Google's Undercover Analyst Disrupts Notorious Hacking Group's Supply Chain Attack Campaign
The notorious hacking group TeamPCP carried out a historic supply chain attack campaign that breached over a thousand companies. The group, which appeared online in late 2025, compromised open-source programs with malware and stole developer accounts to plant its malicious code in other software tools.
During this time, Google's threat intelligence group had an undercover researcher infiltrate the group, allowing them to monitor the hacking spree from the inside. The analyst gained access to TeamPCP's server where they stored stolen credentials from their victims.
Google's team decided to disrupt the group's campaign by warning providers like Amazon Web Services and Microsoft to revoke the compromised credentials, preventing further exploitation. They also sent notification emails to victims, many of which responded immediately.
The analyst was not the only one who had infiltrated TeamPCP. Another cybercriminal group, ShinyHunters, partnered with TeamPCP but later went rogue, carrying out their own extortions without giving TeamPCP its cut.