{
  "id": 8273269,
  "title": "An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang",
  "url": "https://urgent.news/2026/09/18/an-undercover-google-analyst-infiltrated-a-notorious-supply-chain",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-18T16:00:00.000Z",
  "source": {
    "name": "Wired",
    "slug": "wired",
    "url": "https://www.wired.com/story/an-undercover-google-analyst-infiltrated-a-notorious-supply-chain-hacking-gang/"
  },
  "original_language": "en",
  "account": "Google's threat intelligence team has revealed a significant infiltration of the notorious supply-chain hacking gang TeamPCP. Austin Larsen, a researcher at Google's Threat Intelligence Group, presented details of their investigation and infiltration at the LABScon security research conference. The group, which began appearing online in late 2025, had launched a series of supply-chain attacks, compromising open-source software and hijacking the credentials of software developers. This allowed the group to repeatedly exploit victims and breach high-profile targets, including Github, Mercor, and employee devices at OpenAI, the European Commission, and unnamed others.\n\nAccording to Larsen, Google's undercover researcher was invited to join TeamPCP's inner circle almost from the group's inception. This mole, one of about 12 members given access to a core chat called CanisterWorm, provided Google with valuable insights into the hackers' activities. The researcher gained access to a server storing stolen credentials, which Google used to warn victims and prevent the ransom scheme. Instead of directly alerting the breached companies, Google targeted providers like Amazon Web Services and Microsoft to revoke the compromised credentials.\n\nIn addition, Google's team discovered that someone within TeamPCP's inner circle was developing a zero-day exploit in widely used login software. Google tested the exploit code and found it to be effective, marking a rare instance of an in-the-wild AI-created hacking technique.",
  "summary": "TeamPCP pulled off the worst-ever software supply-chain hacking spree and breached thousands of companies. Now Google’s threat intelligence group says it had a mole inside the hackers’ inner circle.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}