---
title: "Google reveals undercover analyst infiltrated supply chain hacking gang TeamPCP"
publisher: "Stockmark.IT"
author: "Stockmark.IT Website"
published: "2026-09-21T14:29:18+00:00"
modified: "2026-09-21T14:29:18+00:00"
date: 2026-09-21
canonical: "https://stockmark.it/an-undercover-google-analyst-infiltrated-a-notorious-supply-chain-hack/"
category: "Google"
categories: ["Google"]
image: "https://i0.wp.com/stockmark.it/wp-content/uploads/2026/09/google-reveals-undercover-analyst-infiltrated-supply-chain.webp?fit=1200%2C800&quality=80&ssl=1"
format: "news"
language: "en-GB"
---

# Google reveals undercover analyst infiltrated supply chain hacking gang TeamPCP

**Published:** September 21, 2026
**Author:** Stockmark.IT Website
**Categories:** Google
**Featured image:** ![Google reveals undercover analyst infiltrated supply chain hacking gang TeamPCP](https://i0.wp.com/stockmark.it/wp-content/uploads/2026/09/google-reveals-undercover-analyst-infiltrated-supply-chain.webp?fit=1200%2C800&quality=80&ssl=1)

---

Google’s threat intelligence division has disclosed that an undercover analyst from its security subsidiary Mandiant infiltrated the notorious hacker group TeamPCP during its extensive supply chain attack campaign. The revelation, presented by researcher Austin Larsen at the SentinelOne LABScon conference, details how Google monitored the group’s internal communications from the inside to identify targets, warn victims, and disrupt the hackers’ extortion efforts. This intelligence gathering contributed to the recent arrests of two Australian nationals who are alleged to have been principal participants in the cybercriminal organisation.

TeamPCP, which emerged online in late 2025, executed a series of cascading attacks that compromised hundreds of open-source programs. The group stole developer accounts to inject malware into widely used software, ultimately breaching more than a thousand companies. Notable victims included the open-source security scanner Trivy, the AI tool LiteLLM, the web application security firm Checkmarx, the web app library TanStack, and the enterprise AI platform Mistral AI. The campaign also resulted in breaches of GitHub, the data contracting firm Mercor, and employee devices at OpenAI and the European Commission. To automate this process, the group deployed a self-spreading worm named Mini Shai-Hulud, a reference to the sandworms in the novel Dune.

According to Larsen, Google’s undercover analyst was invited to join the group’s inner circle in March, just as the hacking spree began. The analyst, whose identity remains undisclosed, gained access to a core chat channel known as CanisterWorm and a server storing stolen credentials. This access allowed Google to observe the group’s operations in real time. Larsen stated that the analyst acted as a passive observer, engaging only enough to avoid suspicion, and did not participate in any illegal hacking or encourage the group’s breaches. The presence of this inside source provided Google with a significant advantage in understanding the group’s tactics and targets.

Armed with this intelligence, Google moved to disrupt TeamPCP’s plan to extort victims using the stolen credentials. Rather than contacting the numerous victim companies individually, which would have been time-consuming, Google reached out to service providers such as Amazon Web Services and Microsoft to have the compromised credentials revoked. This proactive approach aimed to prevent the hackers from exploiting the stolen data before they could monetise it. Additionally, Google’s monitoring revealed that a member of the group was using an AI tool to develop a zero-day exploit for a widely used login software, allowing it to bypass two-factor authentication. Google obtained a copy of the exploit code, tested it, and warned the software developer, who subsequently patched the vulnerability.

The group’s financial gains from its extensive data theft were reportedly modest, with Larsen estimating extortion payments in the tens of thousands of dollars rather than the millions typical of similar cybercriminal groups. In an attempt to improve its monetisation, TeamPCP partnered with other hacker groups, including ShinyHunters, sharing stolen credentials in exchange for a percentage of extortion payments. However, ShinyHunters later betrayed the group by carrying out its own extortions without sharing the proceeds. This betrayal led TeamPCP to narrow its inner circle, move its data to a new server, and exile ShinyHunters and several other members, including Google’s undercover analyst, from its core chat.

Beyond the infiltration, traditional digital forensics played a crucial role in identifying the group’s members. Larsen traced a trail of operational security mistakes made by one of the alleged leaders. By linking a Gmail address found in a hacker forum leak to a PayPal account, investigators identified Ruben Ian Thomson. Further evidence showed that stolen material was being backed up to a Google Drive account tied to the same individual. Google passed this identifying information to the FBI, which assisted Australian police in the subsequent legal process. Thomson and Louis Michael Gaebler, both in their early 20s, were arrested in Australia last month in a joint investigation with the FBI. The Australian Federal Police described them as principal participants in TeamPCP, though they have not been named in official press releases due to privacy laws. Neither Thomson nor Gaebler could be reached for comment.

The FBI declined to comment on the active investigation but noted its commitment to increasing impact on adversaries through partnerships. The AFP also declined to comment. Larsen emphasised that Google’s actions represent a shift towards more aggressive disruption of cybercrime, aligning with the launch of Google’s Cyber Disruption Unit. He stated that while writing reports is useful, taking direct action to protect users and customers is the next necessary step in combating sophisticated hacking groups.

---

**Original URL:** https://stockmark.it/an-undercover-google-analyst-infiltrated-a-notorious-supply-chain-hack/
*Created by [WP Markdown Endpoint](https://wpmarkdownendpoint.com/)*
