Grafana, an open-source data visualization tool, recently reported an unauthorized access incident involving its GitHub environment. According to ChainCatcher, an attacker obtained a token that allowed access to Grafana Labs' GitHub repositories and downloaded code. The investigation confirmed that no customer data or personal information was compromised, and there was no impact on customer systems or business operations. Following the incident, Grafana initiated a forensic analysis and identified the source of the credential leak, implementing additional security measures to protect the environment.
Additionally, Grafana revealed that the attacker attempted to extort the company by demanding a ransom to prevent the public release of the code. However, Grafana decided not to pay the ransom. The company plans to release more information about the incident after the investigation concludes.