Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Technology

Google mole infiltrated supply-chain hacking gang TeamPCP before arrests

Google’s threat intel team placed an undercover analyst inside the TeamPCP hacker group, enabling it to monitor the campaign and aid law-enforcement.

The hacker collective TeamPCP launched an unprecedented series of supply-chain attacks, injecting malware into popular open-source tools and stealing developer credentials to infiltrate thousands of organizations. Google’s Threat Intelligence Group disclosed that a Mandiant analyst had been accepted into the group’s inner chat, CanisterWorm, almost from the start of its public activity. Using that access, Google alerted cloud services such as AWS and Microsoft to revoke compromised credentials and sent notifications to affected victims.

The intelligence gathered also helped pinpoint two Australian members, who were later arrested by police in cooperation with the FBI. The operation illustrates Google’s new Cyber Disruption Unit’s focus on active interference rather than passive reporting.

Why it matters

Embedding a mole let Google disrupt a massive supply-chain hack and assist authorities in arresting key perpetrators.

In this story

supply chain hackingundercover analystTeamPCPcredential theftGooglecyber disruptionarrestsopen source malware
Get the beta ↗