Grafana Labs confirmed in a recent disclosure that hackers used a stolen token credential to access its GitLab environment and obtain repositories of source code. The company refused to pay a ransom after the attackers threatened to release its codebase.
"The attacker attempted to blackmail us, demanding payment to prevent the release of our codebase." Grafana Labs said its investigation was ongoing and that it will share its findings once the probe concludes.
The stolen token did not provide access to customer records or financial data, and no customer data was taken in the incident. It is unclear if the hackers stole any proprietary code or information. The GitLab environment is used for code development.
Grafana Labs invalidated the stolen token and added additional security measures to prevent a repeat incident. The company makes eponymous open source web visualization software. Its code is open source and public, allowing anyone to download the software and edit its code before running it on their own machines.
The disclosure follows another recent ransom incident involving Instructure, which reached an agreement to pay hackers who had compromised its network twice in recent weeks. The Instructure hackers demanded an unspecified ransom, threatening to release stolen data about staff and students following a data breach and a website defacement.
The FBI advises victims not to pay hackers because cooperating does not guarantee that stolen data will be returned or not published later. Grafana Labs did not pay the ransom demanded by the attackers who accessed its source code repositories.
forum Comments (0)
No comments yet. Be the first to comment.