---
title: "FBI FLASH: TeamPCP Hits Software Supply Chain,… | Firevault"
description: "FBI FLASH warns that TeamPCP is compromising widely used developer and security tools to steal cloud tokens, SSH keys and Kubernetes secrets. What UK…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": "GB"
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/fbi-flash-teampcp-software-supply-chain-attacks#webpage",
      "url": "https://fire-vault.com/news/fbi-flash-teampcp-software-supply-chain-attacks",
      "name": "FBI FLASH: TeamPCP Hits Software Supply Chain,…",
      "description": "FBI FLASH warns that TeamPCP is compromising widely used developer and security tools to steal cloud tokens, SSH keys and Kubernetes secrets. What UK…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/d0b7d825-a497-405f-943d-e15e09a5406d/teampcp-fbi-flash.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/fbi-flash-teampcp-software-supply-chain-attacks#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/fbi-flash-teampcp-software-supply-chain-attacks#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "FBI FLASH: TeamPCP Hits Software Supply Chain, Steals Cloud Keys",
          "item": "https://fire-vault.com/news/fbi-flash-teampcp-software-supply-chain-attacks"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "FBI FLASH: TeamPCP Hits Software Supply Chain, Steals Cloud Keys",
      "description": "FBI FLASH warns that TeamPCP is compromising widely used developer and security tools to steal cloud tokens, SSH keys and Kubernetes secrets. What UK organisations must isolate now.",
      "url": "https://fire-vault.com/news/fbi-flash-teampcp-software-supply-chain-attacks",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/d0b7d825-a497-405f-943d-e15e09a5406d/teampcp-fbi-flash.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/d0b7d825-a497-405f-943d-e15e09a5406d/teampcp-fbi-flash.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/d0b7d825-a497-405f-943d-e15e09a5406d/teampcp-fbi-flash.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://fire-vault.com/__l5e/assets-v1/d0b7d825-a497-405f-943d-e15e09a5406d/teampcp-fbi-flash.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-07-05T10:19:25.065729+00:00",
      "dateModified": "2026-07-05T10:24:15.389802+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/fbi-flash-teampcp-software-supply-chain-attacks"
      },
      "inLanguage": "en-GB",
      "articleSection": "Breaking",
      "wordCount": 778,
      "keywords": "Breaking, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "The FBI has issued a FLASH advisory on the cybercriminal group known as TeamPCP , which has been carrying out large-scale software supply chain compromises by targeting widely used developer and security tools. Once inside a victim environment, the group extracts the credentials that matter most: cloud access tokens, SSH keys and Kubernetes secrets . It then extorts victims, publishes their names ",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What is TeamPCP?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "TeamPCP is a cybercriminal group named in an FBI FLASH advisory for carrying out large-scale software supply chain compromises. The group targets widely used developer and security tools, extracts cloud access tokens, SSH keys and Kubernetes secrets from victim environments, and then extorts victims by publishing their names on a public leak site and threatening to release stolen data."
          }
        },
        {
          "@type": "Question",
          "name": "How can UK organisations protect against software supply chain attacks like TeamPCP?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Read the FBI FLASH and hunt for the listed indicators of compromise, rotate long-lived cloud tokens, remove signing keys and CI secrets from online build hosts, audit every third-party developer or security tool that holds cloud or cluster credentials, and hold high-value material such as root cloud tokens and signing keys on physically air-gapped hardware so a compromised trusted tool cannot exfiltrate them."
          }
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Breaking News Updated as information becomes available 

Overview

What TeamPCP is actually doingWhy this matters for UK organisa…The Firevault viewWhat to do this weekShareMore Resources

[Knowledge Vault](/learn/knowledge)/ Breaking 

Breaking · 5 July 2026 · Breaking 

# FBI FLASH: TeamPCP Hits Software Supply Chain, Steals Cloud Keys

FBI FLASH warns that TeamPCP is compromising widely used developer and security tools to steal cloud tokens, SSH keys and Kubernetes secrets. What UK organisations must isolate now.

![Mark Fermor](/assets/mark-fermor-C-vy1NeN.jpg)

Mark Fermor Director & Co-Founder, Firevault 

4 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Ffbi-flash-teampcp-software-supply-chain-attacks)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Ffbi-flash-teampcp-software-supply-chain-attacks&text=FBI%20FLASH%3A%20TeamPCP%20Hits%20Software%20Supply%20Chain%2C%20Steals%20Cloud%20Keys%0A%0AFBI%20FLASH%20warns%20that%20TeamPCP%20is%20compromising%20widely%20used%20developer%20and%20security%20tools%20to%20steal%20cloud%20tokens%2C%20SSH%20keys%20and%20Kubernetes%20secrets.%20What%20UK%20organisations%20must%20isolate%20now.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Ffbi-flash-teampcp-software-supply-chain-attacks)[](mailto:?subject=FBI%20FLASH%3A%20TeamPCP%20Hits%20Software%20Supply%20Chain%2C%20Steals%20Cloud%20Keys&body=FBI%20FLASH%20warns%20that%20TeamPCP%20is%20compromising%20widely%20used%20developer%20and%20security%20tools%20to%20steal%20cloud%20tokens%2C%20SSH%20keys%20and%20Kubernetes%20secrets.%20What%20UK%20organisations%20must%20isolate%20now.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Ffbi-flash-teampcp-software-supply-chain-attacks)

![Abstract editorial illustration of a software supply chain compromise with magenta package nodes and leaking cyan credential tokens on a dark navy background](/__l5e/assets-v1/d0b7d825-a497-405f-943d-e15e09a5406d/teampcp-fbi-flash.jpg)

Breaking 

Article record

**Breaking**Category 

**5 July 2026**Published 

**4 min read**Reading time 

**Mark Fermor**Written by 

Abstract editorial illustration of a software supply chain compromise with magenta package nodes and leaking cyan credential tokens on a dark navy background

Why it matters

## What this means for organisations holding critical data

FBI FLASH warns that TeamPCP is compromising widely used developer and security tools to steal cloud tokens, SSH keys and Kubernetes secrets. What UK organisations must isolate now.

In this analysis

1.  01 [What TeamPCP is actually doing](#section-0)
2.  02 [Why this matters for UK organisa…](#section-1)
3.  03 [The Firevault view](#section-2)
4.  04 [What to do this week](#section-3)

**On this page**[What TeamPCP is actually doing](#section-0)[Why this matters for UK organisa…](#section-1)[The Firevault view](#section-2)[What to do this week](#section-3)

The **FBI has issued a FLASH advisory** on the cybercriminal group known as **TeamPCP**, which has been carrying out large-scale software supply chain compromises by targeting widely used developer and security tools. Once inside a victim environment, the group extracts the credentials that matter most: **cloud access tokens, SSH keys and Kubernetes secrets**. It then extorts victims, publishes their names on a public leak site and, in several cases, collaborates with other threat actor groups to increase pressure.

For UK boards, this is not another ransomware headline. It is a reminder that the software you trust to build, ship and defend your estate is now a first-class attack surface.

## What TeamPCP is actually doing

According to the FBI FLASH, TeamPCP is not brute-forcing perimeters. The group is compromising the tools that already sit inside trusted software delivery pipelines. That includes developer utilities, CI and CD components, and in some cases security tooling itself. Once a trusted binary is compromised, the group reaches downstream victims through the software update or agent channel that those victims already permit.

Inside the victim environment, TeamPCP focuses on the credentials that unlock everything else:

-   **Cloud access tokens** for AWS, Azure and GCP tenancies
-   **SSH keys** for production servers and jump hosts
-   **Kubernetes secrets**, service account tokens and container registry credentials

The group then moves to extortion. Victims are named on a public leak site, stolen data is threatened for release, and in some cases the group works alongside other criminal actors to escalate the pressure. The FBI FLASH sets out TeamPCP's tactics, techniques and procedures (TTPs), indicators of compromise (IOCs) and defensive recommendations. UK security teams should read it directly and cross-reference the IOCs against their own telemetry.

## Why this matters for UK organisations

A supply chain compromise of a developer or security tool bypasses most of the controls a UK organisation has paid for. The binary is signed. The update channel is trusted. The agent already runs with the permissions it needs to reach production. Endpoint detection tools are looking for suspicious processes, not for a legitimate agent being told to exfiltrate a Kubernetes secret to an attacker-controlled endpoint.

One compromised tool, one time, gives an attacker keys to production, CI/CD, cloud tenancies and container platforms in a single operation. That is why TeamPCP is going after software supply chains rather than individual companies. It is a force multiplier.

The uncomfortable question for every UK board is simple. **Where are your long-lived cloud tokens, SSH keys and Kubernetes secrets stored right now?** If the answer is "in a secrets manager that any compromised build agent can reach", the exposure is direct.

## The Firevault view

Firevault's position on this is deliberate. High-value credentials that could hand an attacker a cloud tenancy or a production cluster should not sit on any always-connected system. Once a trusted developer or security tool is compromised, every online secrets store, key vault and CI runner in its blast radius becomes reachable in the same operation.

A physically air-gapped vault removes the exfiltration path entirely. Signing keys, break-glass credentials, root cloud tokens and long-lived infrastructure secrets held on a Firevault are not on the network TeamPCP or any downstream operator can touch. Security is enforced by physics, not by the assumption that every piece of trusted software will stay uncompromised.

## What to do this week

1.  **Read the FBI FLASH.** Pull the TTPs and IOCs, hand them to your SOC and hunt for the indicators across endpoint, cloud audit and Kubernetes control-plane logs. Source: [FBI FLASH on TeamPCP](https://lnkd.in/eKwDRTeC).
2.  **Rotate long-lived cloud tokens.** Any AWS, Azure or GCP credential older than 90 days, especially those held by build agents or third-party developer tools, should be rotated on a defined schedule this quarter.
3.  **Move signing keys and CI secrets off online build hosts.** A compromised runner should not be able to reach the key material that signs your releases or unlocks production.
4.  **Audit third-party developer and security tools with cloud scope.** List every vendor agent that has an API token into your cloud tenancy or cluster. Reduce the scope of each token to the minimum needed and remove any that are no longer used.
5.  **Isolate high-value credential stores.** Root cloud accounts, domain administrator credentials, disaster-recovery keys and signing material belong on hardware that is physically disconnected from the systems TeamPCP is targeting.

The pattern behind TeamPCP is not new, but the scale is. Software supply chain attacks will keep happening because they work. The organisations that come through them well are the ones that assumed, in advance, that their trusted tools could be turned against them, and put their most sensitive credentials somewhere those tools could never reach.

_Mark Fermor, Co-Founder, Firevault._

About the author

![Mark Fermor](/assets/mark-fermor-C-vy1NeN.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## Physical disconnection removes the path an attacker needs

Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your data sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Command**Access windows and retrieval under your control 

**Location**Held in a secure Firevault Bunker 

Related Reading

## You may also find these useful

[

![Russia's NoName Hacks Quebec Water Plant | Utility Response](/__l5e/assets-v1/7ee07055-807f-48ab-aa25-1607f065f99e/quebec-water-plant-hero.jpg)

Breaking 

### Russia's NoName Hacks Quebec Water Plant | Utility Response

Russia-linked NoName breached a Quebec water treatment plant's SCADA. What UK and Canadian water utilities must isolate, air-gap and audit now.

5 Jul 2026 6 min 







](/news/russian-noname-hack-quebec-water-treatment-plant)[

![Iran-linked hackers shut down a UK power plant for four days](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/iran-uk-power-plant-cyber-attack-2026.jpg)

Insight 

### Iran-linked hackers shut down a UK power plant for four days

A small British generator was taken offline for four days after an Iran-linked cyber attack, reported as the first successful intrusion of its kind against UK power generation. The grid held. The control layer did not.

23 Aug 2026 4 min 







](/news/iran-linked-hackers-uk-power-plant-shutdown-2026)[

![GTA 6 leaks: a nightmare or a blip for the biggest video game of the year?](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/gta6-leaks-rockstar-2026.jpg)

Insight 

### GTA 6 leaks: a nightmare or a blip for the biggest video game of the year?

Unreleased Grand Theft Auto 6 footage has appeared online ahead of Rockstar's official preview, and Take-Two is now in court seeking the identities behind the accounts sharing it. The game will still sell. The material that leaked can never be unseen.

22 Aug 2026 3 min 







](/news/gta-6-leaks-rockstar-development-footage-2026)[

![Nine PBS: 50 Terabytes of History Trapped by a Cloud Vendor That Closed](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/nine-pbs-archives-cloud-vendor-shutdown-2026.jpg)

Insight 

### Nine PBS: 50 Terabytes of History Trapped by a Cloud Vendor That Closed

A public broadcaster lost access to fifty terabytes of archival footage, spanning seventy years of regional history, when its cloud storage supplier suddenly went out of business. The files are still trapped in a Denver data centre.

18 Aug 2026 4 min 







](/news/nine-pbs-archives-cloud-vendor-shutdown-2026)[

![When Access Fails: Continuity Needs Offline Secure Storage](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/when-the-grid-fails-offline-secure-storage-business-continuity-2026.jpg)

Industry Insight 

### When Access Fails: Continuity Needs Offline Secure Storage

Fire and grid failure are only one of six ways organisations lose access to their own records. A practical case for holding critical material offline, whatever the cause.

18 Aug 2026 9 min 







](/news/when-the-grid-fails-offline-secure-storage-business-continuity)[

![French tax authority breach exposes 678,000 taxpayers and the land registry behind them](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/french-tax-authority-dgfip-data-breach-2026.jpg)

Insight 

### French tax authority breach exposes 678,000 taxpayers and the land registry behind them

France's Directorate General of Public Finances has confirmed that attackers used compromised access points to extract tax and cadastral data on 678,000 individuals and businesses. The same seller claims to have held a live session on the central land registry platform covering roughly 20 million people.

17 Aug 2026 3 min 







](/news/french-tax-authority-dgfip-data-breach-678000-2026)

Share this article

Breaking News 

Breaking 5 July 2026 4 min read 

## FBI FLASH: TeamPCP Hits Software Supply Chain, Steals Cloud Keys

FBI FLASH warns that TeamPCP is compromising widely used developer and security tools to steal cloud tokens, SSH keys and Kubernetes secrets. What UK organisations must isolate now.

![FBI FLASH: TeamPCP Hits Software Supply Chain, Steals Cloud Keys](/__l5e/assets-v1/d0b7d825-a497-405f-943d-e15e09a5406d/teampcp-fbi-flash.jpg)

![Mark Fermor](/assets/mark-fermor-C-vy1NeN.jpg)

Published by Mark Fermor , Director & Co-Founder 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Ffbi-flash-teampcp-software-supply-chain-attacks)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Ffbi-flash-teampcp-software-supply-chain-attacks&text=FBI%20FLASH%3A%20TeamPCP%20Hits%20Software%20Supply%20Chain%2C%20Steals%20Cloud%20Keys%0A%0AFBI%20FLASH%20warns%20that%20TeamPCP%20is%20compromising%20widely%20used%20developer%20and%20security%20tools%20to%20steal%20cloud%20tokens%2C%20SSH%20keys%20and%20Kubernetes%20secrets.%20What%20UK%20organisations%20must%20isolate%20now.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Ffbi-flash-teampcp-software-supply-chain-attacks)[](mailto:?subject=FBI%20FLASH%3A%20TeamPCP%20Hits%20Software%20Supply%20Chain%2C%20Steals%20Cloud%20Keys&body=FBI%20FLASH%20warns%20that%20TeamPCP%20is%20compromising%20widely%20used%20developer%20and%20security%20tools%20to%20steal%20cloud%20tokens%2C%20SSH%20keys%20and%20Kubernetes%20secrets.%20What%20UK%20organisations%20must%20isolate%20now.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Ffbi-flash-teampcp-software-supply-chain-attacks)

[Read full article](https://fire-vault.com/news/fbi-flash-teampcp-software-supply-chain-attacks)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/offline-secure-storage/what-is-oss)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)