CSIDB logo
Incident

Target Corporation

Incident posture

Attack window
Sep 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-27 02:14

Linked entities

Victim
Target Corporation
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Sep 2025
Discovered
Jan 2026
Disclosed
Jan 2026
Resolved
Pending

Summary

Target employees confirm that leaked source code and documentation match internal systems, citing references to platforms like BigRED and TAP, customized CI/CD tooling, and internal identifiers. After being contacted about the alleged leak, the company accelerated a security change requiring managed‑network access to its on‑prem Git server. Investigators note a compromised employee workstation infected with infostealer malware that had access to IAM, Confluence, wiki, and Jira, though no direct link to the exfiltrated data has been established. The threat actor advertises an approximately 860 GB dataset, of which a 14 MB sample has been verified as authentic.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On January 13, 2026, BleepingComputer reported that threat actors were claiming to sell Target's internal source code after publishing a sample on the public Gitea platform. Multiple current and former Target employees contacted the outlet to confirm that the leaked code and documentation matched real internal systems. Employees verified that system names such as 'BigRED' and 'TAP [Provisioning]' corresponded to actual cloud and on‑premise deployment platforms used at Target. They also confirmed that technology stack elements like Hadoop datasets, a customized CI/CD platform based on Vela, and supply‑chain infrastructure such as JFrog Artifactory were present in the sample. Additionally, proprietary project codenames and internal taxonomy identifiers known as 'blossom IDs' appeared in the leaked material. The employees noted that the presence of internal URLs, employee names, and project names indicated the sample reflected a genuine development environment rather than fabricated code. The threat actor claimed the full dataset was approximately 860 GB, while BleepingComputer had only examined a 14 MB sample consisting of five partial repositories.

Following the initial report, a current Target employee shared a screenshot of a company‑wide Slack message from a senior product manager announcing an accelerated security change. The message stated that, effective January 9, 2026, access to git.target.com (Target's on‑premises GitHub Enterprise Server) now required connection to a Target‑managed network, either on‑site or via VPN. The employee said the change was rolled out a day after BleepingComputer first contacted Target about the alleged leak. This adjustment aligned with how the company was handling access to GitHub.com. No further details about additional technical controls were provided in the source material.

Security researcher Alon Gal, CTO and co‑founder of Hudson Rock, told BleepingComputer that his team had identified a Target employee workstation compromised by infostealer malware in late September 2025. The infected workstation had extensive access to internal services including IAM, Confluence, wiki, and Jira. The researcher noted that, among the dozens of infected Target employees observed, almost none possessed IAM credentials and none had wiki access except for this one other case. The article explicitly states that there is no confirmation linking this infection to the source code now being advertised for sale. The researcher added that it is not uncommon for threat actors to exfiltrate data and attempt to monetize or leak it months later.

Sources

Sources available to members: 1 source.

CSIDB