Cyber Incident Victim: Target Corporation
Date:
Sep 2025
Location:
United States of America
Summary
Target employees confirmed that leaked source code and documentation posted online match internal systems, citing references to platforms such as BigRED and TAP [Provisioning] and proprietary identifiers like blossom IDs. A senior manager announced infostealer malware on an employee workstation with access to IAM, Confluence, wiki, and Jira, and the company accelerated a policy requiring VPN or on‑site connection to its Git server. The threat actor claims the full dataset is about 860GB, while a 14MB sample reviewed by researchers contains authentic code, and no definitive source of the exfiltration has been established.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On January 13, 2026, BleepingComputer published a report stating that threat actors were claiming to sell Target Corporation's internal source code after posting a sample of repositories on the public Gitea platform. Multiple current and former Target employees contacted the outlet to verify that the leaked material matched real internal systems, citing specific references such as the internal platform names 'BigRED' and 'TAP [Provisioning]' used for cloud and on‑premise application deployment and orchestration. Employees also confirmed that technology stack elements mentioned in the sample, including Hadoop datasets and a customized CI/CD platform based on Vela, align with systems used internally at Target. The leaked sample further contained references to supply‑chain infrastructure like JFrog Artifactory and proprietary project codenames known internally as 'blossom IDs.' The presence of these system references, employee names, project names and matching URLs in the 14MB sample comprising five partial repositories led employees to conclude that the material reflects an authentic internal development environment rather than fabricated code.

A current employee shared a screenshot of a company‑wide Slack message sent by a senior product manager on January 9, 2026, announcing an accelerated security change that required access to Target's on‑prem GitHub Enterprise Server (git.target.com) to be made only from a Target‑managed network, either on‑site or via VPN. The message indicated that the change was implemented a day after BleepingComputer first contacted Target about the alleged leak and aligned with how the company was handling access to GitHub.com. Separately, security researcher Alon Gal of Hudson Rock told BleepingComputer that his team had identified a Target employee workstation compromised by infostealer malware in late September 2025, which had extensive access to internal services including IAM, Confluence, wiki and Jira. The researcher noted that, despite observing dozens of infected Target employee machines, almost none had IAM credentials and none had wiki access except for one other case, but there was no confirmation that this specific infection was directly connected to the source code now being advertised for sale.
The threat actor claims the full dataset is approximately 860GB in size, although BleepingComputer has only examined the 14MB sample. Employees who reviewed the sample said even this limited subset contains authentic internal code and system references, raising questions about the scope and sensitivity of what the much larger archive could contain. As of the report's publication, the root cause of how the data ended up in the hands of the threat actor had not been determined, and no direct link had been established between the compromised workstation identified by Hudson Rock and the leaked source code. The incident prompted Target to implement the accelerated access restriction to its internal Git server as part of its response, while the company continued to investigate the origin and extent of the exposure.
