Open source tool maker Grafana Labs says hackers stole its code, refuses to pay ransom


Grafana Labs, the maker of its eponymous popular open source web visualization software, confirmed it had been hacked but that it refused to pay the hackers who had threatened to release the company’s codebase.

In a series of posts on social media, the lab said its investigation found that the hackers had abused a stolen token credential that allowed access to the company’s GitHub environment, which it uses for storing its source code, but the token did not allow access to customer records or financial data. The company has since invalidated the token and added additional security measures to prevent a repeat incident.

“The attacker attempted to blackmail us, demanding payment to prevent the release of our codebase,” the company said.

Grafana’s code is open source and public, meaning anyone can download the software and edit its code before running it on their own machines. It’s unclear if the hackers stole any proprietary code or information. A spokesperson for the company did not immediately return a request for comment.

The incident contrasts with the recent hack at education tech giant Instructure, which last week “reached an agreement” to pay the hackers who had compromised its network twice in recent weeks. The hackers had demanded an unspecified ransom, threatening to release stolen data about staff and students who use its software following a massive data breach and a subsequent website defacement.

While in Grafana’s case, no customer data was taken, the company cited the FBI’s long-standing advice urging victims not to pay hackers, as cooperating with them does not guarantee they will return stolen data or refrain from publishing it later. Critics also say paying cybercriminals helps to fund future cyberattacks.

Grafana said its investigation was ongoing and will share its findings once its probe concludes.

This story was updated to correct that the hackers compromised access to Grafana’s GitHub environment.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.



Source link

  • Related Posts

    Best iPhone in 2026: Here’s Which Apple Phone You Should Buy

    We’ve tested and reviewed the powerful iPhone 17 Pro and 17 Pro Max, the thin and light iPhone Air, the solid iPhone 17 and the newer iPhone 17E to determine…

    Dyson’s super-slim PencilWash just hit its best price to date for Memorial Day

    If Dyson’s PencilVac Fluffycones made you wish the company had built something similarly slim for scrubbing the hard floors in your home, enter the recently released Dyson PencilWash. The cordless…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Supreme Court sends Native American voting rights decision back to lower court

    Supreme Court sends Native American voting rights decision back to lower court

    Best iPhone in 2026: Here’s Which Apple Phone You Should Buy

    Best iPhone in 2026: Here’s Which Apple Phone You Should Buy

    Alabamans to choose nominees for US Senate as voting maps in flux

    Alabamans to choose nominees for US Senate as voting maps in flux

    Global Building Emissions Tick Up as Urbanization Accelerates

    Fears of new China shock as EU industry’s reliance on imports grows | International trade

    Fears of new China shock as EU industry’s reliance on imports grows | International trade

    51 Best Early Memorial Day Sales 2026

    51 Best Early Memorial Day Sales 2026