Target may have suffered another damaging data leak as hackers claim 8.6GB haul
Hackers claim to have nabbed Target source code, but some experts are skeptical
- Hacker alias Xpl0itrs claims to have stolen 8.6GB of Target source code
- Researchers suspect it’s recycled data from January’s confirmed 860GB breach
- Xpl0itrs has a history of dubious leak claims, fueling skepticism about authenticity
Hackers are claiming to have breached Target in what would be the US supermarket giant's second breach of 2026 alone.
The attackers are threatening to release gigabytes of source code into the dark web unless the company pays up, but not everyone is sold on the idea that the US merchandise giant was actually hacked this time around.
Some security researchers believe this might just be a case of a lowly criminal piggybacking on someone else’s work.
Was there really a hack?
Target was first hit in January 2026, when a threat actor posted a new thread in an underground hacking community to claim they were selling the company's data, and that this was the first of many datasets to go on auction. To support their claim, they created multiple repositories on Gitea, a self-hosted Git platform, and uploaded a small sample of the data.
The repositories, totaling around 860 GB in size, appeared to contain internal Target source code, configuration files, and developer documentation, while repository names were referencing internal systems such as wallet services, identity management, store networking tools, secrets documentation, and gift card systems.
Target later confirmed the authenticity of the breach.
This time around, however, a different threat actor - with an alias Xpl0itrs - created a new data leak site in mid-June 2026, and earlier this month added Target. They claim to have stolen 8.6GB of the company's source code and have given it two days to pay up or see the data leak into the dark web.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Xpl0itrs is not exactly a household name in the cybercriminal community, and they have not shared any samples of the data they are claiming to have nabbed - further fueling the idea that this data was already grabbed eight months ago.
Even some of their previous “work” is questionable. Cybernews reports that in June, they teased leaking data from Spotify, the US Department of the Treasury, OpenAI, and Trustpilot, which never happened. Before that, they claimed to have stolen documents from BMW, containing details about motorcycles and dealerships. This, too, was somewhat debunked, as it turned out that some of the data was already publicly available.
➡️ Read our full guide to the best antivirus
1. Best overall:
Bitdefender Total Security
2. Best for families:
Norton 360 with LifeLock
3. Best for mobile:
McAfee Mobile Security
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.
You must confirm your public display name before commenting
Please logout and then login again, you will then be prompted to enter your display name.