In late August 2026, the Australian Federal Police detained two residents of the country — Ruben Ian Thomson and Louis Michael Geibler — formally charging them with organizing cybercrime and leading the hacker group TeamPCP. Behind this arrest lies a months-long undercover operation carried out by a specialized Google unit — the Cyber Disruption Unit. As reported by WIRED, cited by RBC-Ukraine, a Mandiant (a Google subsidiary) analyst remained inside the group for an extended period, observing the preparation of attacks, the collection of stolen data, and the hackers' internal communications. According to the tech giant's representatives, the employee acted solely as an observer and did not take part in carrying out any attacks.
The Scale of TeamPCP's Attacks: From Trivy to OpenAI
The TeamPCP group first announced itself in late 2025 and immediately launched a series of attacks on open-source software. The criminals infected popular developer tools with malicious code, stole credentials, and then used them to compromise subsequent victims. Among the compromised services were the Trivy security scanner, the LiteLLM AI tool, Checkmarx infrastructure, the TanStack library, and the Mistral AI platform. This allowed the cybercriminals to infiltrate GitHub repositories, the Mercor service, and gain access to the devices of OpenAI and European Commission employees. In total, more than a thousand companies were affected. To speed up and automate the breaches, the hackers released a self-propagating network worm called Mini Shai-Hulud, named after the sandworms from Frank Herbert's "Dune" universe.
Infiltrating the Closed CanisterWorm Chat
In March 2026, as the scale of the attacks peaked, the secret Mandiant analyst gained the trust of one of the hackers and received an invitation to a closed chat called CanisterWorm. This channel contained about 12 key members of the group. Thanks to the presence of the secret agent, Google gained access to a server where the hackers stored stolen databases and access keys for over 500,000 users. Since contacting each affected company directly would have taken too long, Google specialists sent hundreds of notifications directly to cloud service providers, including Amazon Web Services and Microsoft. This allowed them to revoke the stolen tokens before the criminals could use them for extortion.
AI-Powered Zero-Day Exploit and the Conflict with ShinyHunters
Particular concern was raised by the interception of a unique zero-day exploit for bypassing two-factor authentication, which one of the hackers had created using artificial intelligence. Google specialists tested the code, confirmed its functionality, and passed it to the software developers for urgent patching of the vulnerability. Meanwhile, a conflict erupted within the criminal ecosystem: TeamPCP had enlisted the ShinyHunters group to monetize the stolen data, but in April 2026 ShinyHunters took the databases for themselves and began demanding ransoms independently. Moreover, ShinyHunters handed over to Google the full logs of TeamPCP's internal chats, unaware that the company already had its own agent inside the group. After the leak, TeamPCP switched servers and excluded outside participants from the new chat.
Surveillance via Google Drive and the Arrests in Australia
Despite the infrastructure change, Google continued its investigation and discovered that the hackers were automatically creating backups of the stolen data on a Google Drive linked to the personal email of one of the members. Having obtained irrefutable evidence linking the account to the stolen materials, Google passed the information to the U.S. Federal Bureau of Investigation. Following an official request, law enforcement confirmed the suspect's identity. In late August 2026, the Australian Federal Police detained Ruben Ian Thomson and Louis Michael Geibler. They have been formally charged with organizing cybercrime and leading the TeamPCP group.
A New Strategy: From Analytics to Active Disruption of Operations
The operation against TeamPCP became a landmark example of Google's shift from writing analytical reports to actively blocking hacker operations. According to company representatives, such actions have become part of a new strategy of the specialized Cyber Disruption Unit, which deliberately embeds analysts into criminal structures to warn victims in advance, gather evidence, and assist law enforcement in arresting group leaders. Experts note that the combination of undercover intelligence, automated notifications to providers, and operational cooperation with the FBI and international police bodies is setting a new standard of corporate cyber-patriotism, in which tech giants act not only as victims but also as active participants in the fight against cybercrime.