Close Menu
AI News TodayAI News Today

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    TechCrunch Mobility: How do we know when an AV is safe enough?

    GraphRAG: A Practitioner’s Guide to 6 Advanced Architectural Patterns

    Humans, not rogue AI, are still the biggest cybersecurity risk to energy systems

    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    Facebook X (Twitter) Instagram Pinterest Vimeo
    AI News TodayAI News Today
    • Home
    • AI News
    • AI Reviews
    • AI Tools
    • AI Tutorials
    • Chatbots
    • Free AI Tools
    • Artificial Intelligence
    AI News TodayAI News Today
    Home»Chatbots»An undercover Google analyst infiltrated a notorious supply-chain hacking gang
    Chatbots

    An undercover Google analyst infiltrated a notorious supply-chain hacking gang

    By No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    An undercover Google analyst infiltrated a notorious supply-chain hacking gang
    Share
    Facebook Twitter LinkedIn Pinterest Email

    “You guys should understand that we pulled off the biggest supplychain [sic] maybe ever recorded in modern history,” one TeamPCP member wrote in the leaked chats.

    Michael Fletcher, a former AFP analyst who now works in the threat research division of an Australian telecom firm, says he approached Larsen around that time about methods for monitoring the group’s members and activities. He says that Larsen responded by asking Fletcher to approach the hackers with caution because one of them was a “friendly,” Fletcher remembers. “I thought, damn, you all have been inside this early,” he says.

    Google’s undercover analyst, Larsen says, gained access to a server where TeamPCP was storing its trove of credentials stolen from its many victims: the usernames, passwords, and access tokens it had obtained through its hacking and seemingly planned to use to extort target companies. So Google’s team decided to take action to warn victims and prevent TeamPCP’s ransom scheme. “My thought was: How can we, as quickly as possible, disrupt their campaign before more compromises can happen?” Larsen says. “Let’s go mess up what they’re doing. That was my goal.”

    Rather than focus on alerting the owners of the stolen credentials at victim companies directly, which Larsen says would have taken too long given the sheer number of breached companies, Google first reached out to providers where those credentials could be used, like Amazon Web Services and Microsoft, to have the credentials revoked and prevent the hackers from exploiting them. Larsen and his team sent out hundreds of notification emails to those providers and then to victims, many of which got immediate responses.

    Around the same time, Larsen says, Google’s visibility into the TeamPCP internal chat also allowed it to learn that someone within the group’s core circle was, distinct from the group’s supply-chain hacking, using an AI tool to develop a zero-day exploit in a widely used piece of login software that would allow the hackers to bypass its two-factor authentication. Google’s team got a copy of the exploit code, tested it out, and found that, with a few tweaks, it worked—a rare instance of an in-the-wild AI-created hacking technique that took advantage of a previously unknown software vulnerability. Google warned the software’s developer, who was able to patch its security flaw. (The incident was described in a case study Google released in May, but without naming TeamPCP or detailing how Google learned about the exploit.)

    Analyst gang Google hacking infiltrated notorious SupplyChain undercover
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleMeta’s Muse Is Better at Surveilling Than Helping Me
    Next Article How to Get Usable Midjourney Results in Six Steps (With Prompts You Can Copy)
    • Website

    Related Posts

    Chatbots

    Humans, not rogue AI, are still the biggest cybersecurity risk to energy systems

    Chatbots

    6 days left to get ahead at Disrupt

    Chatbots

    A24’s reputation is on the line with the SCP Foundation movie

    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    TechCrunch Mobility: How do we know when an AV is safe enough?

    0 Views

    GraphRAG: A Practitioner’s Guide to 6 Advanced Architectural Patterns

    0 Views

    Humans, not rogue AI, are still the biggest cybersecurity risk to energy systems

    0 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    AI Tutorials

    Quantization from the ground up

    AI Tools

    David Sacks is done as AI czar — here’s what he’s doing instead

    AI Reviews

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    TechCrunch Mobility: How do we know when an AV is safe enough?

    0 Views

    GraphRAG: A Practitioner’s Guide to 6 Advanced Architectural Patterns

    0 Views

    Humans, not rogue AI, are still the biggest cybersecurity risk to energy systems

    0 Views
    Our Picks

    Quantization from the ground up

    David Sacks is done as AI czar — here’s what he’s doing instead

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Terms & Conditions
    • Privacy Policy
    • Disclaimer

    © 2026 ainewstoday.co. All rights reserved. Designed by DD.

    Type above and press Enter to search. Press Esc to cancel.