Google Mole Watched TeamPCP Supply-Chain Spree
Google's Mandiant analyst infiltrated TeamPCP, the supply-chain hacking gang, watching its spree from day one and helping disrupt it.
TeamPCP pulled off a supply-chain hacking campaign. One of its own members bragged it was possibly the biggest software supply-chain campaign in modern history, and Google watched much of it unfold from inside the room. Austin Larsen is a Google Threat Intelligence Group researcher. He's set to lay out how his team infiltrated the group, warned its victims, and ultimately helped put two alleged members behind bars, during a talk at SentinelOne's LABScon research conference.
A Mole in the Inner Circle
The story starts well before TeamPCP became a household name in security circles. One of Mandiant's undercover personas spent months building trust with an actor who was later invited into the group, and that relationship earned the analyst a seat inside TeamPCP's core chat, a channel the hackers called CanisterWorm. Roughly a dozen members had access to it. Google's mole was one of them.
"So essentially, almost day one, Mandiant was watching everything behind the scenes," Larsen said ahead of his talk.
The timing matters. TeamPCP appears to have surfaced online in late 2025 and quickly built a reputation for cascading attacks. It compromised open-source software to plant malware, used that foothold to steal developer credentials, then planted malicious code in yet another widely used tool. The cycle repeated. Over the spring, the group hit the security scanner Trivy, the AI API tool LiteLLM, infrastructure at Checkmarx, the web app library TanStack, and the enterprise AI platform Mistral AI. Those intrusions opened doors into GitHub, the data contracting firm Mercor, and employee devices at OpenAI and the European Commission, among others who remain unnamed.
At points, TeamPCP unleashed a self-spreading worm called Mini Shai-Hulud, named for the sandworms of Dune, to automate the spread and widen the blast radius. More than a thousand companies were breached in total.
Watching the Credential Vault Fill Up
From inside CanisterWorm, Google's analyst gained access to a server where TeamPCP stockpiled the usernames, passwords, and access tokens stolen from victims, material the group apparently intended to use for extortion.
"My thought was: How can we, as quickly as possible, disrupt their campaign before more compromises can happen? Let's go mess up what they're doing. That was my goal."
Alerting every victim company directly would have taken too long given the sheer number of breached organizations. So Google went upstream instead, contacting providers like Amazon Web Services and Microsoft where the stolen credentials could actually be used, and getting them revoked. Hundreds of notification emails followed, first to providers and then to victims. Many recipients responded immediately.
That visibility produced a second discovery. Someone in TeamPCP's core circle was using an AI tool to develop a zero-day exploit against a widely used piece of login software, a flaw that would let the hackers bypass two-factor authentication. Google obtained the exploit code, tested it, and found that with minor adjustments it worked, a rare case of an AI-created attack technique exploiting a previously unknown vulnerability in the wild. The software's developer was warned and patched the flaw. Google described the case in a May writeup without naming TeamPCP or explaining how it learned of the exploit.
Partners Who Stole the Loot
About how badly TeamPCP was actually doing. For all the stolen data, which Australian authorities say included credentials for more than half a million users, the group struggled to turn a profit. Larsen estimates it collected only tens of thousands of dollars in extortion payments, nowhere near the millions comparable crews have pulled in. So TeamPCP brought in outside cybercriminal groups, handing over access to stolen credentials in exchange for a cut of any payouts.

One partner was ShinyHunters, a prolific outfit tied to years of data theft and ransomware, including a breach of the education platform Canvas that later disrupted thousands of US schools. Around April, a few weeks into the arrangement, ShinyHunters went rogue. It ran its own extortions using TeamPCP's credentials and skipped the revenue share. It even sent Larsen, unprompted, a full log of TeamPCP's chat, apparently unaware he already had eyes on it.
The betrayal did not stay quiet. ShinyHunters taunted the group publicly on X, and TeamPCP responded by tightening its circle, migrating its data to a new server, and kicking ShinyHunters and several others out of CanisterWorm, Google's analyst included. "Just delete that and stop sharing shit with shinyhunters," one leader wrote.
Breadcrumbs to an Arrest
Losing the inside seat did not end the investigation. Larsen turned to older-fashioned detective work. In a leak of user data from the BreachForums hacker forum, he found that one of the most active handles in the CanisterWorm chat had been registered to the Gmail address [email protected]. Digging through other forum archives turned up a 2019 dispute between someone using the pseudonym sheepstealing and a seller of pirated Microsoft Office keys, in which the user demanded a refund to a PayPal account tied to [email protected].
Then came the detail that Larsen could hardly believe. After TeamPCP moved its stolen credentials to a server run by a different provider, Google learned through what Larsen calls a trusted partner that the new server was being backed up to a Google Drive on that same [email protected] account.
"When we saw that, I just thought: There's no way. Why would he be sending all of this illicit, stolen material to a Google Drive that's tied to himself?" Larsen said. "That's when we gave the tip to the FBI."
An agent replied within minutes. About a month later, US law enforcement had completed the warrant process to obtain Thomson's data from Google. Late last month, Australian police arrested Ruben Ian Thomson and Louis Michael Gaebler, both in their early 20s, in a joint operation with FBI assistance. Authorities described the pair as principal participants in TeamPCP. Video released by police showed Thomson being walked out of a suburban home in a Northface hoodie and sweatpants. Neither man could be reached for comment.
The Guardrails Question
Larsen draws a line. A careful one. And it's a line around what the undercover analyst did and did not do, because the persona never engaged in illegal hacking, never encouraged the group's breaches, and she wants that distinction to hold firm no matter how much scrutiny it faces. The persona never hacked. It never cheered them on. We've got no evidence otherwise, and they're not about to pretend the record says something it doesn't.
"They were a fly on the wall, only saying enough to not be suspicious," Larsen says. "There are guardrails around what we do."
That restraint sits alongside a broader shift in how Google approaches these operations. The TeamPCP investigation began around the same time the company stood up its Cyber Disruption Unit, a team formally tasked with taking a more aggressive posture against cybercrime and state-sponsored hacking.
Michael Fletcher, a former Australian Federal Police analyst now working in threat research at an Australian telecom firm, recalls approaching Larsen about methods for tracking the group. Larsen told him to move carefully because one of the hackers was a friendly, Fletcher remembers. "I thought, damn, you all have been inside this early," he said.
What Google Says Comes Next
The operation reflects a deliberate change in mission, according to Larsen. Publishing reports, in his view, only goes so far. "Google Threat Intelligence Group has put an emphasis on disruption. That's one of our missions now," he says. "Writing reports can only be so useful. Taking action to protect users and customers, that is the next step."
Defenders watched the TeamPCP supply-chain hacking saga closely. It's a rare look. They saw how a sprawling, chaotic campaign came apart, and it didn't happen through one dramatic takedown, because what actually undid the operation was sloppy operational security, a betrayed partner, and an analyst who spent months quietly earning a seat at the table. So the collapse wasn't cinematic. It was slow.
Frequently Asked Questions
How did Google gain access to TeamPCP's core chat channel?
One of Mandiant's undercover personas spent months building trust with an actor who was later invited into the group, which earned the analyst a seat inside TeamPCP's core chat called CanisterWorm. Roughly a dozen members had access to it, and Google's mole was one of them.
Why did Google contact providers like Amazon Web Services and Microsoft instead of alerting every victim company directly?
Alerting every victim company directly would have taken too long given the sheer number of breached organizations. So Google went upstream instead, contacting providers where the stolen credentials could actually be used, and getting them revoked.
What did Google discover about an AI tool used by someone in TeamPCP's core circle?
Someone in TeamPCP's core circle was using an AI tool to develop a zero-day exploit against a widely used piece of login software, a flaw that would let the hackers bypass two-factor authentication. Google obtained the exploit code, tested it, and found that with minor adjustments it worked, and the software's developer was warned and patched the flaw.
What happened when ShinyHunters went rogue after being brought in as a partner?
Around April, a few weeks into the arrangement, ShinyHunters ran its own extortions using TeamPCP's credentials and skipped the revenue share, even sending Larsen a full log of TeamPCP's chat. ShinyHunters taunted the group publicly on X, and TeamPCP responded by tightening its circle, migrating its data to a new server, and kicking ShinyHunters and several others out of CanisterWorm, Google's analyst included.
How did the investigation lead to the arrest of two alleged TeamPCP members?
In a leak of user data from BreachForums, Larsen found that an active handle in the CanisterWorm chat had been registered to [email protected], and Google later learned the group's new server was backed up to a Google Drive on that same account. Google gave the tip to the FBI, and late last month Australian police arrested Ruben Ian Thomson and Louis Michael Gaebler in a joint operation with FBI assistance.
๐ฌ Comments (0)
No comments yet. Be the first!













