\n\n\n\n Sock Puppets Beat Scanners, and That Should Bother Your Security Budget - AgntBox Sock Puppets Beat Scanners, and That Should Bother Your Security Budget - AgntBox \n

Sock Puppets Beat Scanners, and That Should Bother Your Security Budget

📖 4 min read•762 words•Updated Sep 22, 2026

Google spends an amount of money on automated threat detection that Google also cracked open TeamPCP, a notorious supply-chain hacking group, because one analyst named Austin Larsen went undercover and stuck around long enough to watch the crew make mistakes.

Those two facts sit uncomfortably next to each other. I review AI tooling for a living, and this story is the kind of thing I keep quiet about at vendor briefings because it undercuts the pitch deck.

What actually happened

The reported version is short. In 2026, an undercover Google analyst worked his way inside TeamPCP, which let Google monitor and disrupt what the group was doing. The intelligence he gathered was used to warn and protect potential victims. Per the reporting, Google followed a trail of operational security lapses allegedly made by one of two Australians later accused of being part of the crew. Ruben Ian Thomson and Louis Michael Gaebler, both in their early 20s, were arrested by Australian police in a joint investigation with FBI assistance.

That’s the whole shape of it. No model architecture. No detection pipeline. A person, a fake identity, patience, and someone else’s sloppiness.

Why this matters for anyone buying AI security tools

Half the AI security products I test are sold on the premise that attribution and intent are pattern problems. Feed the system enough telemetry, enough dark web scraping, enough behavioral baselines, and it will tell you who is coming for you and why.

Some of that works. Anomaly detection on network traffic is genuinely useful. Automated triage that cuts alert volume by a meaningful margin earns its license cost. I’ve said as much in previous reviews and I stand by it.

But there’s a category of claim that this story quietly deflates. Products that promise to map threat actor groups, identify members, and predict campaigns are selling you inference on top of scraps. The TeamPCP case got resolved because a human being was in the room, reading context that no scraper collects: who trusts whom, who talks too much, who reuses a handle they shouldn’t.

That distinction matters when you’re allocating budget. Detection tooling and intelligence work are not the same purchase, even when the same vendor sells both on the same slide.

The honest read on what tools can and can’t do

Here’s how I’d break down where automation earned its place in a story like this and where it didn’t:

  • Almost certainly helped: correlating the operational security lapses across data sources once someone knew what to look for. That’s a search and join problem, and machines are excellent at it.
  • Almost certainly helped: pushing victim notifications out at scale after the intelligence existed. Warning potential targets quickly is infrastructure work.
  • Did not happen automatically: deciding to go undercover, maintaining a believable identity inside a criminal group, and judging which chatter was signal.
  • Did not happen automatically: the trust that made the access possible in the first place.

The tooling amplified a human decision. It did not make the decision.

What I’d ask a vendor after reading this

If you sit through security tool demos, this story gives you a useful question to bring. Ask the vendor what their product would have contributed to the TeamPCP case specifically. Not what it would have detected in general. What it would have done at each stage.

Most answers will land on “we would have surfaced the operational security lapses faster.” Fair enough, and worth paying for. What you should watch for is the vendor who claims their platform would have identified the group’s membership without human infiltration. That’s where the marketing stops matching the record.

I’d also push on data provenance. Threat intelligence feeds are only as good as their sources, and the best sources in this case were people, not crawls. A tool that presents inferred actor profiles with high confidence scores and thin sourcing is a liability during incident response, because your team will act on it.

Where I land

Supply-chain attacks are the failure mode that keeps me up at night, because one compromised dependency reaches everyone downstream. The tooling market knows this and prices accordingly.

Nothing here says the tools are useless. It says the hardest part of this particular win was not automatable, and the people selling automation as a complete answer are overselling. Use the software for what it does well: volume, correlation, speed of notification. Staff the rest with humans who have time to be patient.

Google has both. Your company probably has a subscription and a hope. Budget accordingly.

đź•’ Published:

đź§°
Written by Jake Chen

Software reviewer and AI tool expert. Independently tests and benchmarks AI products. No sponsored reviews — ever.

Learn more →
Browse Topics: AI & Automation | Comparisons | Dev Tools | Infrastructure | Security & Monitoring
Scroll to Top