Skip to content
Tech News
← Back to articles

An undercover Google analyst infiltrated a notorious supply-chain hacking gang

read original get YubiKey 5C NFC Security Key → more articles
Why This Matters

This story reveals how Google's threat intelligence team went beyond passive monitoring to actively infiltrate and disrupt a major hacking group targeting supply-chain credentials, highlighting a more aggressive approach to counter-hacking. It underscores the scale of modern supply-chain attacks and the emerging risk of AI tools being used to develop zero-day exploits, which has significant implications for enterprise security and vendor risk management.

Key Takeaways
Worth a Look

YubiKey 5C NFC Security Key — With supply-chain hackers hunting for stolen credentials and access tokens, hardware-based multi-factor authentication is one of the best defenses against account takeover. The YubiKey lets you secure logins with a physical key that phishing and credential-stuffing attacks can't replicate. It's a practical step anyone can take after reading about groups like TeamPCP harvesting passwords at scale.

See YubiKey 5C NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

“You guys should understand that we pulled off the biggest supplychain [sic] maybe ever recorded in modern history,” one TeamPCP member wrote in the leaked chats.

Michael Fletcher, a former AFP analyst who now works in the threat research division of an Australian telecom firm, says he approached Larsen around that time about methods for monitoring the group’s members and activities. He says that Larsen responded by asking Fletcher to approach the hackers with caution because one of them was a “friendly,” Fletcher remembers. “I thought, damn, you all have been inside this early,” he says.

Google’s undercover analyst, Larsen says, gained access to a server where TeamPCP was storing its trove of credentials stolen from its many victims: the usernames, passwords, and access tokens it had obtained through its hacking and seemingly planned to use to extort target companies. So Google’s team decided to take action to warn victims and prevent TeamPCP’s ransom scheme. “My thought was: How can we, as quickly as possible, disrupt their campaign before more compromises can happen?” Larsen says. “Let’s go mess up what they’re doing. That was my goal.”

Rather than focus on alerting the owners of the stolen credentials at victim companies directly, which Larsen says would have taken too long given the sheer number of breached companies, Google first reached out to providers where those credentials could be used, like Amazon Web Services and Microsoft, to have the credentials revoked and prevent the hackers from exploiting them. Larsen and his team sent out hundreds of notification emails to those providers and then to victims, many of which got immediate responses.

Around the same time, Larsen says, Google’s visibility into the TeamPCP internal chat also allowed it to learn that someone within the group’s core circle was, distinct from the group’s supply-chain hacking, using an AI tool to develop a zero-day exploit in a widely used piece of login software that would allow the hackers to bypass its two-factor authentication. Google’s team got a copy of the exploit code, tested it out, and found that, with a few tweaks, it worked—a rare instance of an in-the-wild AI-created hacking technique that took advantage of a previously unknown software vulnerability. Google warned the software’s developer, who was able to patch its security flaw. (The incident was described in a case study Google released in May, but without naming TeamPCP or detailing how Google learned about the exploit.)