People search Target data breach timeline because millions of customers entrust payment and identity data to everyday transactions. BreachHistory indexes 9 Target-linked incidents, with headline counts up to 110M+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.
Why Target breach history matters
Target operates in Retail (United States). Across indexed rows, recurring themes include credential theft and social engineering, cloud and database misconfiguration, third-party and supply-chain exposure, zero-day exploitation and malware. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.
Full timeline through 2026
2026 — Employee workstation infostealer compromise
Cataloged incident. Infostealer logs from compromised Target employee workstation. Malware captured session cookies and credentials for Confluence, Jira, and IAM portals. Exposed categories include Session cookies, credentials, Confluence/Jira/IAM access. No attested victim count is published for this row yet. See the tgt2026inf and canonical BreachHistory entry.
2026 — ~860 GB internal source code and developer docs leaked (Jan)
Unverified claim — treat actor counts cautiously. In January 2026, BleepingComputer reported that repositories on a public Gitea instance appeared to contain Target internal code and developer documentation; Security Magazine (Jan 13, 2026) cited Target employees confirming the materials were authentic and the threat actor claiming roughly 860 GB of data. Target removed the files and made its Git server inaccessible; the retailer had not publicly detailed intrusion mechanics at initial reporting. BreachHistory classifies this as corporate source-code exposure with Exposed categories include Proprietary source code, internal developer documentation, architectural metadata—not customer PII per trade press. No attested victim count is published for this row yet. See the tgt2026src and canonical BreachHistory entry.
2023 — full timeline
Cataloged incident. Target breach timeline and related incidents through 2023. Exposed categories include Details not publicly disclosed. No attested victim count is published for this row yet. See the tgtx and canonical BreachHistory entry.
2020 — 2020–2022 Account Takeover (ATO) waves
Cataloged incident. Credential stuffing attacks using automated bots. Attackers used credentials leaked from other platforms to gain access to Target.com accounts. While not a breach of Target's core database, it resulted in unauthorized access to saved payment methods and Target Circle rewards. Exposed categories include Credentials, Payment information. BreachHistory cites approximately 5K+ affected records in this row. See the tgt2020ato and canonical BreachHistory entry.
2016 — — Target: As reported by Health and Human Services…
Cataloged incident. As reported by Health and Human Services unauthorized access/disclosure paper films. No specific information as to what information was compromised as provided by health and human services. More Information: https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf;jsessionid=9BF4AF... Exposed categories include Personal information. BreachHistory cites approximately 719 affected records in this row. See the target2016 and canonical BreachHistory entry.
2014 — — Target: Investigators believe the data was obtained via…
Cataloged incident. Investigators believe the data was obtained via software installed on machines that customers use to swipe magnetic strips on their cards when paying for merchandise at Target stores. Originally 40m customers. Now 70m! BreachHistory cites approximately 70M+ affected records in this row. See the targetu and canonical BreachHistory entry.
2013 — payment cards & PII
Cataloged incident. Initial entry via phishing attack on third-party HVAC vendor (Fazio Mechanical). Lack of internal network segmentation allowed lateral movement from vendor portal to POS systems. RAM-scraping malware (Kaptoxa) stole card data during decryption in memory. Exposed: credit/debit card numbers (40M+), CVV codes, names, addresses, emails, phone numbers. Exposed categories include Email addresses, Names, Addresses, Phone numbers, Payment card details, Card numbers, Personal identifiable information, Payment information, Credit/financial data, Internal docume. BreachHistory cites approximately 110M+ affected records in this row. See the hvnr and canonical BreachHistory entry.
2013 — — Target: Investigators believe the data was obtained via…
Cataloged incident. Dec 2013. Investigators believe the data was obtained via software installed on machines that customers use to swipe magnetic strips on their cards when paying for merchandise at Target stores. Originally 40m customers. Now 70m! BreachHistory cites approximately 70M+ affected records in this row. See the target2013 and canonical BreachHistory entry.
2008 — — Target: Three employees were discovered to have used…
Cataloged incident. Three employees were discovered to have used customer account information to place fraudulent charges on Target Visa accounts. The account information included names, Social Security numbers, addresses, account numbers and telephone numbers. The total number of affected individuals was not reported. It appears that at least 40 people in four states had their accounts accessed; some of them became victims of fraud. Exposed categories include Personal information. BreachHistory cites approximately 40 affected records in this row. See the target2008 and canonical BreachHistory entry.
Patterns and analysis
- Credential theft and social engineering — appears across multiple Target catalog entries; prioritize controls that address this class of failure.
- Cloud and database misconfiguration — appears across multiple Target catalog entries; prioritize controls that address this class of failure.
- Third-party and supply-chain exposure — appears across multiple Target catalog entries; prioritize controls that address this class of failure.
- Zero-day exploitation and malware — appears across multiple Target catalog entries; prioritize controls that address this class of failure.
- Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
- 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.
What to do if you may be affected
- Step 1: Enable phishing-resistant MFA on every account tied to this brand.
- Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
- Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
- Step 4: Use virtual card numbers for online checkout where your bank supports it.
- Step 5: Bookmark the Target company page for new 2026+ disclosures.
Canonical BreachHistory hub
Explore every indexed row: breachhistory.com/target · Latest: tgt2026inf.
Sources: BreachHistory catalog (9 rows for Target), company and regulator disclosures cited in individual breach records.