Photo: Bidgee, CC BY-SA 3.0, via Wikimedia Commons (cropped) — Australian Federal Police headquarters in Canberra (file photo, 2009). The AFP charged two Western Australian men in August over the software compromises; neither man has been convicted.

Google Says a Mandiant Analyst Spent Months Inside a Hacking Group’s Private Chat

A Google threat-intelligence researcher said this past week that the company’s Mandiant unit had an undercover analyst embedded inside the inner circle of a hacking group accused of a long run of open-source software compromises. The analyst had joined almost from the group’s earliest days. The researcher, Austin Larsen, described the operation in a talk at LABScon, the security conference SentinelOne runs at the Omni Scottsdale Resort in Scottsdale, Arizona. The conference ran Sept. 16–19, and secondary accounts of the schedule place his talk on Sept. 18. He also discussed it in an interview with WIRED, published Friday, Sept. 18. Google’s own threat-intelligence group published a report on Sept. 8 that describes the group’s 2026 supply-chain compromises, but the company has published nothing about the undercover operation itself. Australian authorities say the campaign tied to the group potentially compromised more than 1,000 organizations worldwide, enabling the theft of more than 500,000 credentials and the exfiltration of at least 300 gigabytes of data, with global remediation costs estimated in the hundreds of millions of dollars.

Larsen told WIRED that one of Mandiant’s online personas had spent months building trust with a member of the group, which called itself TeamPCP, before being invited to join. “One of our personas had been working for many months to build trust with one of the actors that was invited to join TeamPCP, and so was added to the group. So essentially, almost day one, Mandiant was watching everything behind the scenes,” Larsen said. The persona was one of roughly a dozen people given access to the group’s core chat. That access began in March, around when the campaign was getting underway. That vantage point, Larsen said, let Google see a trove of stolen login credentials the group had amassed. Rather than try to reach every affected organization individually, Google went to the providers where the credentials could be used — Amazon Web Services and Microsoft, by name — and asked them to revoke the credentials, while separately sending hundreds of notification emails. “My thought was: How can we, as quickly as possible, disrupt their campaign before more compromises can happen? Let’s go mess up what they’re doing. That was my goal,” Larsen said.

The operation did not end the way a straightforward success story would. Google said the group brought in outside partners to help monetize what it had stolen, including a crew called ShinyHunters, which broke away in April and began extorting victims with the stolen credentials on its own, without sharing proceeds, and publicly taunted TeamPCP. TeamPCP responded by moving its data and expelling members from its core chat — including Google’s undercover persona — months before Australian authorities, working with the FBI, made arrests.

The Australian Federal Police, working with the FBI and the Western Australia Police Force, said in an Aug. 27 media release that two Western Australian men were charged Aug. 26 with a combined 14 offenses, following search warrants carried out in the Perth suburbs of Cottesloe, Hamilton Hill and Mandurah. Both were listed to appear in Perth Magistrates Court on Aug. 27. The AFP’s release does not name the two men. It says a 21-year-old man from Cottesloe is charged with one count of possessing data with intent to commit a computer offense, four counts of unauthorized modification of data with intent to commit a serious offense, one count of supplying data with intent to commit a computer offense, one count of failing to comply with a section 3LA order — a court order requiring a person to give information or assistance to access data — and one count of dealing with proceeds of crime worth $100,000 or more. A 23-year-old man from Mandurah is charged with one count of possessing data with intent, four counts of unauthorized modification of data with intent to commit a serious offense, and one count of supplying data with intent. Both men are presumed innocent, and neither has been convicted. WIRED and other outlets have identified them as Ruben Ian Thomson and Louis Michael Gaebler — reporting differs on the spelling of one middle name — but that identification comes from the news outlets, not from the AFP. AFP Commander Graeme Marshall said, “In this matter, the information provided to authorities by a number of threat assessment companies proved crucial for investigators.” He added: “Cybercrime knows no borders and is a growing threat globally, so by leveraging connections and sharing advanced policing capabilities with our partners, the AFP amplifies its impact by disrupting cybercriminals across the world.” The AFP did not name which companies provided that information.

The alleged campaign itself surfaced in security advisories over several months before the arrests. Aqua Security disclosed compromises affecting the open-source scanner Trivy in March, saying exploitation had begun in late February. A compromise affecting Checkmarx’s own infrastructure dates to March 23, and the AI tool LiteLLM disclosed compromised software the following day; advisories exist from all three. In May, researchers at Snyk and safedep.io said a wave of compromised packages hit the web library TanStack, spreading to well over 100 packages within hours; CyberScoop reported that a May phase of the campaign reached substantially more packages within a few hours. WIRED reported that the campaign’s reach also extended to the AI company Mistral AI and, downstream, to GitHub, the data-contracting firm Mercor, and employee devices at OpenAI and the European Commission. Trade publications including CyberSecurityNews, GovInfoSecurity and CyberScoop reported scale figures on Aug. 26–27 matching the AFP’s own numbers. Several of those organizations have since published their own accounts. TanStack posted a post-mortem on May 11. OpenAI published a response to the TanStack compromise on May 13. GitHub published an investigation into unauthorized access to its internal repositories on May 20. Mistral AI, in a statement to BleepingComputer, said, “They contaminated some of our SDK packages for a brief period,” and confirmed that a codebase management system had been compromised. No public comment has been located from Mercor or the European Commission. The projects with advisories published them as the compromises came to light, and the campaign’s confirmed intrusions date from February to May 2026.

Several things remain unclear. Google has published nothing about the undercover operation itself — its Sept. 8 threat-intelligence report covers the group’s compromises, not the persona — so everything here about the infiltration comes from Larsen’s conference talk and his interview with WIRED. No source ties the undercover access to the arrests: the AFP credits information from “a number of threat assessment companies” without naming any, while Larsen has said separately that Google identified one of the men through ordinary open-source investigative work and passed a tip to the FBI. Separately, an undercover corporate analyst spending months embedded inside an alleged criminal group raises its own questions; no on-the-record assessment of the practice from a named outside expert turned up in this reporting.

The case is not closed. “A large volume of data seized is being forensically examined and the investigation remains ongoing,” the AFP said in its Aug. 27 release. “Further arrests and charges have not been ruled out.” Krebs on Security has separately reported that one of the men was denied bail, that the other’s lawyer did not seek it, and that both were due back in court around Sept. 18 — reporting that has not been verified against a primary court record.

Sources and further reading

Share this article