Google infiltrated TeamPCP hacker group to disrupt attacks from the inside

1 hour ago 1



For a brief window earlier this year, someone in TeamPCP’s private chat was not who they seemed. While the hacker collective was executing one of the most damaging software supply-chain campaigns on record, a Google researcher was sitting in the room, watching every move. Google’s Threat Intelligence Group, operating through its Mandiant subsidiary, disclosed the operation on September 18, revealing that an undercover analyst had been embedded inside TeamPCP’s internal communications channel, known as CanisterWorm, since March 2026. The infiltration let Google monitor the campaign in real time, alert companies that had been breached, and actively work to blunt the group’s follow-on exploitation attempts. What TeamPCP actually did The scale of the operation was, to put it plainly, extraordinary. TeamPCP compromised more than 1,000 organizations, exfiltrated at least 300 GB of data, and walked away with more than 500,000 stolen credentials across several months of activity. The group’s method was a textbook software supply-chain attack, with some creative embellishments. Rather than breaking into companies one by one, TeamPCP went upstream, tainting hundreds of widely used open-sourc...

Read Entire Article