Before two of its suspected operators were arrested in Australia, the cybercriminal syndicate known as TeamPCP executed a relentless hacking campaign that challenged traditional understandings of software supply-chain security. The group compromised hundreds of open-source programs, hijacked developer credentials to sustain its operations, and deployed a self-spreading, Dune-themed worm to automate its reach. In total, the group’s chaotic rampage breached more than a thousand companies worldwide, leaving a trail of compromised infrastructure in its wake.
Now, a major revelation has emerged from Google’s threat intelligence division. At a critical juncture of TeamPCP’s operations, an undercover researcher from Google’s security subsidiary, Mandiant, successfully infiltrated the group’s inner circle. This deep-cover operation allowed the tech giant to monitor the group’s activities in real time, warn unsuspecting targets, and actively disrupt extortion attempts from the inside.
The details of this infiltration were disclosed by Austin Larsen, a researcher with the Google Threat Intelligence Group, at security firm SentinelOne’s LABScon research conference. Larsen’s presentation outlined how Google traced a series of critical operational security (opsec) failures back to one of the alleged ringleaders, eventually passing key identifying data to federal law enforcement.
The investigation also leveraged intelligence from an unlikely source: ShinyHunters, a notorious cybercriminal cartel that briefly partnered with TeamPCP before turning on them. Most notably, Larsen revealed that Mandiant had placed an undercover analyst inside TeamPCP’s core communications channel almost from the moment the group gained international prominence.
"One of our personas had been working for many months to build trust with one of the actors that was invited to join TeamPCP, and so was added to the group," Larsen explained in an interview. "So essentially, almost day one, Mandiant was watching everything behind the scenes."
The TeamPCP Mole
The public downfall of TeamPCP began when Australian police, working in coordination with the FBI, arrested Ruben Ian Thomson and Louis Michael Gaebler. The two Australian nationals, both in their early 20s, were charged with multiple hacking offenses. The Australian Federal Police (AFP) described them as "principal participants" in TeamPCP, though official agency statements omitted their names in compliance with domestic privacy laws.
TeamPCP first surfaced in late 2025, quickly distinguishing itself through a series of cascading supply-chain attacks. The group’s methodology was circular and highly effective: they compromised open-source software packages to embed malicious code, which they then used to harvest the credentials of legitimate software developers. These stolen credentials allowed them to compromise even more widely used software tools, expanding their reach exponentially.
By the spring of 2026, TeamPCP’s victim list grew to include several high-profile developer tools and security platforms. Among their targets were the open-source security scanner Trivy, the artificial intelligence API tool LiteLLM, the web application security firm Checkmarx, the web application library TanStack, and the enterprise platform Mistral AI.
Each compromise served as a stepping stone. The stolen credentials eventually granted the group access to repositories on GitHub, the data contracting firm Mercor, and individual employee devices at OpenAI and the European Commission, alongside hundreds of other unnamed organizations.
To scale their operations, the hackers deployed a worm called "Mini Shai-Hulud," named after the iconic giant sandworms from the science fiction franchise Dune. The worm automated the propagation of their malware, accelerating the compromise of developer environments.
While a similar worm named "Shai-Hulud" had appeared in September 2025, investigators remain unsure whether TeamPCP or its arrested members were responsible for that earlier campaign.
As TeamPCP’s campaign intensified, Google’s undercover analyst secured an invitation to the group’s private communications. The analyst was granted access to a highly restricted chat server that the hackers called "CanisterWorm"—a channel limited to roughly a dozen core members.
"You guys should understand that we pulled off the biggest supplychain [sic] maybe ever recorded in modern history," one TeamPCP member boasted in the intercepted logs.

Google’s presence in the channel was highly classified, even within the broader cybersecurity research community. Michael Fletcher, a former AFP analyst now working in the threat research division of an Australian telecommunications firm, recalled reaching out to Larsen during the active campaign to discuss strategies for monitoring the group. Fletcher noted that Larsen urged him to proceed with extreme caution, revealing that a "friendly" was already inside the group’s network.
"I thought, damn, you all have been inside this early," Fletcher said.
The undercover analyst eventually gained access to a central storage server where TeamPCP compiled credentials stolen from their victims. The repository contained a massive trove of sensitive data, including usernames, passwords, and access tokens belonging to hundreds of companies, which the group intended to use for extortion.
Faced with this volume of compromised data, Google’s threat intelligence team prioritized rapid disruption over traditional, slower disclosure channels. Rather than notifying each victim individually—a process that would have taken weeks—Google contacted major cloud and infrastructure providers, such as Amazon Web Services and Microsoft, where the stolen credentials could be exploited.
By sending hundreds of rapid notification emails to these platform providers, Google ensured that compromised access tokens and accounts were revoked before TeamPCP could execute its extortion plans.
The infiltration also yielded critical insights into how cybercriminals are beginning to experiment with emerging technologies. Through the "CanisterWorm" chat, Google’s analyst discovered that a core member of TeamPCP was utilizing an artificial intelligence tool to write a custom, zero-day exploit. The exploit was designed to bypass two-factor authentication on a widely used login software platform.
Google’s team obtained a copy of the AI-generated code, tested it in a controlled environment, and confirmed that it was functional with minor adjustments. This represented a documented instance of an in-the-wild, AI-assisted zero-day exploit. Google immediately alerted the software developer, who patched the vulnerability before it could be deployed at scale. The incident was briefly detailed in a public threat report in May, though Google withheld TeamPCP’s identity at the time to protect the ongoing operation.
More Betrayals, Sloppy Opsec
Despite the scale of their technical compromises, TeamPCP struggled to translate their access into financial gain. The AFP estimated that the group had harvested more than half a million user credentials, yet Larsen estimated their total extortion earnings at only tens of thousands of dollars—a fraction of the millions typically amassed by comparable ransomware syndicates.
Desperate to monetize their access, TeamPCP reached out to other established cybercriminal organizations, offering access to their database of stolen credentials in exchange for a percentage of any successful extortion payouts.
Among those invited to partner was ShinyHunters, a prolific hacking collective known for high-profile data thefts, including a breach of the educational software platform Canvas that disrupted school systems across the United States.
The partnership quickly soured. Within weeks of gaining access to TeamPCP’s data, ShinyHunters began conducting independent extortion campaigns using the credentials, withholding TeamPCP’s cut of the profits.
In a surprising turn, ShinyHunters contacted Larsen directly, providing him with a complete export of their chat logs with TeamPCP—unaware that Google’s undercover analyst had already recorded the same conversations from the inside.
The dispute spilled over into public view when ShinyHunters began taunting TeamPCP on the social media platform X. Realizing they had been compromised or betrayed, TeamPCP’s leadership panicked. They restricted access to their core channels, migrated their stolen data to a new server, and purged several members from the "CanisterWorm" chat, including ShinyHunters and Google’s undercover analyst.

"Just delete that and stop sharing shit with shinyhunters," one of the TeamPCP leaders instructed in the final days of the group’s unified operations.
Despite losing their direct line of sight inside the chat, Google’s investigators continued tracking the group through digital forensics. Larsen began analyzing archived data from a historical leak of the cybercrime forum BreachForums. He discovered that one of the most active handles in the "CanisterWorm" server had registered on the forum using the email address [email protected].
Further research into historical forum archives revealed a 2019 dispute where a user named "sheepstealing" demanded a refund from a vendor selling pirated Microsoft Office keys. The dispute log showed that the refund was processed via a PayPal account linked to the email address [email protected].
The final link in the chain came after TeamPCP moved its stolen credential database to a new hosting provider. Through a trusted industry partner, Google obtained visibility into the new server’s configuration. They discovered that the database was being backed up directly to a Google Drive account associated with the same [email protected] address.
"When we saw that, I just thought: There’s no way," Larsen said. "Why would he be sending all of this illicit, stolen material to a Google Drive that’s tied to himself? That’s when we gave the tip to the FBI."
Larsen noted that federal agents responded to the tip within minutes. Independent cybersecurity researchers, including journalist Brian Krebs, had also been tracking similar digital breadcrumbs leading to Thomson’s identity prior to the arrests.
In a statement, the FBI declined to comment on the specifics of the active investigation, but noted that the bureau "strives to increase impact on adversaries through partnerships as documented in our newly released FBI Cyber Strategy." The AFP also declined to comment on the operational specifics.
Roughly a month after Google provided the tip, federal law enforcement completed the legal process required to serve a warrant for Thomson’s account data. Shortly thereafter, Australian police raided a suburban home in Western Australia, arresting Thomson. Footage released by law enforcement showed the 21-year-old being escorted from the property in handcuffs.
Throughout the entire operation, Larsen emphasized that Google’s undercover persona adhered to strict ethical and legal boundaries, serving strictly as a passive observer. "They were a fly on the wall, only saying enough to not be suspicious," Larsen said. "There are guardrails around what we do."
The operation marks a visible shift in how private threat intelligence firms interact with active cybercriminal campaigns. The investigation coincided with the launch of Google’s Cyber Disruption Unit, a specialized division tasked with actively neutralizing threats rather than simply documenting them.
"Google Threat Intelligence Group has put an emphasis on disruption. That’s one of our missions now," Larsen said. "Writing reports can only be so useful. Taking action to protect users and customers—that is the next step."