Monday, August 3, 2026

Apps & Consumer

Grafana Labs confirms code theft, refuses to pay ransom

Grafana Labs confirmed hackers stole code via a GitHub token breach but refused to pay a ransom, though it remains unclear if proprietary information was compromised.

Grafana Labs confirms code theft, refuses to pay ransom

Grafana Labs, the developer of open source web visualization software—defined as software with source code that anyone can inspect, modify, and enhance—has confirmed a security breach. The company stated that hackers stole its code after hackers had abused a stolen token credential to access the firm’s GitHub environment. A token credential is a digital authentication key used to access systems. Despite the breach, the company refused to pay the ransom.

The company stated that the compromised token credential did not allow access to customer records or financial data. However, because Grafana Labs’ core software is open source and publicly available, it remains unclear if any proprietary code or information was stolen during the incident. In explaining its decision to reject the extortion attempt, the company stated: “The attacker attempted to blackmail us, demanding payment to prevent the release of our codebase.”

This response contrasts with the recent decision by education technology company Instructure to pay hackers following a similar incident. Instructure reached an agreement to pay hackers last week after its network was compromised. Grafana Labs’ decision to reject the blackmail attempt aligns instead with guidance from the FBI (the US federal law enforcement agency), which advises victims against paying ransoms because doing so does not guarantee the safety of the data and funds future cyberattacks.

Why it matters

Grafana Labs’ refusal to pay a ransom highlights a growing divide in corporate cybersecurity strategy, contrasting sharply with recent decisions by other firms like Instructure to pay hackers.