Google Undercover Operation Leads to Arrest of Key Hackers in Global Cybercrime Network

September 18, 2026
Google Undercover Operation Leads to Arrest of Key Hackers in Global Cybercrime Network
  • Google Threat Intelligence Group infiltrated the TeamPCP hacker network by having an undercover Mandiant analyst join CanisterWorm, the core TeamPCP chat, early in the campaign.

  • Australian police arrested Thomson and Louis Michael Gaebler, described as principal participants, in a joint operation with the FBI; authorities have not released further details.

  • Google researchers monitored TeamPCP’s internal activities, alerted vulnerable providers to revoke credentials, and notified victims to disrupt the attackers’ extortion schemes.

  • The group deployed a self-spreading worm named Mini Shai-Hulud to automate attacks and expanded its reach to major targets including GitHub’s data contractor Mercor, OpenAI, and the European Commission.

  • An internal betrayal occurred when partner group ShinyHunters extorted using TeamPCP credentials and leaked TeamPCP chat logs to Google in retaliation or as leverage.

  • TeamPCP carried out unprecedented supply-chain attacks by compromising open-source software and stealing developer credentials to spread malware across platforms such as Trivy, LiteLLM, Checkmarx, TanStack, and Mistral AI, impacting numerous high-profile targets.

  • Google stressed that the undercover analyst operated within guardrails and did not commit illegal hacking, aligning with Google’s Cyber Disruption Unit and signaling a shift toward proactive disruption of cybercrime.

  • Google, aided by the FBI, traced and identified Ruben Ian Thomson as a leading figure through data leaks and forum activity, culminating in his arrest in Australia after the collaborative tip.

Summary based on 1 source


Get a daily email with more Tech stories

More Stories