TeamPCP Supply Chain Campaign: Update 005 - First Confirmed Victim Disclosure, Post-Compromise Cloud Enumeration Documented, and Axios Attribution Narrows, (Wed, Apr 1st)
2026-04-01T19:23:53Z•a39d41ab0c92252c3f445905f3dc5241b06df0b0e992ad094a3a51ebb009d0b3
AstraZenecaDatabricksPyPI-compromiseTeamPCPTelnyxVectcloud-enumerationdata-exfiltrationdata-leakincident-responseransomwaresecurity-scannersupply-chainsupply-chain-campaignsupply-chain-compromisethreat-intel
What happened
SANS ISC diary update consolidating intelligence through 2026-04-01 on the TeamPCP supply-chain campaign (“When the Security Scanner Became the Weapon”). Key developments: first confirmed victim disclosure; documented post-compromise cloud enumeration; Axios reporting narrows attribution; Databricks investigating an alleged compromise; TeamPCP running dual ransomware operations and entering monetization (Vect ransomware affiliate activity noted previously); Telnyx PyPI compromise and AstraZeneca data release among earlier impacts. The campaign leverages a compromised security scanner and open‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- a39d41ab0c92252c3f445905f3dc5241b06df0b0e992ad094a3a51ebb009d0b3
- Enrichment time
- 2026-04-01T19:23:53Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.