Google Threat Intelligence Group Reveals Undercover Mandiant Analyst Infiltrated Notorious Hacker Syndicate TeamPCP

The landscape of modern cybersecurity changed forever when law enforcement agencies in Australia, supported by international partners, apprehended two men accused of orchestrating the most devastating software supply-chain hacking campaign in history. Behind those arrests lay a clandestine digital drama: Google’s elite threat intelligence apparatus had successfully embedded an undercover analyst deep within the inner circle of the hacking collective known as TeamPCP. For months, this operative functioned as a silent observer, monitoring a staggering wave of cyberattacks that compromised hundreds of open-source libraries, infiltrated global tech giants, and breached over a thousand corporate entities worldwide.
The revelation, detailed publicly by Google Threat Intelligence Group researcher Austin Larsen at SentinelOne’s LABScon research conference, sheds unprecedented light on the inner mechanics of a high-level cybercriminal enterprise. It also highlights a strategic shift within major cybersecurity firms toward proactive disruption—moving away from passive reporting and defense toward direct intervention, intelligence sharing, and law enforcement collaboration.
The Anatomy of an Unprecedented Hacking Campaign
Before federal authorities moved in to arrest Ruben Ian Thomson and Louis Michael Gaebler—two Australian nationals in their early twenties—TeamPCP executed a cascading series of intrusions that bypassed traditional perimeter defenses. Originating in late 2025, the group perfected a malicious methodology: infiltrating widely used open-source software packages, hiding payloads within legitimate code repositories, and hijacking developer credentials to propagate further attacks.
The scale of the campaign was staggering. Throughout the spring, TeamPCP systematically targeted essential tools and infrastructure components used by software developers globally. Their hit list included the open-source security scanner Trivy, the AI application programming interface tool LiteLLM, infrastructure belonging to web application security firm Checkmarx, the web app library TanStack, and enterprise AI platform Mistral AI.
By successfully compromising these foundational layers, the hackers cast an exceptionally wide net. Their secondary and tertiary targets included code repository GitHub, enterprise data contractor Mercor, and internal employee devices at OpenAI and the European Commission, alongside numerous other organizations whose identities remain shielded. In some instances, the syndicate deployed an automated, self-spreading worm dubbed "Mini Shai-Hulud"—paying homage to the sandworms of Frank Herbert’s science fiction epic Dune—to scale their operations exponentially across digital ecosystems.
The Inside Track: Mandiant’s Infiltration
The most remarkable facet of the investigation was Google’s ability to gain real-time visibility into the threat actors’ operations. According to Larsen, a Mandiant analyst working under a carefully constructed persona spent months building trust with individuals associated with the syndicate. By March, just as TeamPCP’s campaign was gathering dangerous momentum, the undercover researcher received an invitation to join the group’s core communication channel, designated as the CanisterWorm chat.

Reserved for approximately twelve key members, this exclusive chat served as the operational command center where the hackers coordinated attacks, shared stolen data, and boasted about their historic impact. In leaked message logs, one syndicate member bluntly summarized their footprint: "You guys should understand that we pulled off the biggest supplychain [sic] maybe ever recorded in modern history."
Operating under strict security guardrails to ensure they never engaged in illegal hacking or facilitated breaches, Google’s mole acted as a passive observer. This insider access allowed the threat intelligence team to monitor the group’s movements, identify compromised servers, and map out their extensive collection of stolen credentials, which reportedly included usernames, passwords, and access tokens belonging to more than half a million users.
Strategic Disruption and Mitigating Collateral Damage
Possessing direct insight into TeamPCP’s stolen data repository presented Google with an immediate tactical dilemma. Alerting individual victim companies one by one would have proved far too slow to prevent widespread extortion and unauthorized access, given the sheer volume of compromised entities.
Instead, Google pivoted to a systemic disruption strategy. Collaborating closely with major cloud infrastructure providers like Amazon Web Services and Microsoft, Google’s team rapidly flagged and revoked compromised credentials at the source. This pre-emptive intervention effectively neutralized the hackers’ ability to exploit their stolen loot, blunting the economic viability of TeamPCP’s extortion scheme before it could fully materialize.
Furthermore, visibility into the CanisterWorm chat allowed Google to uncover a separate, highly sophisticated development: members of the group were leveraging artificial intelligence tools to engineer a zero-day exploit against widely deployed authentication software. This exploit was designed to bypass two-factor authentication mechanisms entirely. Google’s analysts acquired a copy of the AI-generated exploit code, tested its validity, and immediately notified the software vendor, enabling a critical security patch before the weaponized code could be deployed in the wild.
Betrayal, Infighting, and Sloppy Operational Security
While Google’s undercover presence provided a significant tactical advantage, TeamPCP was simultaneously undermined by internal fractures and poor operational security. Despite harvesting over half a million credentials, the group struggled to monetize its cache effectively through traditional extortion channels, generating only tens of thousands of dollars rather than the millions amassed by rival syndicates.
In an effort to scale their profits, TeamPCP partnered with ShinyHunters, a prolific cybercriminal organization notorious for high-profile data thefts and ransomware attacks, such as the Canvas educational software platform breach. The partnership proved short-lived. By April, ShinyHunters turned on their associates, utilizing TeamPCP’s stolen credentials to conduct independent extortion campaigns without sharing the proceeds. In an aggressive display of betrayal, ShinyHunters forwarded complete logs of the TeamPCP chat server directly to Google’s researchers—unaware that Google already held an insider seat within the chat.

When TeamPCP realized they had been compromised and publicly mocked by ShinyHunters on social media platforms, they panicked. Syndicate leaders purged their membership lists, expelled ShinyHunters and Google’s undercover analyst, and migrated their stolen data trove to a new server hosted by an alternative provider.
However, the damage was already done. Traditional digital detective work, combined with the group’s increasingly sloppy operational security (opsec), sealed their fate. Larsen traced an active handle within the CanisterWorm chat back to a BreachForums user database entry linked to the Gmail address [email protected]. Historical forum archives revealed a PayPal account tied to the same username, which pointed directly to Ruben Ian Thomson.
Crucially, when TeamPCP shifted their stolen data to a new server, intelligence gathered via trusted industry partners revealed that the illicit material was being actively backed up to a Google Drive account registered to that exact same Gmail address. Armed with undeniable digital evidence, Google transferred its comprehensive dossier to the Federal Bureau of Investigation (FBI), initiating the formal legal processes that led to international law enforcement action.
The Arrests and International Law Enforcement Action
In late August, a coordinated law enforcement operation involving the Australian Federal Police (AFP) and the FBI culminated in the apprehension of Ruben Ian Thomson and Louis Michael Gaebler in Australia. Both men, in their early twenties, were charged with serious cybercrime offenses. Australian authorities released footage showing Thomson being escorted from a suburban residence in a sweatshirt, marking a dramatic public conclusion to the manhunt.
While law enforcement agencies declined to comment extensively on ongoing legal proceedings, the swift execution of warrants underscores an increasingly globalized, collaborative framework for combating borderless cyber threats. The arrests validate strategies outlined in official security doctrines, such as the FBI’s updated Cyber Strategy, which emphasizes leveraging private-public partnerships to disrupt adversary networks.
The Evolution of Threat Intelligence
The infiltration and subsequent dismantling of TeamPCP mark a watershed moment for the cybersecurity industry. For years, threat intelligence groups operated primarily as analysts and historians, cataloging vulnerabilities, issuing advisories, and documenting attacks after the fact.
The integration of undercover personas and active disruption units—such as Google’s newly formed Cyber Disruption Unit—signals a permanent evolution in how private security entities protect digital ecosystems. By transforming passive intelligence into active intervention, security researchers can intercept cyberattacks mid-stream, safeguard vulnerable infrastructure, and provide law enforcement with the precise digital breadcrumbs required to bring prolific threat actors to justice.







