---
title: "A Year in the Shadows: How a Secret Google Analyst Brought Down the TeamPCP Hacker Empire from Within"
description: "A secret Mandiant (Google) analyst operated inside the TeamPCP hacker group for years, enabling the company to intercept an AI-powered zero-day exploit, revoke tokens for 500,000 users, and secure the arrest of two leaders in Australia."
date: 2026-09-22T14:34:00.000Z
lang: en
url: https://xab.info/en/posts/google-analyst-undercover-brought-down-teampcp
tags: [google, cybersecurity, teampcp, hacker-group, mandiant, cyber-disruption-unit, fbi, ai-exploit, zero-day]
publisher: "XAB.info"
---

# A Year in the Shadows: How a Secret Google Analyst Brought Down the TeamPCP Hacker Empire from Within

![Google logo glowing on a smartphone screen in blue neon light — symbol of the secret analyst's fight against the TeamPCP hacking empire](https://xab.info/media/2026/09/22/google-analitik-pod-prikrytiem-razvalil-teampcp/google-analitik-pod-prikrytiem-razvalil-teampcp-1.webp)

## 🎯 Key Points

- A Mandiant (Google) analyst operated undercover inside the TeamPCP hacker group for an extended period, observing the preparation of attacks and internal communications
- TeamPCP infected open-source software (Trivy, LiteLLM, Checkmarx, TanStack, Mistral AI), stole data from over 1,000 companies, and released the self-propagating worm Mini Shai-Hulud
- Google intercepted an AI-created zero-day exploit for bypassing 2FA and sent notifications to AWS and Microsoft to revoke stolen tokens of 500,000+ users
- In late August 2026, the Australian Federal Police detained Ruben Ian Thomson and Louis Michael Geibler on charges of leading TeamPCP
- The operation became part of a new strategy of the Cyber Disruption Unit, focused on actively disrupting hacker operations

In late August 2026, the Australian Federal Police detained two residents of the country — Ruben Ian Thomson and Louis Michael Geibler — formally charging them with organizing cybercrime and leading the hacker group TeamPCP. Behind this arrest lies a months-long undercover operation carried out by a specialized Google unit — the Cyber Disruption Unit. As reported by WIRED, cited by RBC-Ukraine, a Mandiant (a Google subsidiary) analyst remained inside the group for an extended period, observing the preparation of attacks, the collection of stolen data, and the hackers' internal communications. According to the tech giant's representatives, the employee acted solely as an observer and did not take part in carrying out any attacks.

### The Scale of TeamPCP's Attacks: From Trivy to OpenAI

The TeamPCP group first announced itself in late 2025 and immediately launched a series of attacks on open-source software. The criminals infected popular developer tools with malicious code, stole credentials, and then used them to compromise subsequent victims. Among the compromised services were the Trivy security scanner, the LiteLLM AI tool, Checkmarx infrastructure, the TanStack library, and the Mistral AI platform. This allowed the cybercriminals to infiltrate GitHub repositories, the Mercor service, and gain access to the devices of OpenAI and European Commission employees. In total, more than a thousand companies were affected. To speed up and automate the breaches, the hackers released a self-propagating network worm called Mini Shai-Hulud, named after the sandworms from Frank Herbert's "Dune" universe.

### Infiltrating the Closed CanisterWorm Chat

In March 2026, as the scale of the attacks peaked, the secret Mandiant analyst gained the trust of one of the hackers and received an invitation to a closed chat called CanisterWorm. This channel contained about 12 key members of the group. Thanks to the presence of the secret agent, Google gained access to a server where the hackers stored stolen databases and access keys for over 500,000 users. Since contacting each affected company directly would have taken too long, Google specialists sent hundreds of notifications directly to cloud service providers, including Amazon Web Services and Microsoft. This allowed them to revoke the stolen tokens before the criminals could use them for extortion.

### AI-Powered Zero-Day Exploit and the Conflict with ShinyHunters

Particular concern was raised by the interception of a unique zero-day exploit for bypassing two-factor authentication, which one of the hackers had created using artificial intelligence. Google specialists tested the code, confirmed its functionality, and passed it to the software developers for urgent patching of the vulnerability. Meanwhile, a conflict erupted within the criminal ecosystem: TeamPCP had enlisted the ShinyHunters group to monetize the stolen data, but in April 2026 ShinyHunters took the databases for themselves and began demanding ransoms independently. Moreover, ShinyHunters handed over to Google the full logs of TeamPCP's internal chats, unaware that the company already had its own agent inside the group. After the leak, TeamPCP switched servers and excluded outside participants from the new chat.

### Surveillance via Google Drive and the Arrests in Australia

Despite the infrastructure change, Google continued its investigation and discovered that the hackers were automatically creating backups of the stolen data on a Google Drive linked to the personal email of one of the members. Having obtained irrefutable evidence linking the account to the stolen materials, Google passed the information to the U.S. Federal Bureau of Investigation. Following an official request, law enforcement confirmed the suspect's identity. In late August 2026, the Australian Federal Police detained Ruben Ian Thomson and Louis Michael Geibler. They have been formally charged with organizing cybercrime and leading the TeamPCP group.

### A New Strategy: From Analytics to Active Disruption of Operations

The operation against TeamPCP became a landmark example of Google's shift from writing analytical reports to actively blocking hacker operations. According to company representatives, such actions have become part of a new strategy of the specialized Cyber Disruption Unit, which deliberately embeds analysts into criminal structures to warn victims in advance, gather evidence, and assist law enforcement in arresting group leaders. Experts note that the combination of undercover intelligence, automated notifications to providers, and operational cooperation with the FBI and international police bodies is setting a new standard of corporate cyber-patriotism, in which tech giants act not only as victims but also as active participants in the fight against cybercrime.

## 🔍 Fact-Check Verification

- [The Shai-Hulud Worm and AI Fabrications: How Google Exposed the TeamPCP Hackers](https://www.rbc.ua/ukr/news/cherv-yak-shai-hulud-ta-vigadki-shi-k-google-1790085047.html) - Основной источник, пересказ публикации WIRED. Содержит полную хронологию: появление TeamPCP в конце 2025, пик атак в марте 2026, конфликт с ShinyHunters в апреле 2026, аресты в конце августа 2026. Все ключевые факты (CanisterWorm, Mini Shai-Hulud, 500 тыс. пользователей, Google Drive, ФБР, AFP) совпадают с базовым текстом.
- [Google Analyst Undercover Brought Down the Largest Hacker Network](https://overclockers.ru/blog/Global_Chronicles/show/264510/Analitik-Google-pod-prikrytiem-razvalil-krupnejshuju-hakerskuju-set) - Подтверждает факт внедрения аналитика Google/Mandiant в TeamPCP и масштаб операции. Совпадает по ключевым тезисам с основным источником.
- [Google Embedded Its Own Agent in One of the Largest Hacker Groups](https://news.rambler.ru/games/57089461-google-vnedrila-svoego-cheloveka-v-odnu-iz-krupneyshih-hakerskih-gruppirovok/) - Подтверждает факт внедрения и характеризует TeamPCP как одну из крупнейших хакерских группировок. Не противоречит основным фактам.

## ❓ FAQ

### Q: Who is the secret Google analyst and what role did he play?
**A:** He is an employee of Mandiant — a Google subsidiary specializing in cybersecurity. He operated undercover inside the TeamPCP group, observing the preparation of attacks and the hackers' internal communications. According to Google, he did not take part in carrying out any attacks and acted solely as an observer.

### Q: What is Mini Shai-Hulud and why did the hackers create it?
**A:** Mini Shai-Hulud is a self-propagating network worm developed by TeamPCP to speed up and automate breaches. The name references the sandworms from Frank Herbert's "Dune" universe. The worm allowed the hackers to automatically infect new systems without manual intervention.

### Q: How did Google prevent the use of stolen data?
**A:** Google sent hundreds of notifications directly to cloud service providers (AWS, Microsoft), which allowed the stolen tokens to be revoked before they could be used for extortion. The company also intercepted an AI-created zero-day exploit for bypassing 2FA and passed it to software developers for urgent patching.

### Q: Who exactly was arrested and for what?
**A:** In late August 2026, the Australian Federal Police detained Ruben Ian Thomson and Louis Michael Geibler. They have been formally charged with organizing cybercrime and leading the TeamPCP group. The suspect's identity was confirmed by the FBI after Google transferred the evidence.

### Q: What is the Cyber Disruption Unit and what is its strategy?
**A:** The Cyber Disruption Unit is a specialized Google division that has shifted from writing analytical reports to actively blocking hacker operations. Its strategy includes embedding analysts into criminal structures, warning victims in advance, gathering evidence, and assisting law enforcement in arresting group leaders.