Google threat intelligence group details how one of its researchers infiltrated hacker group TeamPCP and helped disrupt its software supply chain hacking spree
First reported by Wired ·
This quarter, the direct cost of compromised credentials falls for organizations targeted by supply chain attacks.
Google's threat intelligence group has revealed that an undercover researcher infiltrated the hacker group TeamPCP during its supply chain hacking spree. This researcher, operating under Mandiant, gained access to the group's internal communications and stolen data from late 2025. The infiltration allowed Google to monitor TeamPCP's activities, warn potential victims, and disrupt their operations by having stolen credentials revoked by providers like AWS and Microsoft. Google's researcher also obtained and helped patch an AI-generated zero-day exploit targeting login software, which was developed by a TeamPCP member. Following a betrayal by a partner group, ShinyHunters, and subsequent security missteps by TeamPCP, Google's intelligence efforts, including correlating a Gmail address with a PayPal account and discovering data backed up to a personal Google Drive, led to the identification of alleged members, Ruben Ian Thomson and Louis Michael Gaebler, who were later arrested by Australian police with FBI assistance.
The infiltration of TeamPCP by a Google researcher highlights a growing trend of intelligence agencies and private security firms embedding assets within sophisticated hacking operations to disrupt them proactively. This insider access provides unparalleled visibility into attack methodologies, target selection, and internal group dynamics, moving beyond reactive threat analysis. The ability to not only observe but actively intervene, as seen with credential revocation and exploit patching, demonstrates a new level of operational capability in cyber defense, potentially reshaping the adversarial landscape by making prolonged, large-scale attacks more difficult to sustain.
This event underscores the evolving nature of cyber warfare, where AI is increasingly weaponized not just for attack but also for defense and intelligence gathering. The use of an AI-generated zero-day exploit by TeamPCP, and Google's subsequent rapid response and patching, points to an escalating arms race in exploit development and vulnerability disclosure. Furthermore, the internal betrayals within TeamPCP and the subsequent sharing of intelligence by a rival group, ShinyHunters, illustrate the inherent instability within criminal organizations and the opportunistic intelligence-sharing that can occur, creating new avenues for attribution and disruption.
AI-written summary. May contain errors.