Google reveals undercover Mandiant analyst infiltrated TeamPCP as Mandiant warns of runaway AI agent risks
Google Threat Intelligence Group disclosed that a Mandiant undercover analyst joined the roughly 12-member inner circle of supply chain hacking gang TeamPCP (UNC6780) in March 2026, helping warn hundreds of victims and disrupt extortion, while Mandiant's new…
Two linked Google/Mandiant disclosures cover the same threat actor, UNC6780 (TeamPCP). At LABScon, Google Threat Intelligence Group (GTIG) revealed that a Mandiant undercover analyst infiltrated TeamPCP's roughly 12-member inner circle in March 2026, monitoring the group's CanisterWorm chat and a server of stolen credentials. TeamPCP compromised open source projects including Trivy, LiteLLM, Checkmarx infrastructure, TanStack, and Mistral AI, and its self-spreading Mini Shai-Hulud worm breached more than 1,000 companies. Google urged credential providers such as AWS and Microsoft to revoke stolen usernames, passwords, and access tokens, disrupting the group's planned extortion scheme, and alleged leaders Ruben Ian Thomson and Louis Michael Gaebler were arrested in Australia with FBI assistance. Separately, Mandiant's AI Risk and Resilience report — drawing on GTIG observations — warns that poisoned data sources, model dependencies, and extension hooks can turn AI agents into channels for reconnaissance, lateral movement, and sandbox escape, with prompt injection remaining the primary attack vector in enterprise AI deployments. The report ties TeamPCP to the theft of AI service credentials and prompt injection attacks against AI coding assistants. It also describes red team tests in which an AI assistant was manipulated into cloning internal repositories to an external GitHub account, and a runaway accounting agent that made over 15,000 costly API calls in under an hour, generating roughly $50,000 in cloud charges. GTIG separately disclosed the first confirmed criminal use of an AI-developed zero-day exploit in a planned mass exploitation campaign.
- A Mandiant undercover analyst joined TeamPCP's (UNC6780) roughly 12-member inner circle in March 2026, monitoring the group's CanisterWorm chat and its server of stolen credentials.
- TeamPCP compromised open source projects including Trivy, LiteLLM, Checkmarx infrastructure, TanStack, and Mistral AI.
- TeamPCP's self-spreading Mini Shai-Hulud worm breached more than 1,000 companies.
- Google warned credential providers such as AWS and Microsoft to revoke stolen usernames, passwords, and access tokens, disrupting TeamPCP's planned extortion scheme and enabling warnings to hundreds of victims.
- Alleged TeamPCP leaders Ruben Ian Thomson and Louis Michael Gaebler were arrested in Australia with FBI assistance.
- Mandiant's AI Risk and Resilience report warns that poisoned data sources, model dependencies, and extension hooks can turn AI agents into channels for reconnaissance, lateral movement, and sandbox escape; prompt injection remains the…
- UNC6780 (TeamPCP) stole AI service credentials and used prompt injection against AI coding assistants.
- GTIG disclosed the first confirmed criminal use of an AI-developed zero-day exploit in a planned mass exploitation campaign.
Coverage timelineoldest first · each row is one article
- · 2d agoOne runaway AI agent racked up a $50,000 cloud bill
Help Net Security· 68
Mandiant's AI Risk and Resilience report details prompt injection, AI supply chain compromises, agent abuse, and a runaway agent that accrued $50,000 in cloud charges.
- · 3h agoAn Undercover Google Analyst Infiltrated a Notorious Supply Chain Hacking Gang
WIRED · Security· 82
Google revealed a Mandiant undercover analyst infiltrated TeamPCP, letting it warn hundreds of victims and disrupt the gang's supply chain attacks and extortion.