Google Undercover Operation Leads to Arrest of Key Hackers in Global Cybercrime Network
September 18, 2026
Google Threat Intelligence Group infiltrated the TeamPCP hacker network by having an undercover Mandiant analyst join CanisterWorm, the core TeamPCP chat, early in the campaign.
Australian police arrested Thomson and Louis Michael Gaebler, described as principal participants, in a joint operation with the FBI; authorities have not released further details.
Google researchers monitored TeamPCP’s internal activities, alerted vulnerable providers to revoke credentials, and notified victims to disrupt the attackers’ extortion schemes.
The group deployed a self-spreading worm named Mini Shai-Hulud to automate attacks and expanded its reach to major targets including GitHub’s data contractor Mercor, OpenAI, and the European Commission.
An internal betrayal occurred when partner group ShinyHunters extorted using TeamPCP credentials and leaked TeamPCP chat logs to Google in retaliation or as leverage.
TeamPCP carried out unprecedented supply-chain attacks by compromising open-source software and stealing developer credentials to spread malware across platforms such as Trivy, LiteLLM, Checkmarx, TanStack, and Mistral AI, impacting numerous high-profile targets.
Google stressed that the undercover analyst operated within guardrails and did not commit illegal hacking, aligning with Google’s Cyber Disruption Unit and signaling a shift toward proactive disruption of cybercrime.
Google, aided by the FBI, traced and identified Ruben Ian Thomson as a leading figure through data leaks and forum activity, culminating in his arrest in Australia after the collaborative tip.
Summary based on 1 source
Get a daily email with more Tech stories
Source

WIRED • Sep 18, 2026
An Undercover Google Analyst Infiltrated a Notorious Supply Chain Hacking Gang