Digital Event Horizon
Google's threat intelligence group infiltrated a notorious supply-chain hacking gang called TeamPCP, allowing the company to monitor the group's activities and warn breach targets. The investigation, which was aided by an undercover analyst, revealed that TeamPCP was struggling to profit from its stolen data and had invited other cybercriminal groups to partner with it. The group's leader was eventually arrested, along with another alleged member, in a joint investigation with the FBI.
Google's threat intelligence group infiltrated TeamPCP, a notorious supply-chain hacking gang, to gather intel on their operations. The group's undercover researcher, Austin Larsen, helped monitor the hacking spree, warn breach targets, and disrupt the gang's attempts to exploit victims. TeamPCP struggled to profit from its stolen data, which included over half a million users' credentials, due to internal conflicts and external partnerships with rogue groups. Google's undercover analyst identified a member using an AI tool to develop a zero-day exploit in login software, which the software's developer was able to patch. The investigation led to the arrest of two Australians, Ruben Ian Thomson and Louis Michael Gaebler, who were charged with hacking crimes. The case highlights the importance of cybersecurity and the need for companies to take a more proactive approach to combating cybercrime.
Google's threat intelligence group had a mole inside the notorious supply-chain hacking gang, TeamPCP, which carried out a hacking spree unlike any other in history. The gang, known for its brazen string of cascading supply-chain attacks, tainted hundreds of open-source programs with its malware, stole developer accounts, and even released a Dune-themed self-spreading worm to automate the process, ultimately breaching over a thousand companies.
The team's undercover researcher, Austin Larsen, infiltrated the group during a key moment of its rampage and allowed Google to monitor the hacking spree from the inside, warn breach targets, and even help disrupt the group's attempts to exploit those victims. Larsen gained access to a server where TeamPCP was storing its trove of stolen credentials and sent out hundreds of notification emails to providers and victims, revoking the hackers' access to stolen credentials and preventing them from exploiting them.
The investigation revealed that even prior to Google's disruption effort, TeamPCP struggled to profit from its enormous collection of stolen data, which included over half a million users' credentials. The group invited multiple other cybercriminal groups to partner with it, giving them access to the stolen credentials in exchange for a percentage of any extortion payments they were able to extract. However, one of those partners, ShinyHunters, went rogue and carried out its own extortions with TeamPCP's credentials without giving the supply-chain hackers their cut.
Google's undercover analyst was not the only traitor in TeamPCP's midst. The group's internal chat was leaked, revealing that one of the members was using an AI tool to develop a zero-day exploit in a widely used piece of login software. Google warned the software's developer, who was able to patch its security flaw.
The investigation, which kicked off around the same time as Google's newly launched Cyber Disruption Unit, revealed that TeamPCP's leader was involved in a 2019 dispute on a hacker forum, where he demanded a refund for pirated Microsoft Office keys. The dispute was linked to an email address that matched one of the hackers' alleged aliases.
The FBI was eventually able to confirm that it had been working with Google to investigate TeamPCP, and that the agency had received a tip from Google's undercover analyst about the group's alleged members. The tip led to the arrest of Ruben Ian Thomson and Louis Michael Gaebler, both Australians in their early 20s, who were charged with hacking crimes.
The investigation into TeamPCP has highlighted the importance of cybersecurity and the need for companies to take a more proactive approach to combating cybercrime. Google's newly launched Cyber Disruption Unit is a testament to the company's commitment to taking action to protect users and customers.
Related Information:
https://www.digitaleventhorizon.com/articles/An-Inside-Look-at-Googles-Undercover-Operation-Against-Notorious-Supply-Chain-Hacking-Gang-deh.shtml
https://arstechnica.com/security/2026/09/an-undercover-google-analyst-infiltrated-a-notorious-supply-chain-hacking-gang/
https://www.wired.com/story/an-undercover-google-analyst-infiltrated-a-notorious-supply-chain-hacking-gang/
https://startupfortune.com/a-google-analyst-spent-months-undercover-inside-a-notorious-hacking-gang/
Published: Sun Sep 20 07:38:57 2026 by llama3.2 3B Q4_K_M