Grafana GitHub Token Stolen, Codebase Downloaded and Extortion Attempted

An unauthorised actor stole a GitHub access token from Grafana, downloaded its codebase, and attempted extortion. The CoinbaseCartel group has claimed responsibility. Grafana refused to pay the ransom and has revoked the compromised credentials.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region6 min read
Developer screen with code and a cracked padlock representing the Grafana GitHub token breach and data extortion incident

Developer screen with code and a cracked padlock representing the Grafana GitHub token breach and data extortion incident

Grafana Labs, the company behind one of the most widely deployed open-source observability and data visualisation platforms in the world, has disclosed a security incident in which an unauthorised party stole a GitHub access token, used it to download the company's private codebase, and subsequently attempted to extort the company by threatening to publish the stolen data unless a ransom was paid. Grafana confirmed the incident in a series of posts on X, stating that its forensic investigation found no evidence that customer data or personal information was accessed, and that there has been no confirmed impact on customer systems or operations. The compromised credentials have been revoked, the vulnerable workflow has been removed, and additional security controls are in place. Grafana also confirmed that investigators have identified the root cause of how the credentials were exposed.

How the attacker got in: the Pwn Request technique

The breach traces back to a recently enabled GitHub Actions workflow that contained a class of misconfiguration known as a "Pwn Request" vulnerability. The workflow was configured to trigger on pull_request_target events, a setting that inadvertently granted external contributors, including anyone who could open a pull request against a public Grafana repository, access to production secrets during CI runs. The attacker's method was calculated and methodical. By forking a Grafana repository, injecting malicious code via a curl command, and dumping environment variables to a file encrypted with a private key, the threat actor extracted a privileged GitHub token. They then deleted their fork to cover their tracks before using the stolen token to access four additional private repositories and download their contents. Grafana's canary token infrastructure detected the activity. One of the company's deployed canary tokens was triggered, immediately alerting the global security team and initiating the incident response process. After downloading the codebase, the attacker made contact with Grafana and demanded payment in exchange for not releasing the stolen source code publicly. Grafana declined to pay, citing FBI guidance on ransomware and extortion payments, which states clearly:

"Paying a ransom doesn't guarantee you or your organisation will get any data back. It also encourages perpetrators to target more victims and offers an incentive for others to get involved in this type of illegal activity."

Grafana's refusal to pay stands in direct contrast to the recent decision by Instructure, parent company of Canvas LMS, which reportedly settled with the ShinyHunters group after they threatened to leak terabytes of data from thousands of US schools and universities.

Who is CoinbaseCartel

The incident has been claimed by a group identified as CoinbaseCartel, according to reports from Hackmanac and Ransomware.live. Analysis from Halcyon and Fortinet FortiGuard Labs places CoinbaseCartel within the broader ecosystem of English-speaking cybercriminal actors known collectively as "The Com." The group is assessed to be an offshoot of ShinyHunters, Scattered Spider and LAPSUS$, three threat actors with a well-documented record of high-profile breaches. ShinyHunters specialises in large-scale data exfiltration from cloud platforms. Scattered Spider is known for sophisticated social engineering and initial access operations. LAPSUS$ made headlines for breaching major technology companies including Microsoft, Okta and NVIDIA through credential theft and insider manipulation. CoinbaseCartel draws from this talent pool and operates as a focused data extortion arm within that broader ecosystem. Unlike traditional ransomware groups, CoinbaseCartel skips file encryption entirely. Their model is simpler and, in some respects, harder to defend against: steal the data, contact the victim, threaten publication, and demand payment. They operate a dark web leak site and use staged disclosures, releasing sample files first to prove possession of the data before escalating to the threat of full publication. The group has accumulated an estimated 170 victims across healthcare, technology, transportation, manufacturing and business services since emerging in September 2025, and reached the top 10 of tracked ransomware and extortion groups within their first few months of operation.

Why this matters beyond Grafana

The Grafana incident is not an isolated breach. It is a signal about where attacks are heading in 2026. Developer infrastructure, CI/CD pipelines, and the credentials that access them have become primary targets precisely because a single privileged token can provide access to far more than one organisation's assets. A successful attack against a widely trusted observability platform, a package registry or a shared build system can create downstream effects across thousands of dependent organisations. This connects directly to the coordinated supply chain attack on RubyGems reported this week, in which over 500 malicious packages were pushed to the open-source registry in a bot-driven campaign. Both incidents point to the same structural vulnerability: the software supply chain and the developer credentials that sustain it are under sustained, organised attack. Grafana is deployed extensively as the observability layer for cloud and Kubernetes infrastructure in enterprise environments. As identity security has become the defining challenge for GCC enterprise teams, a stolen developer token that bypasses every perimeter control is exactly the kind of credential exposure that security leaders need to build explicit controls around. Security researchers also note that even when customer data is unaffected, stolen source code creates a long-term risk. Attackers study proprietary code to identify undisclosed vulnerabilities, extract authentication logic, and map deployment details that assist future intrusions.

What enterprise security teams should do now

The following actions are recommended as immediate priorities for any organisation using GitHub or similar source code platforms. Audit all personal access tokens and OAuth credentials with access to production or sensitive repositories, and rotate any that have not been reviewed in the past 90 days. Enforce short expiry periods and least-privilege scopes across all developer credentials. Review all GitHub Actions workflows for pull_request_target triggers in public repositories and restrict CI secrets accordingly. Deploy canary tokens across private repositories to detect unauthorised access attempts early. Ensure that source code repository access events are logged and that bulk clone or export activity outside normal working hours triggers an alert. In regulated environments across Dubai and the broader MENA region, organisations operating under NESA, SAMA CSF or UAE IA standards should review whether a breach of proprietary source code falls within their incident notification obligations. The regulatory risk of a breach of this nature extends beyond reputational damage into potential compliance exposure that security teams should not overlook.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.

Intelligence Focus Areas

Data ExtortionCloud SecurityDeveloper Credential SecurityThreat Actor IntelligenceSupply Chain SecurityCode Repository Securitymena cyber security news