Grafana (@grafana) on X

2 min read Original article ↗

user avatar

Our investigation has determined that no customer data or personal  information was accessed during this incident, and we have found no evidence of impact to customer systems or operations. (2/6)

user avatar

We immediately initiated forensic analysis and we believe we’ve identified the source of the credential leak.  We have since invalidated the compromised credentials and implemented additional security measures to further secure our environment against unauthorized access. (3/6)

user avatar

The attacker attempted to blackmail us, demanding payment to prevent the release of our codebase. (4/6)

user avatar

Based on our operational experience and the published stance of the FBI, which notes that "paying a ransom doesn't guarantee you or your organization will get any data back" and only "offers an incentive for others to get involved in this type of illegal activity," (5/6)

user avatar

… we’ve determined the appropriate path forward is to not pay the ransom.  As part of Grafana Labs’ standard security practices, we will share additional information from our post-incident review when our investigations are complete. (6/6)

user avatar

user avatar

⚠️ On May 16, 2026, we confirmed a targeted attack by a cybercrime group that gained unauthorized access to our GitHub repositories and downloaded our codebase. Here is the latest update about our investigations. grafana.com/blog/grafana-l…

user avatar

user avatar

Our review of the TanStack supply chain ransom incident confirmed it was limited to Grafana Labs’ GitHub environment. No customer production systems were accessed, Grafana Cloud was not affected, and

@Mandiant

found no evidence of code tampering. grafana.com/blog/post-inci…