Round 2 of the Target data breach? Hackers threaten to leak data
Target hit twice this year, or is someone bluffing?

- Ransomware gang Xpl0itrs claims they stole 8.6GB of Target source code and threatens to leak it unless the company negotiates.
- Target has not confirmed the breach yet.
- Cybernews researchers say the breach claim may relate to a January code leak.
- Xpl0itrs previously claimed attacks on OpenAI, Spotify, the US Treasury, and Trustpilot. However, they released no data samples.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
US merchandise giant Target may have been hit by another breach this year, with hackers claiming to have stolen source code.
Target, a major US general merchandise retailer, has once again appeared on the dark corners of the internet.
A newcomer to the ransomware scene, going under the name Xpl0itrs, is behind the claims.
The gang created the leak site on the Dark Net on June 17th and started listing victims on August 15th. The threat actor claims to have stolen 8.6GB of Target’s source code.
It has set a deadline for the company to reach out and negotiate within 2 days, threatening to leak the data if it doesn't.
The legitimacy of the claims remains unverified. Cybernews has reached out to Target and will update this article once a response is received.
With over 2,000 stores across the United States, the Target Corporation boasts $104.78 billion in annual revenue.
Has Target been breached again?
At this point, there is no confirmation if it is a new data breach affecting Target. However, Cybernews researchers believe that the claimed 8.6GB dataset may be connected to a data leak that hit Target in January this year.
An unknown threat actor created multiple repositories on Gitea, a self-hosted Git service, purportedly containing portions of Target's internal code and developer documentation.
The listing was more than 57,000 lines long and advertised a total archive size of approximately 860GB.
Target locked down git[.]target[.]com behind VPN on January 9th. Reportedly, the breach was traced to an infostealer that hit an employee workstation in late September 2025.
Xpl0itrs has not provided any data samples to help define what data has been stolen. While significantly smaller than the previously stolen dataset, it also includes source code, as the threat actor claims in the listing.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Target has leaked 40 million credit cards before
Target has been associated with a tremendous data leak before. In 2013, Target suffered a massive data breach.
After credentials were stolen from a third-party contractor, the credit and debit card information of 40 million people was stolen.
Target later acknowledged that the attack had also exposed contact and identifying information for as many as 70 million individuals.
Xpl0itrs has previously claimed OpenAI and Spotify
The gang has previously claimed high-profile victims, but the legitimacy of these alleged breaches raises questions.
In June, Xpl0itrs conducted a staged, 2-post campaign on X (formerly Twitter), publicly naming Spotify, the US Department of the Treasury, OpenAI, and Trustpilot as its victims.
According to analysis by Dataminr, attackers had an affiliate account, @xpl0itrsturtle2, which posted a teaser – a winking emoji next to a 4-logo image grid showing Spotify, US Treasury, OpenAI, and Trustpilot logos.
After a week, the primary @xpl0itrs account followed up, confirming the same 4 targets by referencing the previous post.
Shortly after, X suspended the @xpl0itrs account. No formal dark-web forum listing with actual data samples for any of the 4 targets has been found since.
Among the gang's other victims is the Australian company Oz Hair & Beauty. The Aussie company was listed with an alleged 2.1M customer records. The company confirmed that some customer data was affected by a breach at a third-party provider.
The threat actor also claimed to have stolen 800 motorcycle and dealership documents from BMW. However, Cybernews researchers discovered that the data was partly publicly available anyway.