Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Target

Target Vendor Cyber Rating & Cyber Score

target.com

Target is one of the world’s most recognized brands and one of America’s leading retailers. We make Target our guests’ preferred shopping destination by offering outstanding value, inspiration, innovation and an exceptional guest experience that no other retailer can deliver. Target is committed to responsible corporate citizenship, ethical business practices, environmental stewardship and generous community support. Since 1946, we have given 5 percent of our profits back to our communities. Our goal is to work as one team to fulfill our unique brand promise to our guests, wherever and whenever they choose to shop. For more information, visit corporate.target.com. Beware of Hiring Scams: Target will never ask you to submit personal


Target A.I CyberSecurity Scoring

Target
Company Information
Website:https://www.target.com/careers
Employees number:184,387
Number of followers:2,539,013
NAICS:43
Industry Type:Retail
Homepage:target.com
Target Risk Score (AI oriented)
Between 650 and 699
logo
TargetRetail
Updated:
12/09/2026
653/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Target Global Score (TPRM)
xxxx
logo
TargetRetail
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

TargetWeak
Current Score
653B (WEAK)
01000
8 incidents
-50 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
654Before Incident
AUGUST 2026
651Before Incident
JULY 2026
649Before Incident
JUNE 2026
704Before Incident
Ransomware
15 Jun 2026Target
Target: Target may have suffered another damaging data leak as hackers claim 8.6GB haul

Target Faces Second Alleged Breach in 2026 as Hacker Demands Ransom

645After Incident
CRITICAL-59
TAR1787336713
Target Faces Second Alleged Breach in 2026 as Hacker Demands Ransom In mid-June 2026, a hacker using the alias Xpl0itrs claimed to have stolen 8.6GB of Target’s source code, threatening to leak the data on the dark web unless the company paid a ransom. The incident would mark Target’s second breach of the year if confirmed. However, cybersecurity researchers remain skeptical. Unlike Target’s confirmed January 2026 breach where a threat actor leaked 860GB of internal data, including source code, configuration files, and developer documentation Xpl0itrs has not provided verifiable samples of the stolen material. Some experts suggest the hacker may be recycling data from the earlier breach, as the claimed leak lacks supporting evidence. Xpl0itrs has a history of unverified claims, including failed threats against Spotify, the U.S. Department of the Treasury, OpenAI, and Trustpilot. A previous alleged breach of BMW was also debunked, with some data found to be publicly available. The lack of transparency and prior inconsistencies cast doubt on the legitimacy of the latest threat. Target has not yet responded to the allegations. If confirmed, the breach would underscore persistent vulnerabilities in the retailer’s cybersecurity defenses, following the January incident that exposed sensitive internal systems.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain
IMPACT
Data Compromised: 8.6GB of source codeBrand Reputation Impact: Potential reputational damage if confirmed
DATA BREACH
Type Of Data Compromised: Source codeSensitivity Of Data: High (internal systems)Data Exfiltration: Claimed but unverifiedSource codeConfiguration files
MAY 2026
701Before Incident
APRIL 2026
699Before Incident
MARCH 2026
697Before Incident
FEBRUARY 2026
696Before Incident
JANUARY 2026
733Before Incident
Breach
05 Jan 2026Target
Target Corporation: Target's dev server offline after hackers claim to steal source code

Alleged Sale of Target Corporation's Internal Source Code

692After Incident
CRITICAL-41
TAR1768244770
Hackers Claim to Sell Target’s Internal Source Code After Leaking Samples An unknown threat actor has allegedly breached Target Corporation’s internal development environment, claiming to possess and sell a massive trove of the retailer’s private source code. Last week, the hackers published sample repositories on Gitea a self-hosted Git platform containing portions of Target’s code and developer documentation as proof of the breach. The leaked samples included repositories with names like wallet-services-wallet-pentest-collections, TargetIDM-TAPProvisioingAPI, and Secrets-docs, along with commit metadata referencing internal Target servers and current senior engineers. A SALE.MD file in each repository advertised a full dataset of approximately 860 GB, listing over 57,000 files and directories. After BleepingComputer contacted Target about the alleged breach, the Gitea repositories were taken down, and the company’s Git server (git.target.com) became inaccessible from the internet. Previously, the subdomain had redirected to a login page for employees, but as of last weekend, it no longer loads externally. While some cached pages from git.target.com appeared in search engine results, it remains unclear whether this indicates prior exposure or misconfiguration. Though BleepingComputer has not independently verified the full dataset, the leaked material including internal API references and employee details suggests an origin from Target’s private development infrastructure rather than its public GitHub projects. Target has not provided further comment following initial inquiries. The incident follows Target’s most significant prior breach in 2013, when attackers stole payment card data and personal information from up to 110 million customers. The current claims, if confirmed, would mark another major security lapse for the retailer.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Financial Gain
IMPACT
Data Compromised: Internal source code and developer documentationSystems Affected: Internal Git server (git.target.com), development environmentDowntime: Git server taken offlineOperational Impact: Potential disruption to development operationsBrand Reputation Impact: Potential reputational damage
DATA BREACH
Type Of Data Compromised: Source code, developer documentation, internal API endpoints, commit metadataNumber Of Records Exposed: Approximately 860 GB of data advertised (57,000+ files/directories)Sensitivity Of Data: High (internal proprietary code and documentation)Data Exfiltration: Allegedly sold on underground forums
DECEMBER 2025
732Before Incident
NOVEMBER 2025
731Before Incident
OCTOBER 2025
730Before Incident
MAY 2025
762Before Incident
Breach
01 May 2025Target
Idscan.net, Hertz, Target, Motorola Solutions and Jack Henry: FBI reportedly opens inquiry into suspected IDScan.net data breach

Nexus Data Breach Exposes Millions of North American Identity Documents

716After Incident
CRITICAL-46
THEMOTIDSTARJAC1788457185
Nexus Data Breach Exposes Millions of North American Identity Documents A newly emerged cybercrime service, Nexus, has surfaced on a Russian-language forum, offering for sale high-resolution scans of over 153 million U.S. and Canadian driver’s licenses, alongside 10 million ID cards, 3 million travel documents, and 579,000 medical cards. Among the leaked records was a driver’s license scan allegedly belonging to U.S. Defense Secretary Pete Hegseth, though the authenticity of the data remains unverified. Nexus claimed the breach stemmed from a year-long intrusion into Idscan.net, a major identity verification provider serving Fortune 500 companies, retailers, financial institutions, and cannabis dispensaries. Idscan.net, which processes 21 million verifications monthly across 20,000+ global locations, uses specialized hardware to scan IDs via infrared, ultraviolet, and standard imaging. Its client list includes Hertz, Target, FedEx, Motorola Solutions, Jack Henry, Caesars Entertainment, and Planet13, a cannabis chain operating in 19 U.S. states. The breach highlights growing risks as Real ID-compliant licenses required for domestic air travel since May 2025 become central to financial and security verification. Security experts have long warned that the expansion of third-party identity verification systems creates high-value targets for cybercriminals. The FBI has not publicly commented on the investigation, and Idscan.net has yet to issue a statement. The Nexus site was later taken offline, with its login page replaced by a message stating the service was "no longer available." The incident underscores the vulnerabilities in centralized identity verification infrastructure.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Financial gain (data for sale on dark web)
IMPACT
Data Compromised: High-resolution scans of identity documentsSystems Affected: Idscan.net identity verification systemsOperational Impact: Potential disruption to identity verification services for clientsBrand Reputation Impact: Severe (centralized identity verification infrastructure vulnerability exposed)Identity Theft Risk: High (exposure of driver’s licenses, ID cards, and medical cards)
DATA BREACH
Driver’s licensesID cardsTravel documentsMedical cardsNumber Of Records Exposed: 166,579,000+ (153M driver’s licenses, 10M ID cards, 3M travel documents, 579K medical cards)Sensitivity Of Data: High (personally identifiable information, Real ID-compliant documents)Data Exfiltration: Yes (data offered for sale on dark web)File Types Exposed: High-resolution scans (infrared, ultraviolet, standard imaging)Personally Identifiable Information: Yes (names, addresses, document numbers, biometric data)
JANUARY 2024
780Before Incident
Breach
01 Jan 2024Target
Wegmans and Target: Facial recognition data is a key to your identity – if stolen, you can’t just change the locks

Facial Recognition Risks: The Permanent Threat of Stolen Biometric Data

743After Incident
CRITICAL-37
TARWEG1777381148
Facial Recognition Risks: The Permanent Threat of Stolen Biometric Data A growing number of organizations retailers, banks, airports, stadiums, and office buildings are deploying facial recognition systems to monitor and identify individuals. Unlike passwords or credit cards, which can be reset or canceled, a person’s face is a permanent biometric identifier. Once captured and converted into a mathematical template, it becomes a lifelong digital key that, if stolen, cannot be revoked. Facial recognition systems don’t store actual images but instead create unique templates mapping facial features. While these templates are more secure than raw photos, they remain vulnerable to theft. A breach could expose individuals to persistent risks, as stolen templates can be matched against surveillance footage or online images to track movements, verify identities, or even bypass security systems. Real-world breaches have already occurred. In 2024, a facial recognition system used in Australian bars and clubs was hacked. In 2019, U.S. Customs and Border Protection’s biometric data was compromised in a subcontractor breach. While it’s unclear whether stolen biometric data has been exploited, the potential for misuse is significant. Unlike fingerprints or iris scans, which require deliberate interaction, facial recognition can capture individuals without their knowledge or consent. Public cameras can scan faces from a distance, creating persistent digital records. If a database is breached, stolen facial templates can be cross-referenced with other data sources, enabling tracking or impersonation. Some organizations, like Madison Square Garden, have used facial recognition to restrict access to specific individuals. Retailers such as Wegmans and Target employ it for theft prevention, adding more records to centralized databases. Many companies lack cybersecurity expertise and rely on third-party vendors, increasing the risk of breaches or unauthorized data linking. A stolen facial template can act as a "primary key," connecting disparate datasets such as email addresses, financial records, or social media profiles to create a comprehensive identity profile. Combined with AI tools like deepfakes, criminals could impersonate individuals in systems requiring live facial verification, making identity theft harder to detect and reverse. While organizations can mitigate risks by encrypting templates, minimizing data retention, and implementing liveness detection, the convenience of facial recognition often comes at the cost of permanent privacy and security vulnerabilities. In regions with privacy laws, individuals may request access to or deletion of their biometric data, but widespread adoption continues to outpace safeguards.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Data theft, Identity theft, Surveillance
IMPACT
Data Compromised: Facial recognition templates (biometric data)Systems Affected: Facial recognition systems, Surveillance databasesOperational Impact: Potential unauthorized access to secured systems, Loss of trust in biometric securityBrand Reputation Impact: High (permanent privacy risks, loss of customer trust)Legal Liabilities: Potential (violations of privacy laws, regulatory fines)Identity Theft Risk: High (stolen biometric data enables persistent impersonation)
DATA BREACH
Type Of Data Compromised: Facial recognition templates (biometric data)Sensitivity Of Data: High (permanent, non-revocable biometric identifier)Data Encryption: Variable (some systems may lack encryption)File Types Exposed: Facial recognition templates (mathematical representations)Personally Identifiable Information: Yes (biometric data linked to individuals)
JANUARY 2019
735Before Incident
Breach
01 Jan 2019Target
Wegmans and Target: Facial recognition data is a key to your identity – if stolen, you can’t just change the locks

Facial Recognition Data Breaches Pose Permanent Identity Risks

698After Incident
CRITICAL-37
WEGTAR1778027645
Facial Recognition Data Breaches Pose Permanent Identity Risks Facial recognition technology is increasingly embedded in daily life scanning shoppers in grocery stores, travelers at airports, and attendees at stadiums often without their knowledge. Unlike passwords or credit cards, biometric data, such as facial templates, cannot be reset if compromised, creating a lifelong vulnerability. These systems convert faces into mathematical templates that map unique features, making them more secure than raw images but still susceptible to theft. Once stolen, a facial template can unlock access to bank accounts, secure facilities, or other systems, with no way to revoke or replace it. Real-world breaches have already occurred: in 2024, a facial recognition database used by Australian bars and clubs was hacked, and in 2019, U.S. Customs and Border Protection’s biometric data was exposed via a subcontractor breach. Unlike fingerprints or iris scans, which require physical interaction, facial recognition can capture individuals from a distance in public spaces, enabling passive tracking. Stolen templates can be matched against surveillance footage or online photos, allowing criminals to monitor movements or impersonate victims. When combined with other leaked data such as email addresses or financial records these templates can create "super-profiles," linking a person’s identity across multiple platforms. Organizations often rely on third-party vendors to manage biometric data, increasing the risk of centralized breaches. Some retailers, like Wegmans and Target, use facial recognition for theft prevention, while venues like Madison Square Garden have employed it to block entry to specific individuals. Unlike device-level biometrics (e.g., phone unlocking), which are stored locally, cloud-based systems remain vulnerable to large-scale attacks. The permanence of facial data makes identity theft particularly damaging. AI tools, such as deepfakes, could further exploit stolen templates, enabling fraudsters to bypass liveness detection systems. While some regions, like the EU and parts of the U.S., offer legal protections such as the right to request data deletion many organizations lack robust safeguards, leaving individuals exposed to long-term risks.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Data theft, Identity theft, Surveillance, Financial fraud
IMPACT
Data Compromised: Facial recognition templates, Personally identifiable information (PII), Surveillance footage matchesSystems Affected: Facial recognition databases, Cloud-based biometric systems, Third-party vendor systemsOperational Impact: Loss of trust in biometric systems, Potential unauthorized access to secure facilities or accountsBrand Reputation Impact: High (due to permanent identity risks and lack of recourse for affected individuals)Legal Liabilities: Potential regulatory violations, Lawsuits from affected individualsIdentity Theft Risk: High (permanent risk due to non-resettable biometric data)
DATA BREACH
Type Of Data Compromised: Facial recognition templates, Personally identifiable information (PII), Biometric dataSensitivity Of Data: High (biometric data is permanent and non-resettable)File Types Exposed: Facial templates (mathematical representations), Surveillance footage matchesPersonally Identifiable Information: Yes (facial templates linked to identities)
DECEMBER 2013
718Before Incident
Ransomware
01 Dec 2013Target
Target

Target Data Breach

549After Incident
CRITICAL-169
TAR304050824
In December 2013, Target fell victim to one of the largest retail cyber attacks in history. The attack exposed payment card information of 41 million customers and contact details for an additional 29 million. Utilizing a spear phishing technique, attackers initially compromised a third-party vendor's credentials, providing them with access to Target's network. Subsequently, malware was installed to collect customer payment data across a two-month period. This breach not only led to significant financial losses amounting to approximately $290 million but also resulted in the departure of Target's CEO and country-wide fines totaling $18.5 million. Remediation efforts, consulting, and various associated expenses substantially increased the cost of this breach.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Financial Loss: $290 millionPayment card informationContact detailsLegal Liabilities: $18.5 million in finesPayment Information Risk: High
DATA BREACH
Payment card informationContact detailsNumber Of Records Exposed: 70 millionSensitivity Of Data: HighPersonally Identifiable Information: Yes
NOVEMBER 2013
754Before Incident
Breach
01 Nov 2013Target
Target Corporation

Target Corporation Data Breach

717After Incident
CRITICAL-37
TAR443072925
The California Office of the Attorney General reported a data breach involving Target Corporation on December 20, 2013. The breach occurred between November 27 and December 15, 2013, resulting from unauthorized access to payment card data. Compromised information included customer names, credit or debit card numbers, expiration dates, and CVVs. The number of individuals affected is unknown.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Customer namesCredit or debit card numbersExpiration datesCVVs
DATA BREACH
Customer namesCredit or debit card numbersExpiration datesCVVsSensitivity Of Data: High
JUNE 2013
830Before Incident
Breach
16 Jun 2013Target
Target

Third-Party Cybersecurity Breaches in Europe’s Top Firms (2023)

749After Incident
CRITICAL-81
TAR0562405102225
In 2013, Target suffered one of the most infamous third-party breaches in retail history when cybercriminals infiltrated its systems via a compromised HVAC vendor (Fazio Mechanical Services). The attackers exploited weak credentials from the vendor’s network to access Target’s payment systems, stealing 40 million credit/debit card records and 70 million customer details (names, addresses, phone numbers, and email addresses). The breach resulted in $200+ million in direct costs, including legal settlements, regulatory fines, and credit monitoring for affected customers. Beyond financial losses, Target faced severe reputational damage, a plummet in consumer trust, and a 46% drop in profits during the post-breach quarter. The incident also triggered industry-wide scrutiny of third-party risk management, prompting stricter compliance mandates like PCI DSS updates and accelerated adoption of vendor security audits. The breach exposed systemic vulnerabilities in supply chain cybersecurity, proving that even robust internal defenses could be bypassed through negligent third-party partners.
INCIDENT DETAILS -
TYPE
Third-Party BreachSupply Chain Attack
MOTIVATION
Financial GainData TheftOperational Disruption
IMPACT
Financial Loss: Over $200 million (e.g., Target breach)Customer DataSensitive Business InformationOperational Impact: Significant disruption (e.g., business continuity risks)Customer Complaints: Loss of consumer trust (e.g., Target breach)Brand Reputation Impact: Irreversible reputational damageRegulatory PenaltiesNon-Compliance with DORA (for financial sector)Identity Theft Risk: High (due to compromised PII in breaches like Target)Payment Information Risk: High (e.g., Target breach involved payment card data)
DATA BREACH
Personally Identifiable Information (PII)Payment Card DataSensitive Business DataSensitivity Of Data: HighData Exfiltration: Likely (e.g., Target breach involved exfiltration)Personally Identifiable Information: Yes (e.g., customer names, payment details)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Target ?
?
What was Target's A.I Rankiteo Cyber Score in August 2026 ?
?
What was Target's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Target's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Target's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Target's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Target's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Target's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Target's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Target's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Target's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Target's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on Target's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Target ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Target's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?