MacFarlane set out to ensure that Ted’s surprising expansion into television would still be a fulfilling experience, ensuring that the series could at least end on a satisfying note. As such, if you wish to see just how having an irresponsible magical stuffed friend shaped John’s life ahead of the movies, you will not be disappointed.​​​​​​​



Source link