This article is about ‘Ransomware 2026 Report June ‘.
TeamPCP is a financially motivated cybercrime group that emerged in late 2025. Its initial activity focused on exposed cloud infrastructure, which it exploited to deploy ransomware and conduct unauthorized cryptocurrency mining. This phase was relatively short-lived. Within approximately three months, the group adopted a more scalable operational model centered on credential theft through compromises of the open-source software supply chain. By early 2026, TeamPCP had become associated with a significant software supply-chain campaign.
The campaign used trusted security and developer tools as malware delivery mechanisms.It began with the compromise of the Trivy vulnerability scanner in March 2026 and subsequently affected Checkmarx KICS, the LiteLLM gateway, the Telnyx SDK, and several other developer-focused tools. The activity extended across GitHub Actions, Docker Hub, npm, PyPI, and OpenVSX.
Public reporting has linked the operation to more than 1,000 affected SaaS environments, approximately 500,000 compromised credentials, and over 300 GB of exfiltrated data. A key factor increasing the campaign’s impact was its chained compromise model. Credentials obtained during one intrusion were used to access additional systems and software ecosystems. The activity is therefore better assessed as a cascading compromise of interconnected trust relationships rather than a series of unrelated security incidents.
TeamPCP also appears to maintain relationships with other cybercriminal operations. We assess that the group functions partly as an access-generation operation, supplying stolen credentials and compromised environments to multiple ransomware ecosystems. Its publicly announced partnership with the Vect ransomware group, the operation of its own CipherForce ransomware brand, and reported links to other criminal actors collectively support this assessment.
This report examines TeamPCP’s origins, the development of its major campaigns, its operational methods, supporting infrastructure, relationships with other cybercriminal groups, and potential future direction.
We see the full picture of the evolving cyber threat landscape thanks to unique tools for monitoring the infrastructure used by cybercriminals and data from battlefields: