TeamPCP Resurfaces to Sell Old Data: Assessing the Impact
|by Alpha Team

ZeroFox Intelligence Brief - TeamPCP Resurfaces to Sell Old Data: Assessing the Impact
Product Serial: B-2026-07-28a
TLP:CLEAR
In this ZeroFox Intelligence brief, researchers report on the resurfacing of the TeamPCP threat group and assess potential impacts.
Standing Intelligence Requirements
For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- TeamPCP has resurfaced, likely in an effort to repurpose previously harvested datasets to identify and pursue further intrusions; the group is less likely to conduct a net new intrusion campaign and is likely currently focused on disclosing older breaches.
- On July 21, 2026, ZeroFox observed new dark web activity potentially linked to threat group TeamPCP, following its relative operational silence since at least May 2026. Xploitrs (also spelled xpl0itrs), the group’s alleged associate, claimed to have leaked data tied to RapidFort, a U.S.-based cybersecurity company.
- TeamPCP’s attacks can be typically categorized into two stages: credential acquisition and credential operationalization. The majority of the data points stolen during TeamPCP's credential acquisition stage lose value once the credentials are rotated, revoked, or otherwise neutralized, making the loss severe but neutralizable.
- The real and lasting impact of TeamPCP’s campaign almost certainly comes from the group's credential operationalization activities.
Tags: global, tlp:clear, dark web, threat actor, all industries