Grafana Labs confirmed that hackers from the extortion group CoinbaseCartel stole its source code by using a stolen GitHub access token. The company found no evidence of customer data exposure and refused to pay the ransom, citing FBI guidance that paying does not guarantee data recovery and only incentivizes further attacks. CoinbaseCartel, active since last September, has claimed over 100 victims and is linked to ShinyHunters and Lapsus$ affiliates who use social engineering, phishing, and compromised credentials to breach targets.
113 Impressions