INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Grafana GitHub Token Breach Leads to Codebase Download and Extortion

| 2026-05-17 07:13 CRITICAL MEDIUM RANSOMWARE & EXTORTION DATA BREACH
Executive Summary
AI-generated
On May 17, 2026, an unauthorized party obtained a GitHub token that granted them access to Grafana's environment and downloaded its codebase. The attackers, reportedly from the data extortion crew CoinbaseCartel, which emerged in September 2025 as an offshoot of other groups, have demanded payment to prevent publication of the stolen database. No customer data or personal information was accessed during this incident, but the company has opted not to pay a ransom, citing warnings from the U.S. Federal Bureau of Investigation against negotiating with perpetrators. The breach has been attributed to CoinbaseCartel and is believed to be their 170th victim across various sectors; however, no further details on how the attackers gained access are available.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

ra•••••.live
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
LAPSUS$LAPSUS$Scattered SpiderScattered Spider
Target & Sectors
NORTH_AMERICA NORTH_AMERICA educationeducation technologytechnology
Incident Timeline
‎September 2025
Threat actors, believed to be an offshoot of the ShinyHunters, Scattered Spider, and LAPSUS$ ecosystems, used stolen GitHub tokens to target victims across multiple industries.
victims 170 victims
threat_actor Scattered Spider
threat_actor LAPSUS$
Tactical Metrics
Metrics
victims
170
Victims
Intelligence Sources