securityonline.info 21 Sept 2026, 04:01 UTC

Mandiant Infiltrated TeamPCP Chat and Helped Revoke Stolen Credentials

Mandiant Infiltrated TeamPCP Chat and Helped Revoke Stolen Credentials
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor

GOOGLE’S Threat Intelligence team said at a security conference that a Mandiant researcher infiltrated TeamPCP’s core chat group by creating a digital persona and building trust with an existing member. The private group contained about 12 people and was used to discuss attacks, stolen data and extortion plans. According to Google, TeamPCP had developed a worm capable of compromising multiple applications and exfiltrating sensitive corporate information, which the group threatened to publish unless victims paid.

The researcher reportedly found that TeamPCP stored large volumes of usernames, passwords and other access credentials on a central server. Google shared this intelligence with Amazon Web Services (AWS), which then helped revoke the exposed credentials at scale. Google subsequently contacted affected organisations, advising them to rotate credentials and strengthen access controls.

The article says the operative did not take part in offensive activity, but used information from the group’s communications to support defensive action and provide intelligence to law enforcement.

Google also said operational-security mistakes in the chat enabled information about suspected members to be passed to authorities. Two core TeamPCP members had previously been arrested in Australia during a joint FBI and Australian law-enforcement operation. Google did not explicitly confirm that the undercover intelligence led to those arrests, and the article presents that connection as probable rather than established.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline