ShinyHunters Infiltrates TeamPCP
Summary
Veteran security journalist Brian Krebs reported in late August 2026 that the data-extortion group Shinyhunters had "completely hacked" Teampcp, gaining access to TeamPCP's internal conversations and exfiltrating data roughly two weeks before TeamPCP members were arrested in Perth. Krebs stated the stolen material was shared with law enforcement and the security research community.
Status: unverified single-source claim. The report rests on Krebs's account; no ShinyHunters statement, no named researcher confirmation, and no law-enforcement attribution have been published as of 2026-08-30. Confidence is therefore medium despite the source's credibility.
Timeline
- March 2026 โ TeamPCP's supply-chain spree peaks (Trivy, LiteLLM compromises).
- April 2026 โ AFP and FBI open parallel investigations after receiving reports from "multiple cyber threat assessment companies" โ predating the alleged ShinyHunters infiltration, which is therefore a late-investigation contributor, not its origin.
- ~mid-August 2026 โ per Krebs, ShinyHunters "completely hacked TeamPCP", accessed internal conversations and stole data.
- 26 August 2026 โ AFP/FBI/WAPF arrest Ruben Ian Thomson and Louis Michael Gaebler in Perth (see Australia Charges Two Men As Teampcp S Principal Participants After Supply Chain).
- 28 August 2026 โ Krebs discloses the ShinyHunters angle on the Risky Business Features podcast, and teases "untold stories" yet to be published.
Mechanism (per Krebs)
A TeamPCP member using the handle "Pricks" invited a ShinyHunters member into the Cybercats Matrix server โ the loose peer-network hub where TeamPCP and allied groups communicated openly. The invitee downloaded the group's material and leaked it, then shared it with law enforcement and researchers. The infiltration succeeded against a group Krebs described as having catastrophic operational security.
Verification status
- Supports: Krebs had months of first-hand access to the Cybercats chat and direct Signal contact with TeamPCP's self-described spokesperson ("Ellis", later identified as Ruben Thomson). The claimed mechanism fits the group's documented openness and poor OPSEC, and matches ShinyHunters' known pattern of forum infiltration and access acquisition.
- Missing: no primary statement from ShinyHunters; no independent researcher or vendor has confirmed receiving the data; AFP/FBI credit "threat assessment companies" generically and have not named ShinyHunters. Law enforcement almost certainly will not confirm even if true.
- Watch for: Krebs's promised follow-up reporting and any ShinyHunters Telegram post.
Significance
If confirmed, the infiltration marks the first reported case of one major cybercrime group breaching another and the stolen intelligence feeding a law-enforcement takedown of a rival. It also illustrates how porous the "Cybercats" peer community was โ a key factor in the arrests' success.
Related Pages
- Teampcp โ the infiltrated group; entity page with full campaign and arrest detail
- Shinyhunters โ the infiltrating group; entity page
- Australia Charges Two Men As Teampcp S Principal Participants After Supply Chain โ the arrests this intel reportedly supported