Google analyst infiltrates TeamPCP hackers to gather evidence
Google confirmed an analyst infiltrated supply-chain hackers TeamPCP for months, gathering evidence to aid law enforcement. This operation aims to disrupt the gang, which caused a $150 million breachโฆ
Googleโs threatโintelligence unit confirmed that it had a spy inside the inner circle of the supplyโchain hacking group TeamPCP, a claim that came out of a brief statement issued on Tuesday. The analyst was reportedly embedded within the gang for several months, gathering evidence that could help trace the groupโs operations and expose its members. The disclosure was made by Googleโs Cyber Threat Intelligence (GCTI) team, which said the mole was placed there after an internal investigation flagged suspicious activity linked to the groupโs recent attacks.
TeamPCP has been on the radar of security firms and lawโenforcement agencies for nearly a year. The gang is known for compromising software supply chains, inserting malicious code into legitimate code repositories, and then distributing the tainted software to thousands of unsuspecting customers. In 2023, TeamPCP was linked to a major breach that affected a leading cloudโstorage provider, causing an estimated $150โฏmillion in damages and forcing the company to roll out emergency patches. The groupโs tactics mirror those used by the more infamous SolarWinds actors, but TeamPCP has operated from a more decentralized structure, making it harder for lawโenforcement to track.
The analystโs infiltration reportedly allowed GCTI to collect hardโcopy evidence, including encrypted communication logs and details of the gangโs operational hierarchy. Google said it will share the findings with partner organizations and relevant nationalโsecurity agencies. The company also announced plans to enhance its own supplyโchain monitoring tools, using the intelligence gained to harden the defenses of software vendors that are frequent targets of TeamPCP. Industry experts say the move could help close a critical blind spot in the cybersecurity ecosystem, where supplyโchain attacks are increasingly the preferred attack vector for sophisticated threat actors.
In the coming weeks, Google expects to publish a detailed technical report outlining the methods used by TeamPCP, along with a set of bestโpractice recommendations for vendors. The company also plans to coordinate a joint task force with the FBIโs Cyber Division and the European Unionโs Cybersecurity Agency to pursue legal action against the groupโs members. If successful, the operation could set a precedent for how privateโsector intelligence can be leveraged to combat stateโsponsored or financially motivated hacking collectives. The broader cybersecurity community will be watching closely to see whether this cooperation signals a turning point in the fight against supplyโchain attacks.
Read Full Story at Ars Technica โ


