Signal Technology, daily
Last updated 21 September 2026 Türkçe
← All stories
Security

Google analyst infiltrated TeamPCP as supply‑chain hacks unfolded

The inside access let Google track the campaign, warn targets and feed police data that preceded two arrests in Australia.

Updated 21 September 2026

Google’s Threat Intelligence Group revealed that during the height of the TeamPCP supply‑chain attacks, an undercover analyst from its Mandiant subsidiary infiltrated the gang’s inner circle, giving Google inside visibility into the operation. TeamPCP had compromised hundreds of open‑source projects, stolen developer credentials, and used a Dune‑themed self‑propagating worm to breach more than 1,000 organizations, making it a major software supply‑chain incident. Using data from this infiltration, Google monitored the campaign in real time, warned affected targets, and helped interfere with TeamPCP’s exploitation attempts. Researcher Austin Larsen is presenting the technical and investigative details of this operation at SentinelOne’s LABScon security conference. Google says it correlated the hackers’ operational security errors with additional intelligence from the cybercrime group ShinyHunters, then provided identifying information about an alleged Australian ringleader to law enforcement, preceding two arrests in Australia.

Why it matters

By planting an analyst inside TeamPCP early, Google gained a rare real‑time view of a major supply‑chain hacking spree, where hundreds of open‑source projects and more than a thousand organizations were compromised. That visibility let it warn victims and disrupt some exploitation attempts, while intelligence from the rival group ShinyHunters and the gang’s own operational mistakes helped Google hand identifying data on an alleged Australian ringleader to law enforcement, ahead of arrests in Australia.

Sources