An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang
5 hours ago
- TeamPCP conducted an unprecedented supply-chain hacking spree, compromising hundreds of open-source programs and breaching over a thousand companies.
- Google's Threat Intelligence Group infiltrated TeamPCP via an undercover analyst from Mandiant who was inside the group's core chat from nearly day one.
- Google used its inside access to disrupt the group's ransom scheme by revoking stolen credentials and warning victims and providers like AWS and Microsoft.
- Google discovered that TeamPCP was developing an AI-generated zero-day exploit for login software with two-factor authentication bypass, and helped patch the vulnerability.
- ShinyHunters, a partner group, betrayed TeamPCP by extorting victims without sharing profits and shared TeamPCP's chat logs with Google.
- Google traced operational security lapses, including a Gmail account tied to an alleged member, leading to the identification of Ruben Ian Thomson.
- Thomson and Louis Michael Gaebler were arrested in Australia with FBI assistance, charged as principal participants in TeamPCP.