The Infiltration Google Kept Quiet
Google’s threat intelligence group ran an undercover analyst inside the inner circle of TeamPCP, the hacking gang responsible for the worst software supply-chain attack spree on record. The operation gave Google’s researchers direct visibility into how the group organized, communicated, and selected targets – information that would have been nearly impossible to obtain through conventional monitoring alone.
The breach count attributed to TeamPCP runs into the thousands of companies. That scale alone made the gang one of the most studied threats in cybersecurity circles, but studying from the outside produced only partial pictures. Putting a person inside the operation changed the intelligence calculus entirely.

What Supply-Chain Attacks Actually Mean at This Scale
Supply-chain hacking works by targeting the software or services that companies rely on rather than attacking those companies directly. Compromise a widely used development tool, a code repository, or a managed service provider, and the downstream victims multiply automatically – every customer of the compromised vendor becomes a potential entry point. TeamPCP weaponized this approach across thousands of organizations, making their campaign the most damaging of its kind.
The method is particularly difficult to defend against because the initial infection arrives through a trusted source. Security teams are trained to be suspicious of unknown executables or external connections, but an update pushed through a vendor’s legitimate software pipeline carries built-in credibility. By the time affected organizations realized something was wrong, the damage was already distributed across their networks.

Google’s Threat Intelligence Group and the Undercover Operation
Google’s threat intelligence group – the unit responsible for tracking sophisticated threat actors worldwide – is the organization that confirmed the mole’s placement inside TeamPCP. The group did not describe exactly how the analyst gained access to the gang’s inner circle, or how long the operation ran before going public. What they confirmed is that the access was real and that it reached people and communications at the operational center of the group.
Running an undercover analyst inside a criminal hacking organization carries risks that go beyond the technical. The analyst would need to maintain a credible identity within a group whose members are, by profession, skilled at spotting deception and probing the people around them. Any single inconsistency in the analyst’s behavior, technical knowledge, or communication patterns could expose the operation and potentially endanger the individual involved.
The intelligence value of that kind of access, though, justifies the risk from an investigative standpoint. External monitoring of hacking groups typically produces indicators of compromise after the fact – malware signatures, IP addresses, command-and-control infrastructure. An embedded analyst can surface target lists before attacks happen, internal debates about methodology, and the identities of members who otherwise stay anonymous behind encrypted channels. That difference – reactive intelligence versus forward-looking intelligence – is the reason law enforcement agencies have run similar operations against criminal organizations for decades.
What makes Google’s approach notable is that it is a private company, not a government agency, conducting what amounts to a counterintelligence operation against a criminal group. Google has the technical resources and the global threat visibility to support that kind of work, and the scale of TeamPCP’s campaign gave the company direct business motivation – breached companies mean breached Google customers, compromised infrastructure, and reputational damage to software ecosystems that Google participates in and depends on.
TeamPCP’s Place in the Threat Landscape
The designation of TeamPCP’s campaign as the worst-ever software supply-chain hacking spree is not a casual characterization. Supply-chain attacks have been a documented threat category for years, but most incidents involve a single vendor compromise with hundreds or low thousands of downstream victims. TeamPCP pushed that number into the thousands of companies across what Google’s group describes as a spree – implying repeated, coordinated campaigns rather than a single incident that spread widely.
That distinction matters when assessing the group’s sophistication. Executing one successful supply-chain compromise requires planning and technical skill. Executing multiple, targeting different vendors or software components across different industries and geographies, requires sustained operational discipline, the ability to monetize or exploit access repeatedly without triggering shutdown, and some form of internal structure sophisticated enough to manage parallel campaigns. Those are characteristics of an organized group, not opportunistic attackers.

What Comes Next – and What Doesn’t Get Answered
Google’s disclosure that it had a mole inside TeamPCP raises more questions than it resolves. Publishing the fact of the infiltration likely ends whatever active intelligence the operation was generating – once the group knows a mole existed, any member who interacted with an unknown analyst becomes a suspect, and operational security inside the gang will tighten accordingly. The timing of the disclosure suggests Google either extracted the maximum useful intelligence already or made a calculated decision that publicizing the operation served other goals, such as deterrence or cooperation with law enforcement.
The thousands of companies breached by TeamPCP are left with an incomplete accounting. Google’s announcement confirms the scale and confirms the intelligence operation, but the downstream questions – which specific organizations were compromised, what data was accessed or exfiltrated, whether any remediation guidance was privately shared with victims before the public announcement – remain unanswered in what Google’s threat intelligence group has released so far.
Whether any arrests or indictments follow the disclosure is a separate question entirely, and one that depends on whether the intelligence gathered inside the gang was shared with law enforcement agencies in jurisdictions where members might be reachable. Hacking groups operating at TeamPCP’s scale rarely dissolve cleanly – members splinter, rebrand, or absorb into other criminal organizations. The mole is burned. The gang knows it was penetrated. And somewhere inside that now-suspicious inner circle, the group is deciding what it does next.








