Hackers claim to have in their possession and are offering for sale internal source code of Target Corporation, one of the largest retailers in the U.S. The claims were accompanied by the publication of code samples and technical documentation on a public software development platform, raising serious concerns about the security of the company's development infrastructure.

The first traces of the alleged leak
Last week, an unknown threat actor created multiple repositories on Gitea, a self-hosted Git service similar to GitHub and GitLab. The repositories appeared to contain internal code snippets, configuration files, and developer documents allegedly related to internal Target projects. According to the hackers, this material was only a small sample of a much larger dataset that was being offered for sale via underground forums or private channels.
See also: BreachForums: Data leak exposes 324,000 criminals
Data sale and "preview" 860 GB
Each repository was accompanied by a file named SALE.MD, which listed tens of thousands of files and folders. The list was over 57,000 lines long and advertised a total data volume of approximately 860 GB. The perpetrators reportedly described the material as “the first package to be auctioned,” suggesting that more would follow.
The names of the repositories included indications of digital wallet services, identification systems, gift card applications , and documents that contained – according to the titles – sensitive information.

Internal reports that raise questions
What was particularly striking was that the metadata and documentation mentioned names of Target’s internal development servers, as well as names of current heads and senior engineers at the company. There were also references to internal APIs and collaboration platforms, such as corporate documentation systems, which would be difficult to find in publicly available code.
See also: Protecting digital assets: Crypto security
Target's Git server down
After inquiries from media sources, Target's Git repositories were removed and began returning 404 errors. At about the same time, the company's official Git server, git.target.com, became inaccessible from the internet. While it had previously redirected to a login page for employees via a secure network or VPN, it no longer loads externally.
Interestingly, search engines had temporarily indexed and cached a limited number of resources from this subdomain, indicating that some content was publicly accessible in the past, but this does not prove a direct link to the current allegations.

How reliable are the claims?
While the full 860GB has not been independently verified nor has a breach been officially acknowledged, the folder structure, project names, and internal references are consistent with a large corporate development environment. Additionally, the content does not appear to be related to Target's known open source projects, reinforcing the internal origin scenario.
See also: HawkSec: Discord data is for sale
The shadow of the past and security lessons
Target’s most notorious security incident remains the massive 2013 breach, when data on up to 110 million customers was leaked online. That case changed the way large companies approach cybersecurity. The current allegations, if confirmed, are a reminder that protecting internal development tools and source code is now a critical issue, not just for the reputation, but also for the operational security of modern organizations.
Source: www.bleepingcomputer.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
