Grafana Labs, a technology company, disclosed that an unauthorized party used a compromised GitHub token to access its GitHub environment and download portions of its codebase. This incident was reported in May 2026. The company stated that it found no evidence of customer data or personal information being accessed, and there was no impact to customer systems. Grafana Labs also reported that it refused an extortion demand and subsequently invalidated the compromised credentials.
The confirmed data type exposed was source code or portions of it from Grafana's GitHub environment. The company has not reported any exposure of Social Security numbers, medical data, financial data, or customer personal information. The number of affected individuals is not applicable as this was not a personal data breach, and no customer data was reported as accessed.
Details surrounding this event may emerge as the situation develops, and official notices are often delayed.