All Breaches
May 11, 2026 Verified Technology

Grafana Labs GitHub 2026 Data Breach

The Grafana Labs GitHub 2026 data breach resulted from a GitHub workflow token leaked during the Mini Shai-Hulud supply-chain attack against TanStack npm packages and missed during the initial response. Attackers used that credential to clone the company's repository collection. Grafana Labs' final review says malicious code executed on its self-hosted runners on May 11, 2026, and repository exfiltration began on May 14.

The company confirmed that the intruder downloaded source code and repositories some teams used for internal operational information and other business details. The content included business contact names and email addresses exchanged in professional relationships, plus some email addresses used in past marketing campaigns. No person or unique record total was published, so pwnCount and totalRecords remain zero as unknown.

How Was the Incident Confirmed?

Grafana Labs' June 23, 2026 post-incident review says its internal investigation closed on May 27 and an independent Mandiant investigation completed on June 18, corroborating the internal findings. Mandiant found no evidence of code tampering or repository poisoning in public organizations or production repositories delivered to end users. The final report provides minute-level times for the initial execution, exfiltration, discovery, and response.

BleepingComputer's May 18 and May 20 reports also described access to Grafana's GitHub environment through a stolen token, the download of its codebase, and the company's refusal to pay a ransom. Reporting about the actor's group affiliation and leak-site statements is not substituted for the scope Grafana confirmed. LeakData treats the company's completed investigation as authoritative for dates and boundaries.

How Did the Attack Chain Work?

During the Mini Shai-Hulud campaign, malicious TanStack npm code reached a Grafana CI/CD workflow and executed on self-hosted GitHub runners on May 11, leaking credentials. Grafana quickly rotated a significant number of GitHub workflow tokens, but one token for a workflow initially believed to be unaffected was missed. The intruder used this credential to enter the company's private repositories.

According to the final timeline, the actor made the first malicious commit with the leaked grafana-delivery-bot identity at 07:21 UTC on May 14, and repository exfiltration began at 13:28 that day. An extortion demand appeared on May 15. Grafana's security team learned of the claim on May 16, confirmed the compromise later that day, and suspended or rotated known affected applications and credentials.

What Data Was Downloaded?

The primary confirmed data class is Grafana's entire collection of public and private source-code repositories. Private repositories held internal tooling and code for certain Grafana Cloud features. Some team repositories also contained internal operational information, business details, business contact names and email addresses used in professional relationships, and email addresses used in some past marketing campaigns.

This record does not claim that customer production data, observability data, passwords, or information processed through Grafana Cloud was stolen. Grafana specifically said the contact details were not pulled from production systems or the Grafana Cloud platform. The company offered a support channel for organizations asking whether addresses from their domain were identified, but did not publish a count of people.

Were Customers or the Software Supply Chain Affected?

The internal investigation and Mandiant review confirmed there was no unauthorized access to customer production systems and that the Grafana Cloud platform was unaffected. Grafana audited every commit, 1,200 repositories, GitHub applications, runners, and multiple infrastructure log sources. The downloaded codebase was not altered, and no repository poisoning was found in public or production repositories delivered to users.

Grafana therefore did not ask customers or open-source users to remove products, change versions, or take another incident-specific emergency action. Changes made through the attacker-controlled identity were identified and reverted; the company imposed code and deployment freezes, rotated credentials, and moved toward short-lived, narrowly scoped tokens. These limits do not negate the GitHub theft, but prevent it from being misread as a customer production breach.

What Was the Ransom Demand and Response?

Grafana received a demand on May 16 from a threat actor seeking payment to prevent publication of the codebase. Following FBI guidance that payment does not guarantee recovery and can incentivize more crime, the company declined to pay. Federal law enforcement was notified. LeakData does not treat unverified additional claims about the actor's identity or holdings as confirmed facts.

During response, Grafana suspended GitHub applications, temporarily froze code and deployments, and cross-checked Vault, GitHub, Okta, Kubernetes, AWS, GCP, and host logs. It reported 1,500 security-focused pull-request reviews, an audit of 280 GitHub applications, and broad credential rotation. The last potentially accessible credential was suspended or rotated on May 17.

How Should This LeakData Record Be Read?

The breachDate is May 11, 2026, based on the first malicious code execution in the company's final timeline. The event is the cloning of a repository collection through a stolen GitHub workflow token and the download of limited business contact information stored in those repositories. The 1,200 repositories Grafana said it scanned are an investigation scope, not a person or leaked-record count, and are not converted into pwnCount.

Readers should treat source code, internal operational information, business contact names, business email addresses, and past marketing email addresses as the confirmed data classes. Customer production systems, Grafana Cloud, code delivered to end users, and service availability were not affected. The record can be updated if a numeric scope is published; the current zero means the number of unique people is unknown, not that no information was exposed.

0
Affected Accounts
6
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

6
Source code
Internal operational information
Business contact names
Business email addresses
Past marketing email addresses
Github workflow credentials

Additional Information

Added DateJuly 27, 2026
Breach DateMay 11, 2026
Domaingrafana.com
SourceStolen GitHub workflow token used to clone Grafana Labs repositories
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information