Cyber Incident Victim: Target Corporation
Timeline
Summary
Target faced a claim that hackers exfiltrated 8.6 gigabytes of its source code and threatened to publish the data unless a payment was made, with the attackers providing no verifiable samples and having a history of unsubstantiated leak announcements. Researchers suspect the data may be recycled from a prior large-scale breach confirmed by the retailer, suggesting the current allegation does not represent a new intrusion.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
In January 2026 a threat actor posted a thread in an underground hacking community claiming to be selling Target’s data and stating that this was the first of many datasets to be auctioned. To support the claim the actor created multiple repositories on the self‑hosted Git platform Gitea and uploaded a small sample of the alleged data. The repositories together totaled around 860 GB and appeared to contain internal Target source code, configuration files, and developer documentation, with repository names referencing internal systems such as wallet services, identity management, store networking tools, secrets documentation, and gift card systems. Target later confirmed the authenticity of this breach, acknowledging that the leaked material corresponded to genuine internal assets.

In mid‑June 2026 a different threat actor using the alias Xpl0itrs established a new data leak site and added Target to it earlier in July 2026. Xpl0itrs asserted that they had stolen 8.6 GB of Target’s source code and gave the company two days to pay a ransom or see the data released on the dark web. No samples of the purported data were shared by Xpl0itrs, and security researchers noted that the lack of evidence, combined with the actor’s history of dubious leak claims, led many to suspect that the alleged 8.6 GB haul was actually recycled material from the January 2026 incident. Researchers also pointed out that Xpl0itrs had previously teased leaks involving Spotify, the U.S. Department of the Treasury, OpenAI, and Trustpilot that never materialized, and had claimed to possess BMW documents that were later shown to be publicly available.
As of the article’s publication date in August 2026 Target had not issued any confirmation regarding the validity of Xpl0itrs’ claim, and the company’s public statements remained focused on the earlier verified breach. The uncertainty surrounding the second allegation persisted, with analysts noting that without verifiable samples or independent verification the claim could not be substantiated, while the earlier January breach remained a confirmed incident involving substantial exposure of Target’s internal source code and related assets.