Technology
Ars Technica - All content

An undercover Google analyst infiltrated a notorious supply-chain hacking gang

Source Entity

Andy Greenberg, WIRED.com

September 20, 2026
An undercover Google analyst infiltrated a notorious supply-chain hacking gang

Google's threat intelligence unit successfully infiltrated the notorious TeamPCP hacking gang using an undercover analyst. This operation provided deep insights into their massive supply-chain attack tactics and enabled the recovery of stolen credentials.

The Infiltration of TeamPCP: A Watershed Moment in Cyber Intelligence

In a landmark operation for digital security, Google’s threat intelligence group has successfully infiltrated TeamPCP, a notorious hacking organization responsible for what has been described as one of the most significant supply-chain attacks in modern history. The operation involved an undercover Google analyst who gained deep access to the group’s inner circle, effectively turning the tables on a collective that prides itself on stealth and systemic disruption.

Unmasking the Supply-Chain Threat

The severity of the situation is underscored by the hackers' own admissions, with members boasting in leaked chats about orchestrating a supply-chain breach of unprecedented scale. Supply-chain attacks are particularly dangerous because they compromise the integrity of software or hardware before it reaches the end user, often bypassing traditional security perimeters. By infiltrating the group’s server, the Google analyst was able to secure a massive trove of stolen credentials, including usernames, passwords, and access tokens, effectively neutralizing a portion of the group's leverage.

The Strategic Role of the 'Mole'

The tactical depth of this operation is highlighted by the involvement of Michael Fletcher, a former AFP analyst now working in the Australian telecom sector. Fletcher’s interactions with Google’s lead, known as Larsen, reveal the high-stakes nature of the intelligence gathering. When Fletcher attempted to coordinate monitoring efforts, he was warned by Larsen to exercise extreme caution because a 'friendly'—the undercover analyst—was already embedded within the group. This revelation confirms that Google had been monitoring TeamPCP from the inside far earlier than previously assumed.

Broader Implications for Global Security

This infiltration represents a shift in how tech giants and security firms handle advanced persistent threats (APTs). Rather than merely reacting to incidents, entities like Google are increasingly utilizing human intelligence (HUMINT) to disrupt operations at the source. The recovery of stolen credentials not only protects victims but also provides researchers with invaluable data regarding the group's methodologies, infrastructure, and potential future targets.

Historical Context and Future Outlook

The history of cyber warfare is littered with supply-chain attacks that have caused billions in damages, such as the SolarWinds breach. TeamPCP’s activities suggest a sophisticated evolution in these tactics. By embedding an analyst directly into the server housing the group's stolen assets, Google has demonstrated that the most effective defense against modern cybercrime is often direct, proactive infiltration. Moving forward, we can expect this 'intelligence-led' security model to become the standard for major tech firms defending global infrastructure.

Conclusion

The successful operation against TeamPCP serves as a stark reminder of the fragile state of global supply-chain security. While the immediate threat has been mitigated through the recovery of stolen data, the incident underscores the ongoing necessity for deep-level threat intelligence. As hacking groups become more audacious, the collaborative efforts between private sector analysts and global intelligence communities will remain the primary bulwark against systemic digital collapse.

Verification Required?

Read the full report from the primary source

Go to Ars Technica - All content