Target may have suffered another damaging data leak as hackers claim 8.6GB haul
Hacker alias Xpl0itrs claims to have stolen 8.6GB of Target source code Researchers suspect it’s recycled data from January’s confirmed 860GB breach Xpl0itrs has a history of dubious leak claims, fueling skepticism about authenticity Hackers are claiming to have breached Target in what would be the
<![CDATA[ <article> <ul><li><strong>Hacker alias Xpl0itrs claims to have stolen 8.6GB of Target source code </strong></li><li><strong>Researchers suspect it’s recycled data from January’s confirmed 860GB breach </strong></li><li><strong>Xpl0itrs has a history of dubious leak claims, fueling skepticism about authenticity</strong></li></ul><p>Hackers are claiming to have breached Target in what would be the US supermarket giant's second breach of 2026 alone. </p><p>The attackers are threatening to release gigabytes of source code into the dark web unless the company pays up, but not everyone is sold on the idea that the US merchandise giant was actually hacked this time around. </p><p>Some security researchers believe this might just be a case of a lowly criminal piggybacking on someone else’s work.</p><h2 id="was-there-really-a-hack">Was there really a hack?</h2><p><a href="https://www.techradar.com/pro/security/hackers-claim-to-have-target-source-code-for-sale-following-recent-cyberattack" target="_blank">Target was first hit in January 2026</a>, when a threat actor posted a new thread in an underground hacking community to claim they were selling the company's data, and that this was the first of many datasets to go on auction. To support their claim, they created multiple repositories on Gitea, a self-hosted Git platform, and uploaded a small sample of the data.</p><p>The repositories, totaling around 860 GB in size, appeared to contain internal Target source code, configuration files, and developer documentation, while repository names were referencing internal systems such as wallet services, <a href="https://www.techradar.com/best/best-identity-management-software" target="_blank">identity management</a>, store networking tools, secrets documentation, and gift card systems.</p><p>Target later confirmed the authenticity of the breach.</p><p>This time around, however, a different threat actor - with an alias Xpl0itrs - created a new data leak site in mid-June 2026, and earlier this month added Target. They claim to have stolen 8.6GB of the company's source code and have given it two days to pay up or see the data leak into the dark web. </p><p>Xpl0itrs is not exactly a household name in the cybercriminal community, and they have not shared any samples of the data they are claiming to have nabbed - further fueling the idea that this data was already grabbed eight months ago. </p><p>Even some of their previous “work” is questionable. <a href="https://cybernews.com/security/target-data-breach-source-code-claim/" target="_blank"><em>Cybernews</em></a> reports that in June, they teased leaking data from Spotify, the US Department of the Treasury, OpenAI, and Trustpilot, which never happened. Before that, they claimed to have stolen documents from BMW, containing details about motorcycles and dealerships. This, too, was somewhat debunked, as it turned out that some of the data was already publicly available. </p> </article> ]]>
Read the full article on TechRadar
Read Full Article →