zerofox logo
Advisories

TeamPCP Resurfaces to Sell Old Data: Assessing the Impact

|by Alpha Team

banner image

ZeroFox Intelligence Brief - TeamPCP Resurfaces to Sell Old Data: Assessing the Impact

Product Serial: B-2026-07-28a

TLP:CLEAR

In this ZeroFox Intelligence brief, researchers report on the resurfacing of the TeamPCP threat group and assess potential impacts.

Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:

https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report here

Key Findings

  • TeamPCP has resurfaced, likely in an effort to repurpose previously harvested datasets to identify and pursue further intrusions; the group is less likely to conduct a net new intrusion campaign and is likely currently focused on disclosing older breaches.
  • On July 21, 2026, ZeroFox observed new dark web activity potentially linked to threat group TeamPCP, following its relative operational silence since at least May 2026. Xploitrs (also spelled xpl0itrs), the group’s alleged associate, claimed to have leaked data tied to RapidFort, a U.S.-based cybersecurity company.
  • TeamPCP’s attacks can be typically categorized into two stages: credential acquisition and credential operationalization. The majority of the data points stolen during TeamPCP's credential acquisition stage lose value once the credentials are rotated, revoked, or otherwise neutralized, making the loss severe but neutralizable.
  • The real and lasting impact of TeamPCP’s campaign almost certainly comes from the group's credential operationalization activities.

Tags: globaltlp:clear dark web threat actor all industries