It turned out that a PAM admin inadvertently deleted the target group, which was a static group, while trying to add target accounts to it. This activity was found in the Credential Management Administrative Activities report. PAM is missing a check on scheduled jobs when processing a target group delete and proceeds with the deletion w/o any warning, potentially leaving a corrupted scheduled job behind.
Affects all PAM releases supported as of July 2020, with 3.4.1 being the latest.
The target group can be restored temporarily by PAM support using SSH access to the PAM appliance to be able to edit the scheduled job again and review its details. Membership to the target group will not be restored this way, but it is better anyway to define a new target group with the desired properties, change the scheduled job to use the new target group, and then delete the old one again.
A defect is being raised with PAM Engineering to consider adding a check on scheduled jobs prior to deleting a target group. This is done for Credential Manager user groups already. You will not be able to delete a target group that is used in a CM user group.