Target Data Breach History
WebsiteTarget Corporation is an American retail corporation. Fortune 500.
This page shows all data breaches of Target. View the complete breach timeline, records exposed, root causes, and AI breach risk score. BreachHistory tracks disclosed data breaches worldwide.
Data Breach Timeline — All Target Breaches
- 2026 2026 Employee workstation infostealer compromise Unknown records Share
- 2026 2026 Target — ~860 GB internal source code and developer docs leaked (Jan) Unknown records Share
- 2023 2023 Target data breach — full timeline Unknown records Share
- 2020 2020–2022 Account Takeover (ATO) waves 5.0K records Share
- 2016 2016 — Target: As reported by Health and Human Services… 719 records Share
Target Data Breach Summary
This page tracks the Target data breach history and cybersecurity incidents affecting Target (United States). BreachHistory currently indexes 9 publicly disclosed or catalogued incidents spanning 2008 through 2026, with approximately 250.0 million records reported as exposed across all indexed events. These totals may include overlapping datasets or third-party estimates and should not be interpreted as unique affected users.
The Target breach timeline includes major data breaches, cyber attacks, data leaks, credential exposures, API abuse, and other security incidents. Each incident provides details on the estimated records exposed, attack method, affected data types, and supporting public sources. Currently, 0 incidents are company-confirmed, while 1 remain unverified claims pending independent verification.
Largest Target Data Breaches
The largest indexed incidents include the 2013 Mega Data Breach — payment cards & PII, the 2014 — Target: Investigators believe the data was obtained via…, and the 2013 — Target: Investigators believe the data was obtained via…, along with additional historical incidents involving exposed passwords, public databases, and large-scale data scraping. Record counts originating from threat actors or leak sites should be treated as estimates unless confirmed by Target or a regulator. Below is the list of large data breaches:
- 2013 2013 Mega Data Breach — payment cards & PII — about 110.0M records exposed · Catalogued incident
- 2014 2014 — Target: Investigators believe the data was obtained via… — about 70.0M records exposed · Catalogued incident
- 2013 2013 — Target: Investigators believe the data was obtained via… — about 70.0M records exposed · Catalogued incident
- 2020 2020–2022 Account Takeover (ATO) waves — about 5.0K records exposed · Catalogued incident
- 2016 2016 — Target: As reported by Health and Human Services… — about 719 records exposed · Catalogued incident
- 2008 2008 — Target: Three employees were discovered to have used… — about 40 records exposed · Catalogued incident
What Information Was Exposed?
Depending on the incident, exposed data may include email addresses, passwords and login credentials, phone numbers, names, physical addresses, payment card and financial account data, and other personal information (PII). The exact data varies between incidents, so review each breach page before assuming your information was affected.
Target Data Breach 2026
At the time of this update, BreachHistory catalogues 2 2026 incidents related to Target. Most recent entry: 2026 Employee workstation infostealer compromise. New incidents are added as official disclosures, regulatory filings, or credible cybersecurity reports become available.
What To Do If You Were Affected
If you believe your account may have been involved in a Target data breach, change any reused passwords, enable multi-factor authentication (MFA), monitor your account for suspicious activity, and be cautious of phishing emails or fake breach notifications.
This Target breach history is maintained by BreachHistory using public disclosures, regulatory filings, security research, and clearly labelled third-party claims. For the complete breach timeline, records exposed, incident details, and AI Breach Risk Score, explore the sections on this page.