Target Corporation
Incident posture
Linked entities
- Victim
- Target Corporation
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Target employees confirm that leaked source code and documentation match internal systems, citing references to platforms like BigRED and TAP, customized CI/CD tooling, and internal identifiers. After being contacted about the alleged leak, the company accelerated a security change requiring managed‑network access to its on‑prem Git server. Investigators note a compromised employee workstation infected with infostealer malware that had access to IAM, Confluence, wiki, and Jira, though no direct link to the exfiltrated data has been established. The threat actor advertises an approximately 860 GB dataset, of which a 14 MB sample has been verified as authentic.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On January 13, 2026, BleepingComputer reported that threat actors were claiming to sell Target's internal source code after publishing a sample on the public Gitea platform. Multiple current and former Target employees contacted the outlet to confirm that the leaked code and documentation matched real internal systems. Employees verified that system names such as 'BigRED' and 'TAP [Provisioning]' corresponded to actual cloud and on‑premise deployment platforms used at Target. They also confirmed that technology stack elements like Hadoop datasets, a customized CI/CD platform based on Vela, and supply‑chain infrastructure such as JFrog Artifactory were present in the sample. Additionally, proprietary project codenames and internal taxonomy identifiers known as 'blossom IDs' appeared in the leaked material. The employees noted that the presence of internal URLs, employee names, and project names indicated the sample reflected a genuine development environment rather than fabricated code. The threat actor claimed the full dataset was approximately 860 GB, while BleepingComputer had only examined a 14 MB sample consisting of five partial repositories.
Following the initial report, a current Target employee shared a screenshot of a company‑wide Slack message from a senior product manager announcing an accelerated security change. The message stated that, effective January 9, 2026, access to git.target.com (Target's on‑premises GitHub Enterprise Server) now required connection to a Target‑managed network, either on‑site or via VPN. The employee said the change was rolled out a day after BleepingComputer first contacted Target about the alleged leak. This adjustment aligned with how the company was handling access to GitHub.com. No further details about additional technical controls were provided in the source material.
Security researcher Alon Gal, CTO and co‑founder of Hudson Rock, told BleepingComputer that his team had identified a Target employee workstation compromised by infostealer malware in late September 2025. The infected workstation had extensive access to internal services including IAM, Confluence, wiki, and Jira. The researcher noted that, among the dozens of infected Target employees observed, almost none possessed IAM credentials and none had wiki access except for this one other case. The article explicitly states that there is no confirmation linking this infection to the source code now being advertised for sale. The researcher added that it is not uncommon for threat actors to exfiltrate data and attempt to monetize or leak it months later.
Sources
Sources available to members: 1 source.