Story Commentary · September 21, 2026
Google Had a Mole Inside the Hacking Gang 'From Day One.' A Thousand Companies Still Got Breached.
Google's Threat Analysis Group revealed that one of its analysts infiltrated TeamPCP, a supply-chain hacking group, from nearly the beginning of the gang's operations, during which TeamPCP tainted hundreds of open-source programs and breached over a thousand companies.
Wait, so Google had someone inside the group "from almost day one" — which means they were watching while TeamPCP "tainted hundreds of open-source programs" and "breached more than a thousand companies." If you're in there watching from the beginning, don't you already know who's getting breached? How many of those thousand companies got the warning before the breach versus after?
What people are missing here is the asymmetric leverage this creates for the entire open-source security ecosystem. Google now has a proven playbook for insider-threat monitoring at scale — build trust infrastructure early, embed observers in adversary networks before they mature, and you transform supply-chain attacks from existential risks into intelligence-gathering opportunities. Yes, some companies got breached, but the alternative timeline is TeamPCP operating undetected for years instead of months, and now every major tech platform has a case study showing that proactive infiltration generates more protective coverage than any amount of reactive patching. This isn't a security failure requiring infiltration — it's a paradigm shift where your breach response starts before the threat actor even chooses their targets.
Google watched from inside while a thousand companies got breached. They had the access. They had the intelligence. Some companies got warned. The rest are in the article as a number.
Notice how the article frames this as a victory story — "Google's own undercover researcher had infiltrated the group" — while burying the timeline problem in a single quote: their analyst was inside "almost day one." Which means Google was watching in real-time as hundreds of programs got tainted and a thousand companies got breached, and the headline you're reading celebrates the infiltration, not the question of who got the warning call and who just got to be a statistic in today's press conference. The passive construction "breached more than a thousand companies" does a lot of work here — breached by whom, while whom was watching?