Think about the difference between a security camera and a neighbor who notices your car is gone. The camera records everything and understands nothing. The neighbor knows your routine, reads context, and calls you before the police even arrive. Most of the AI security tooling I review is a very expensive camera. What Google pulled off with TeamPCP was the neighbor.
Here’s the story, as reported this year: an undercover Google analyst got inside TeamPCP, a supply-chain hacking group with an ugly reputation, and stayed there long enough for Google to monitor and disrupt what the group was doing. The analyst fed back intelligence that let Google warn and protect potential victims. Per the reporting, the researcher who went undercover was Austin Larsen, and Google got its foothold by following a trail of operational security mistakes allegedly made by one of two Australians later accused of being part of the crew. Ruben Ian Thomson and Louis Michael Gaebler, both in their early twenties, were arrested by Australian police in a joint investigation with FBI assistance.
No model card. No agent framework. No vector database. A person, patience, and someone else’s sloppiness.
What the tooling could not do
I spend most of my working life poking at AI security products, and I want to be fair to them: pattern detection at scale is real, and a lot of these tools genuinely catch things humans miss. Anomaly detection across millions of package installs is not a job for a person with a spreadsheet.
But notice what this operation actually required, and ask yourself which part an autonomous agent handles today.
- Recognizing that a specific opsec slip was worth chasing rather than logging.
- Building enough credibility inside a criminal group that people talk freely around you.
- Judging which chatter meant an attack was imminent and which was posturing.
- Deciding what to share, with whom, and when, without burning the source.
- Sustaining a false identity over time under suspicion.
Current agents are decent at the first item if you tune them hard. They are nowhere near the rest. Social trust is not a retrieval problem. Neither is deciding how much risk another human being should absorb on your behalf.
The uncomfortable part for the AI security pitch
Every vendor deck I see promises autonomous threat response. Detection to containment with no human in the loop. That story sells because it flatters the buyer: you have a headcount problem, and software is cheaper than analysts.
This case runs the other direction. The decisive asset was an analyst with judgment and nerve, backed by an organization willing to fund slow work with no guaranteed payoff. You cannot procure that. You cannot ship it quarterly. It does not demo well.
Which is exactly why it will get underfunded at most companies. Undercover work produces nothing measurable for months. A dashboard produces a number every morning. Guess which one survives a budget review.
What I would actually want from an AI tool here
The useful framing is not human versus machine. It is: what tedious work would have made this analyst faster?
Correlating identities across forums and leaked data. Summarizing months of chat logs into a timeline. Flagging when a handle’s writing style shifts, suggesting a different person behind the keyboard. Cross-referencing named packages against the actual dependency graph of downstream victims so warnings go to the right people first. That last one is genuinely hard, genuinely valuable, and genuinely suited to software.
Notice that none of these make decisions. They compress information so a person can decide better. That is the product category I keep wishing more startups would build instead of another agent that promises to triage your alerts and mostly closes real tickets as noise.
The supply-chain angle nobody wants to hear
Supply-chain attacks work because trust is transitive and nobody audits the chain. You install a package, which pulls forty more, and one of them updated last night. That structure is the whole reason a group like TeamPCP could do damage worth this kind of response.
AI coding assistants are making that chain longer and faster. They suggest dependencies with the same confidence whether a package has ten million weekly downloads or eleven. If your workflow now includes an agent that adds imports on your behalf, you have added a link to the chain and removed a human who used to glance at it.
I am not telling you to stop using them. I use them. I am telling you that the tooling accelerating your dependency growth and the tooling defending your dependency graph are not developing at the same rate, and the gap is where the next TeamPCP lives.
My read
This operation deserves the attention it is getting, but for the opposite reason most of the coverage implies. It is not a story about advanced capability. It is a story about a well-resourced team betting on one person’s judgment and being right.
If you are evaluating AI security products this quarter, use this as your test question: does this thing make my analysts sharper, or does it promise to replace judgment it cannot actually perform? Vendors that answer honestly are worth your time. The rest are selling you a very good camera.
🕒 Published: